Broadnet SMS Services Security & Risk Analysis

wordpress.org/plugins/broadnet-sms-services

A plugin for sending SMS notification to customers and administrator when orders status is changed using WooCommerce.

0 active installs v0.0.2 PHP 7.4+ WP 5.9+ Updated Jan 4, 2024
order-cancelled-sms-notificationorder-completed-sms-notificationorder-on-hold-sms-notificationorder-pending-payment-sms-notificationorder-processing-sms-notification
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Broadnet SMS Services Safe to Use in 2026?

Generally Safe

Score 85/100

Broadnet SMS Services has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The "broadnet-sms-services" plugin version 0.0.2 presents a mixed security posture. While it exhibits strengths in avoiding dangerous functions, utilizing prepared statements for SQL queries, and having no recorded historical vulnerabilities, significant concerns arise from its attack surface. The plugin has two identified AJAX handlers, both of which lack authentication checks, creating a direct pathway for unauthorized actions. The output escaping is also a concern, with only 51% of outputs being properly escaped, leaving room for potential cross-site scripting (XSS) vulnerabilities. The absence of taint analysis results is neutral; it could indicate clean code or insufficient analysis.

Given the identified unprotected AJAX endpoints, there is a clear risk of privilege escalation or unauthorized data manipulation if these handlers perform sensitive operations. The moderate output escaping rate further exacerbates this risk, potentially allowing malicious scripts to be injected and executed. The plugin's clean vulnerability history is a positive indicator, suggesting a generally secure development approach, but it does not negate the immediate risks identified in the static analysis.

In conclusion, the "broadnet-sms-services" plugin has a concerning lack of security controls on its AJAX endpoints, which is the most critical weakness. While its SQL handling and historical security are positive, the unprotected entry points and moderate output escaping create a tangible risk that needs immediate attention. Developers should prioritize implementing proper authentication and capability checks for all AJAX handlers and improve output escaping to mitigate these vulnerabilities.

Key Concerns

  • AJAX handlers without auth checks
  • Moderate output escaping rate
Vulnerabilities
None known

Broadnet SMS Services Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Broadnet SMS Services Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
72
76 escaped
Nonce Checks
2
Capability Checks
4
File Operations
26
External Requests
4
Bundled Libraries
0

Output Escaping

51% escaped148 total outputs
Attack Surface
2 unprotected

Broadnet SMS Services Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_nds_form_responseincludes\class-broadnet-sms-services.php:175
authwp_ajax_nds_form_responsetrunk\includes\class-broadnet-sms-services.php:175
WordPress Hooks 32
actionplugins_loadedincludes\class-broadnet-sms-services.php:148
actionadmin_enqueue_scriptsincludes\class-broadnet-sms-services.php:163
actionadmin_enqueue_scriptsincludes\class-broadnet-sms-services.php:164
actionadmin_menuincludes\class-broadnet-sms-services.php:167
actionadmin_initincludes\class-broadnet-sms-services.php:168
actionadmin_noticesincludes\class-broadnet-sms-services.php:170
actionadmin_post_nds_form_responseincludes\class-broadnet-sms-services.php:172
actionwp_enqueue_scriptsincludes\class-broadnet-sms-services.php:191
actionwp_enqueue_scriptsincludes\class-broadnet-sms-services.php:192
actionwoocommerce_order_status_pendingpublic\class-broadnet-sms-services-public.php:59
actionwoocommerce_order_status_processingpublic\class-broadnet-sms-services-public.php:60
actionwoocommerce_order_status_on-holdpublic\class-broadnet-sms-services-public.php:61
actionwoocommerce_order_status_completedpublic\class-broadnet-sms-services-public.php:63
actionwoocommerce_order_status_cancelledpublic\class-broadnet-sms-services-public.php:64
actionwoocommerce_order_status_refundedpublic\class-broadnet-sms-services-public.php:65
filterwoocoomerce_sms_messagepublic\class-broadnet-sms-services-public.php:67
actionplugins_loadedtrunk\includes\class-broadnet-sms-services.php:148
actionadmin_enqueue_scriptstrunk\includes\class-broadnet-sms-services.php:163
actionadmin_enqueue_scriptstrunk\includes\class-broadnet-sms-services.php:164
actionadmin_menutrunk\includes\class-broadnet-sms-services.php:167
actionadmin_inittrunk\includes\class-broadnet-sms-services.php:168
actionadmin_noticestrunk\includes\class-broadnet-sms-services.php:170
actionadmin_post_nds_form_responsetrunk\includes\class-broadnet-sms-services.php:172
actionwp_enqueue_scriptstrunk\includes\class-broadnet-sms-services.php:191
actionwp_enqueue_scriptstrunk\includes\class-broadnet-sms-services.php:192
actionwoocommerce_order_status_pendingtrunk\public\class-broadnet-sms-services-public.php:59
actionwoocommerce_order_status_processingtrunk\public\class-broadnet-sms-services-public.php:60
actionwoocommerce_order_status_on-holdtrunk\public\class-broadnet-sms-services-public.php:61
actionwoocommerce_order_status_completedtrunk\public\class-broadnet-sms-services-public.php:63
actionwoocommerce_order_status_cancelledtrunk\public\class-broadnet-sms-services-public.php:64
actionwoocommerce_order_status_refundedtrunk\public\class-broadnet-sms-services-public.php:65
filterwoocoomerce_sms_messagetrunk\public\class-broadnet-sms-services-public.php:67
Maintenance & Trust

Broadnet SMS Services Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedJan 4, 2024
PHP min version7.4
Downloads789

Community Trust

Rating0/100
Number of ratings0
Active installs0
Alternatives

Broadnet SMS Services Alternatives

No alternatives data available yet.

Developer Profile

Broadnet SMS Services Developer Profile

rabihz

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Broadnet SMS Services

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/broadnet-sms-services/css/broadnet-sms-services-admin.css/wp-content/plugins/broadnet-sms-services/js/broadnet-sms-services-admin.js
Version Parameters
broadnet-sms-services-admin.css?ver=broadnet-sms-services-admin.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Broadnet SMS Services