
Citrasms Woocommerce SMS Notification Security & Risk Analysis
wordpress.org/plugins/citrasms-woocommerce-sms-notificationCitrasms Woocommerce SMS Notification send SMS notifications automatically for orders received at WooCommerce
Is Citrasms Woocommerce SMS Notification Safe to Use in 2026?
Generally Safe
Score 85/100Citrasms Woocommerce SMS Notification has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "citrasms-woocommerce-sms-notification" plugin v1.9 exhibits a mixed security posture. On the positive side, it shows good practices by not utilizing dangerous functions, all SQL queries are properly prepared, and there are no known historical vulnerabilities. The taint analysis also yielded no concerning flows, indicating a lack of immediately exploitable cross-site scripting or remote code execution vectors through tainted input.
However, significant concerns arise from the static analysis. The plugin exposes one AJAX handler without any authentication checks, creating a direct attack vector. Furthermore, only a very small percentage (7%) of output is properly escaped, suggesting a high risk of cross-site scripting vulnerabilities where user-supplied data could be rendered on a page without sufficient sanitization. The plugin also makes an external HTTP request, which could be a vector for information leakage or man-in-the-middle attacks if not handled securely.
While the absence of vulnerability history is a positive sign, it doesn't negate the risks identified in the current code. The combination of an unprotected AJAX endpoint and widespread output escaping deficiencies presents a substantial security risk that requires immediate attention. The plugin's strengths lie in its SQL handling and lack of historical issues, but these are overshadowed by the immediate exploitable weaknesses.
Key Concerns
- AJAX handler without auth checks
- Low output escaping rate
- External HTTP request
Citrasms Woocommerce SMS Notification Security Vulnerabilities
Citrasms Woocommerce SMS Notification Release Timeline
Citrasms Woocommerce SMS Notification Code Analysis
Output Escaping
Citrasms Woocommerce SMS Notification Attack Surface
AJAX Handlers 1
WordPress Hooks 14
Maintenance & Trust
Citrasms Woocommerce SMS Notification Maintenance & Trust
Maintenance Signals
Community Trust
Citrasms Woocommerce SMS Notification Alternatives
Order SMS Notification – WooCommerce
order-sms-notification-woocommerce
A plugin for sending SMS notification after placing orders using WooCommerce
Branded SMS
branded-sms
Add to your WooCommerce store SMS notifications to your customers when order status changed.
افزونه پیامک حرفه ای فراز اس ام اس
farazsms
شما می توانید با استفاده از افزونه فراز اس ام اس، سایت خود را با ابزاری خودکار برای ارسال پیامک و ذخیره شماره در دفترچه تلفن، تقویت کنید.
miniOrange OTP Verification and SMS Notification for WooCommerce
miniorange-sms-order-notification-otp-verification
OTP Verification via SMS, Email,or WhatsApp, and SMS Order Notifications, Vendor Notifications for WooCommerce.OTP Login and registration with Phone →
Order SMS For WooCommerce
order-sms-for-woocommerce
Send WooCommerce order SMS notifications and custom SMS messages using popular SMS gateways.
Citrasms Woocommerce SMS Notification Developer Profile
1 plugin · 0 total installs
How We Detect Citrasms Woocommerce SMS Notification
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/citrasms-woocommerce-sms-notification/assets/css/admin.css/wp-content/plugins/citrasms-woocommerce-sms-notification/assets/js/admin.js/wp-content/plugins/citrasms-woocommerce-sms-notification/assets/js/admin.jscitrasms-woocommerce-sms-notification/assets/css/admin.css?ver=citrasms-woocommerce-sms-notification/assets/js/admin.js?ver=HTML / DOM Fingerprints
buyer-sms-notifycitrasms