cloudrebuesms Security & Risk Analysis

wordpress.org/plugins/cloud-rebue-wpsms

Send Woocomerce Notifications, Access Bulk SMS Portal

10 active installs v1.0.9 PHP 7.0+ WP 5.6.0+ Updated Nov 10, 2023
cloud-rebuemobilesecuritysmswoocommerce-sms
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is cloudrebuesms Safe to Use in 2026?

Generally Safe

Score 85/100

cloudrebuesms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The "cloud-rebue-wpsms" v1.0.9 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by avoiding dangerous functions and using prepared statements for all SQL queries. There is also a history of no known vulnerabilities, which is a strong indicator of prior good security development. However, a significant concern arises from its attack surface. With a total of 4 entry points, 3 of which (all AJAX handlers) lack authentication checks, this plugin presents a considerable risk. While nonce checks and capability checks are present, their absence on a majority of the AJAX entry points means that any authenticated user could potentially trigger these actions. The moderate rate of proper output escaping (45%) also suggests a potential for cross-site scripting (XSS) vulnerabilities, though the taint analysis did not reveal any immediate exploitable flows. The lack of any recorded vulnerabilities in its history could be a sign of a well-maintained plugin or a lack of focused security auditing in the past. The primary risk lies in the unprotected AJAX endpoints, which could be exploited if further input validation and sanitization are insufficient. A strong emphasis on securing these entry points is crucial.

Key Concerns

  • AJAX handlers without auth checks
  • Low percentage of properly escaped output
Vulnerabilities
None known

cloudrebuesms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

cloudrebuesms Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
46
37 escaped
Nonce Checks
1
Capability Checks
2
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

45% escaped83 total outputs
Attack Surface
3 unprotected

cloudrebuesms Attack Surface

Entry Points4
Unprotected3

AJAX Handlers 3

noprivwp_ajax_cgsms_security_add_phoneinc\security_two_factor.php:669
noprivwp_ajax_cgsms_security_confirm_phoneinc\security_two_factor.php:670
noprivwp_ajax_cgsms_security_confirm_logininc\security_two_factor.php:671

Shortcodes 1

[crsms] inc\shortcode.php:24
WordPress Hooks 23
filtersafe_style_csscloudrebuesms-utility.php:169
filtersafe_style_csscloudrebuesms-utility.php:378
filterplugin_row_metacloudrebuesms.php:44
filteradmin_footer_textcloudrebuesms.php:45
actionadmin_enqueue_scriptscloudrebuesms.php:47
actioninitcloudrebuesms.php:165
actionadmin_menucloudrebuesms.php:170
actionadmin_menucloudrebuesms.php:184
actionadmin_initcloudrebuesms.php:186
actionwoocommerce_order_status_changedcloudrebuesms.php:282
actionwoocommerce_new_ordercloudrebuesms.php:284
actionwoocommerce_payment_completecloudrebuesms.php:301
actionlogin_enqueue_scriptsinc\security_two_factor.php:268
actionlogin_forminc\security_two_factor.php:304
filtercgsms_throttle_errorinc\security_two_factor.php:425
filtercgsms_confirm_phone_form_idinc\security_two_factor.php:524
filtercgsms_throttle_errorinc\security_two_factor.php:553
actionwp_logininc\security_two_factor.php:668
actionlogin_form_gwb2fainc\security_two_factor.php:674
filteruser_contactmethodsinc\security_two_factor.php:677
filteradmin_enqueue_scriptsinc\security_two_factor.php:678
actionadmin_post_cgsms_profile_change_phoneinc\security_two_factor.php:679
actionlogin_form_gwb2fa_resetinc\security_two_factor.php:680
Maintenance & Trust

cloudrebuesms Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedNov 10, 2023
PHP min version7.0
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

cloudrebuesms Developer Profile

cloudrebue

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect cloudrebuesms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cloud-rebue-wpsms/css/style.css/wp-content/plugins/cloud-rebue-wpsms/js/script.js
Script Paths
/wp-content/plugins/cloud-rebue-wpsms/js/script.js
Version Parameters
cloud-rebue-wpsms/style.css?ver=cloud-rebue-wpsms/script.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about cloudrebuesms