
CRSMS Contact Form 7 SMS Notification Security & Risk Analysis
wordpress.org/plugins/crsms-contact-form-7-sms-notificationWorks with the Contact Form 7 plugin to send SMS notifications when somebody submits your contact form, using the API Configured By Site Admin
Is CRSMS Contact Form 7 SMS Notification Safe to Use in 2026?
Generally Safe
Score 85/100CRSMS Contact Form 7 SMS Notification has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The crsms-contact-form-7-sms-notification v1.0.0 plugin presents a mixed security posture. While it demonstrates good practices by avoiding dangerous functions and SQL injection vulnerabilities through prepared statements, significant concerns arise from its attack surface and output escaping. The presence of two AJAX handlers without authentication checks is a critical weakness, potentially allowing unauthorized users to trigger plugin functionality. Furthermore, a substantial portion of output (60%) is not properly escaped, posing a risk of cross-site scripting (XSS) vulnerabilities. The lack of any recorded vulnerabilities in its history is a positive sign, suggesting a potentially stable codebase, but this cannot offset the immediate risks identified in the static analysis. The plugin's reliance on an external HTTP request also warrants careful monitoring, though the data doesn't specify its purpose or security implications.
Despite the absence of known CVEs, the identified lack of authentication on AJAX endpoints and insufficient output escaping creates clear opportunities for exploitation. The plugin's total entry points are all unprotected, which is a major red flag. Until these critical security gaps are addressed, the plugin should be considered a moderate to high risk for any WordPress installation. The strengths lie in its clean SQL handling and absence of historical vulnerabilities, but these are overshadowed by the direct threats from unprotected endpoints and potential XSS.
Key Concerns
- AJAX handlers without auth checks
- Unsanitized output (60%)
- No nonce checks on AJAX
- No capability checks on entry points
CRSMS Contact Form 7 SMS Notification Security Vulnerabilities
CRSMS Contact Form 7 SMS Notification Release Timeline
CRSMS Contact Form 7 SMS Notification Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
CRSMS Contact Form 7 SMS Notification Attack Surface
AJAX Handlers 2
WordPress Hooks 16
Maintenance & Trust
CRSMS Contact Form 7 SMS Notification Maintenance & Trust
Maintenance Signals
Community Trust
CRSMS Contact Form 7 SMS Notification Alternatives
WSMS (formerly WP SMS) – SMS & MMS Notifications with OTP and 2FA for WooCommerce
wp-sms
Send SMS/MMS notifications, OTP & 2FA messages, and WooCommerce updates with support for multiple gateways and plugin integrations.
miniOrange OTP Login, Verification and SMS Notifications
miniorange-otp-verification
OTP Verification via Email/SMS/WhatsApp,SMS Notifications for WooCommerce,OTP Login with Phone,PasswordLess Login.Custom Gateway for OTP Verification
SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery
sms-alert
Send WooCommerce SMS notifications, OTP verification, abandoned cart recovery alerts, and real-time order updates to customers and admins.
BulkGate SMS Plugin for WooCommerce
woosms-sms-module-for-woocommerce
SMS and Viber plugin for WooCommerce. Order status notifications, personalized Bulk SMS and Viber campaigns, 2-way messaging and admin alerts.
ShopMagic – Twilio SMS
shopmagic-for-twilio
Send WooCommerce SMS notifications, reminders, and text messages to your customers. The plugin is the ShopMagic add-on and it lets you send sms remind …
CRSMS Contact Form 7 SMS Notification Developer Profile
2 plugins · 20 total installs
How We Detect CRSMS Contact Form 7 SMS Notification
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/crsms-contact-form-7-sms-notification/css/style.css/wp-content/plugins/crsms-contact-form-7-sms-notification/js/script.js/wp-content/plugins/crsms-contact-form-7-sms-notification/js/select2.js/wp-content/plugins/crsms-contact-form-7-sms-notification/js/app.jscrsms-contact-form-7-sms-notification/css/style.css?ver=crsms-contact-form-7-sms-notification/js/script.js?ver=crsms-contact-form-7-sms-notification/js/select2.js?ver=crsms-contact-form-7-sms-notification/js/app.js?ver=HTML / DOM Fingerprints
cf7isi-optionsContact_FormSI_SLUG