
EasySMS Security & Risk Analysis
wordpress.org/plugins/easysmsEasySMS provides an easy way for readers to subscribe to SMS updates and for admins to send SMS messages to groups. Auto SMS with post publishing.
Is EasySMS Safe to Use in 2026?
Generally Safe
Score 85/100EasySMS has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "easysms" plugin v2.0.7.2 presents a mixed security profile. On the positive side, the static analysis reveals a very small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events that could be directly exploited without authentication. Furthermore, there are no known CVEs associated with this plugin, and no critical or high severity taint flows were detected, suggesting a generally cautious development approach.
However, significant concerns arise from the code analysis regarding output escaping and SQL query handling. The fact that 0% of the 7 identified outputs are properly escaped is a major red flag, indicating a high likelihood of cross-site scripting (XSS) vulnerabilities. Additionally, only 25% of the SQL queries utilize prepared statements, leaving 75% potentially vulnerable to SQL injection attacks. The absence of nonce checks on any entry points, combined with only two capability checks, further weakens the plugin's defenses against unauthorized actions.
While the lack of historical vulnerabilities is encouraging, it doesn't negate the immediate risks identified in the current code. The plugin exhibits good practice in limiting its attack surface but falls short in fundamental security measures like output sanitization and secure database interaction. Therefore, despite a clean vulnerability history, the identified coding practices pose a substantial risk to users.
Key Concerns
- Output escaping is not used
- SQL queries are not consistently prepared
- No nonce checks on entry points
EasySMS Security Vulnerabilities
EasySMS Code Analysis
SQL Query Safety
Output Escaping
EasySMS Attack Surface
WordPress Hooks 9
Maintenance & Trust
EasySMS Maintenance & Trust
Maintenance Signals
Community Trust
EasySMS Alternatives
افزونه پیامک حرفه ای فراز اس ام اس
farazsms
شما می توانید با استفاده از افزونه فراز اس ام اس، سایت خود را با ابزاری خودکار برای ارسال پیامک و ذخیره شماره در دفترچه تلفن، تقویت کنید.
Abandoned cart SMS reminders and SMS campaigns – CartFox
cartfox
Dynamic SMS abandoned cart reminders with coupons, post-purchase campaigns and various options for SMS campaigns. Available for 58 languages worldwide …
Receive Notifications After Form Submitting – Form Notify for Any Forms
form-notify
⭐Description
Contact Group Button
contact-group-button
Add group contact phone, sms, facebook messages, zalo... to website. Display in desktop, laptop, table, phone and more.
Message Mate
message-mate
Message Mate lets customers text you from their phone or computer. Reply via email, text or dashboard.
EasySMS Developer Profile
2 plugins · 30 total installs
How We Detect EasySMS
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/easysms/css/easysms.css/wp-content/plugins/easysms/css/easysms_admin.css/wp-content/plugins/easysms/js/easysms.js/wp-content/plugins/easysms/js/easysms.jseasysms/style.css?ver=easysms/css/easysms.css?ver=easysms/css/easysms_admin.css?ver=easysms/js/easysms.js?ver=HTML / DOM Fingerprints
easysmsDiveasysms_widgetdata-easysms-settingseasysms<div id='easysmsDiv'><div class=