
eSMS Security & Risk Analysis
wordpress.org/plugins/esms-gui-tin-nhan-smseSMS - là plugin dành riêng cho khách hàng sử dụng dịch vụ của eSMS, giúp quý khách gửi tin nhắn vào số điện thoại của khách hàng khi sử dụng Contact …
Is eSMS Safe to Use in 2026?
Generally Safe
Score 85/100eSMS has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "esms-gui-tin-nhan-sms" plugin v1.0.2 exhibits a generally positive security posture based on the static analysis, with no critical or high severity code signals detected. The absence of dangerous functions, raw SQL queries, file operations, and a limited attack surface are strong indicators of good development practices. The high percentage of properly escaped output also suggests an effort to prevent cross-site scripting vulnerabilities. Furthermore, the lack of any recorded vulnerabilities in its history is a very encouraging sign, implying the plugin has been developed with security in mind or has been relatively free from exploitable flaws.
However, there are a few areas that warrant attention. The presence of external HTTP requests, while not inherently a vulnerability, could be a potential vector for issues if the external services are compromised or if data is transmitted insecurely. The complete absence of nonce checks and capability checks, especially given the external HTTP requests, is a concern. While the attack surface is currently reported as zero, future additions or changes to the plugin could introduce risks if these fundamental security checks are not implemented. The fact that taint analysis yielded no flows might be due to the limited scope of the analysis or a genuine lack of complex data flows, but it's important to acknowledge that zero taint flows do not guarantee absolute security against all possible injection vulnerabilities.
In conclusion, "esms-gui-tin-nhan-sms" v1.0.2 appears to be a relatively secure plugin, with strengths in its lack of known vulnerabilities, absence of dangerous code patterns, and good output escaping. The primary weaknesses lie in the missing nonce and capability checks, and the presence of external HTTP requests which, if not handled with extreme care, could introduce subtle risks. Continued vigilance and careful development are recommended.
Key Concerns
- No capability checks found
- No nonce checks found
- External HTTP requests present
eSMS Security Vulnerabilities
eSMS Code Analysis
Output Escaping
eSMS Attack Surface
WordPress Hooks 11
Maintenance & Trust
eSMS Maintenance & Trust
Maintenance Signals
Community Trust
eSMS Alternatives
VHT SMS
vht-sms
VHT SMS - là plugin dành riêng cho khách hàng sử dụng dịch vụ của VHT, giúp quý khách gửi tin nhắn vào số điện thoại của khách hàng khi sử dụng Contac …
MDSCO SMS
mdsco-sms
MDSCO SMS - là plugin dành riêng cho khách hàng sử dụng dịch vụ của MDSCO, giúp quý khách gửi tin nhắn vào số điện thoại của khách hàng khi sử dụng Co …
WSMS (formerly WP SMS) – SMS & MMS Notifications with OTP and 2FA for WooCommerce
wp-sms
Send SMS/MMS notifications, OTP & 2FA messages, and WooCommerce updates with support for multiple gateways and plugin integrations.
SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery
sms-alert
Send WooCommerce SMS notifications, OTP verification, abandoned cart recovery alerts, and real-time order updates to customers and admins.
افزونه پیامک حرفه ای فراز اس ام اس
farazsms
شما می توانید با استفاده از افزونه فراز اس ام اس، سایت خود را با ابزاری خودکار برای ارسال پیامک و ذخیره شماره در دفترچه تلفن، تقویت کنید.
eSMS Developer Profile
8 plugins · 44K total installs
How We Detect eSMS
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/esms-gui-tin-nhan-sms/assets/css/admin-style.css/wp-content/plugins/esms-gui-tin-nhan-sms/assets/js/admin-script.js/wp-content/plugins/esms-gui-tin-nhan-sms/assets/js/woo-script.jsesms-gui-tin-nhan-sms/assets/css/admin-style.css?ver=esms-gui-tin-nhan-sms/assets/js/admin-script.js?ver=esms-gui-tin-nhan-sms/assets/js/woo-script.js?ver=HTML / DOM Fingerprints
esms-api-key-wrapesms-secret-key-wrapesms-mess-content-wrapesms-cf7-id-wrapesms-sms-type-wrapesms-brandname-wrapesms-enable-woo-wrapesms-woo-status-wrapdata-esms-prefixesms_data