eSMS - là plugin dành riêng cho khách hàng sử dụng dịch vụ của eSMS, giúp quý khách gửi tin nhắn vào số điện thoại của khách hàng khi sử dụng Contact …

50 active installs v1.0.2 PHP + WP 3.0+ Updated Jun 22, 2022
esmssmssms-for-contact-form-7sms-for-ninjaformwoocommerce-sms
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is eSMS Safe to Use in 2026?

Generally Safe

Score 85/100

eSMS has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "esms-gui-tin-nhan-sms" plugin v1.0.2 exhibits a generally positive security posture based on the static analysis, with no critical or high severity code signals detected. The absence of dangerous functions, raw SQL queries, file operations, and a limited attack surface are strong indicators of good development practices. The high percentage of properly escaped output also suggests an effort to prevent cross-site scripting vulnerabilities. Furthermore, the lack of any recorded vulnerabilities in its history is a very encouraging sign, implying the plugin has been developed with security in mind or has been relatively free from exploitable flaws.

However, there are a few areas that warrant attention. The presence of external HTTP requests, while not inherently a vulnerability, could be a potential vector for issues if the external services are compromised or if data is transmitted insecurely. The complete absence of nonce checks and capability checks, especially given the external HTTP requests, is a concern. While the attack surface is currently reported as zero, future additions or changes to the plugin could introduce risks if these fundamental security checks are not implemented. The fact that taint analysis yielded no flows might be due to the limited scope of the analysis or a genuine lack of complex data flows, but it's important to acknowledge that zero taint flows do not guarantee absolute security against all possible injection vulnerabilities.

In conclusion, "esms-gui-tin-nhan-sms" v1.0.2 appears to be a relatively secure plugin, with strengths in its lack of known vulnerabilities, absence of dangerous code patterns, and good output escaping. The primary weaknesses lie in the missing nonce and capability checks, and the presence of external HTTP requests which, if not handled with extreme care, could introduce subtle risks. Continued vigilance and careful development are recommended.

Key Concerns

  • No capability checks found
  • No nonce checks found
  • External HTTP requests present
Vulnerabilities
None known

eSMS Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

eSMS Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
125 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

94% escaped133 total outputs
Attack Surface

eSMS Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionplugins_loadedesms.php:77
actionadmin_menuesms.php:81
actionadmin_initesms.php:82
actionwpcf7_mail_sentesms.php:84
actionninja_forms_after_submissionesms.php:86
actionninja_forms_post_processesms.php:88
actionadmin_enqueue_scriptsesms.php:91
actionwoocommerce_checkout_processesms.php:95
actionwoocommerce_created_customeresms.php:97
actionwoocommerce_new_orderesms.php:103
actionwoocommerce_order_status_changedesms.php:113
Maintenance & Trust

eSMS Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedJun 22, 2022
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs50
Developer Profile

eSMS Developer Profile

Le Van Toan

8 plugins · 44K total installs

84
trust score
Avg Security Score
94/100
Avg Patch Time
85 days
View full developer profile
Detection Fingerprints

How We Detect eSMS

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/esms-gui-tin-nhan-sms/assets/css/admin-style.css/wp-content/plugins/esms-gui-tin-nhan-sms/assets/js/admin-script.js/wp-content/plugins/esms-gui-tin-nhan-sms/assets/js/woo-script.js
Version Parameters
esms-gui-tin-nhan-sms/assets/css/admin-style.css?ver=esms-gui-tin-nhan-sms/assets/js/admin-script.js?ver=esms-gui-tin-nhan-sms/assets/js/woo-script.js?ver=

HTML / DOM Fingerprints

CSS Classes
esms-api-key-wrapesms-secret-key-wrapesms-mess-content-wrapesms-cf7-id-wrapesms-sms-type-wrapesms-brandname-wrapesms-enable-woo-wrapesms-woo-status-wrap
Data Attributes
data-esms-prefix
JS Globals
esms_data
FAQ

Frequently Asked Questions about eSMS