
ExpertTexting Official WordPress Plugin Security & Risk Analysis
wordpress.org/plugins/experttexting-officialExpertTexting official plugin for WordPress. Send notifications, alerts, and personalized messages using ExpertTexting's API.
Is ExpertTexting Official WordPress Plugin Safe to Use in 2026?
Generally Safe
Score 85/100ExpertTexting Official WordPress Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'experttexting-official' v1.2.0 plugin exhibits a generally strong security posture, with no recorded vulnerabilities or CVEs. The static analysis reveals good practices like a high percentage of prepared SQL statements and properly escaped output. The plugin also implements a reasonable number of nonce and capability checks for its entry points.
However, several areas warrant attention. The presence of `unserialize` is a significant concern, as it can lead to remote code execution if user-supplied data is unserialized without proper validation. Furthermore, the taint analysis indicates a high number of flows with unsanitized paths, with 8 flows identified as high severity. While these haven't manifested as critical issues or CVEs yet, they represent potential attack vectors that could be exploited in the future, especially in conjunction with the `unserialize` function.
Overall, the plugin's lack of historical vulnerabilities is a positive sign. Coupled with the strong emphasis on prepared statements and output escaping, this suggests a developer who understands fundamental security principles. Nevertheless, the identified risks, particularly the `unserialize` function and the high count of unsanitized taint flows, mean that the plugin is not entirely risk-free. Further scrutiny of these specific areas within the codebase is recommended.
Key Concerns
- Dangerous function unserialize found
- 8 high severity taint flows
- 11 unsanitized paths in taint flows
ExpertTexting Official WordPress Plugin Security Vulnerabilities
ExpertTexting Official WordPress Plugin Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
ExpertTexting Official WordPress Plugin Attack Surface
AJAX Handlers 4
Shortcodes 1
WordPress Hooks 82
Maintenance & Trust
ExpertTexting Official WordPress Plugin Maintenance & Trust
Maintenance Signals
Community Trust
ExpertTexting Official WordPress Plugin Alternatives
text message sms plugin
text-message
text message by biz text lets your website receive and send text messages. reply to text messages from a pc or forward messages to your mobile phone.
SMS send for Africa's Talking
sms-send-for-africas-talking
Send single or bulk SMS via Africa's Talking API with secure WordPress integration. Manage recipients and customize messages.
SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery
sms-alert
Send WooCommerce SMS notifications, OTP verification, abandoned cart recovery alerts, and real-time order updates to customers and admins.
افزونه پیامک حرفه ای فراز اس ام اس
farazsms
شما می توانید با استفاده از افزونه فراز اس ام اس، سایت خود را با ابزاری خودکار برای ارسال پیامک و ذخیره شماره در دفترچه تلفن، تقویت کنید.
NotifSMS – SMS Notifications OTP & 2FA for WordPress & WooCommerce
wp-twilio-core
Send SMS, OTP & 2FA notifications from WordPress via Twilio. Includes automated alerts, bulk messaging, and integrations with popular plugins.
ExpertTexting Official WordPress Plugin Developer Profile
1 plugin · 10 total installs
How We Detect ExpertTexting Official WordPress Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/experttexting-official/assets/et_style_admin.css/wp-content/plugins/experttexting-official/assets/et_script_admin.js/wp-content/plugins/experttexting-official/assets/chosen.css/wp-content/plugins/experttexting-official/assets/chosen.jquery.js/wp-content/plugins/experttexting-official/assets/et_style.css/wp-content/plugins/experttexting-official/assets/et_script.js/wp-content/plugins/experttexting-official/assets/bootstrap/bootstrap.et.css/wp-content/plugins/experttexting-official/assets/bootstrap/popper.min.js+4 more/wp-content/plugins/experttexting-official/assets/et_script_admin.js/wp-content/plugins/experttexting-official/assets/chosen.jquery.js/wp-content/plugins/experttexting-official/assets/et_script.js/wp-content/plugins/experttexting-official/assets/bootstrap/popper.min.js/wp-content/plugins/experttexting-official/assets/bootstrap/bootstrap.js/wp-content/plugins/experttexting-official/assets/intlTelInput.js+1 moreexperttexting-official/assets/et_style_admin.css?ver=experttexting-official/assets/et_script_admin.js?ver=experttexting-official/assets/chosen.css?ver=experttexting-official/assets/chosen.jquery.js?ver=experttexting-official/assets/et_style.css?ver=experttexting-official/assets/et_script.js?ver=experttexting-official/assets/bootstrap/bootstrap.et.css?ver=experttexting-official/assets/bootstrap/popper.min.js?ver=experttexting-official/assets/bootstrap/bootstrap.js?ver=experttexting-official/assets/intlTelInput.css?ver=experttexting-official/assets/intlTelInput.js?ver=experttexting-official/assets/et_intlTelInput.js?ver=HTML / DOM Fingerprints
exptxt-wrapperexptxt-form<!-- Admin Header -->data-country-codedata-phone-numberdata-country-code-placeholderdata-initial-countrydata-only-countriesdata-preferred-countries+2 more__expttxt_need_upgradeet_intl_tel_inputExptTxt__Expt_BaseControllerExptTxt\Expt_Base\Expt_ActivateExptTxt\Expt_Base\Expt_Deactivate+3 more