
FraudLabs Pro SMS Verification Security & Risk Analysis
wordpress.org/plugins/fraudlabs-pro-sms-verificationDescription: SMS verification help merchants to authenticate the client's phone number via SMS verification to prevent fraudulent orders.
Is FraudLabs Pro SMS Verification Safe to Use in 2026?
Generally Safe
Score 99/100FraudLabs Pro SMS Verification has a strong security track record. Known vulnerabilities have been patched promptly.
The "fraudlabs-pro-sms-verification" plugin version 1.11.4 exhibits a mixed security posture. While it demonstrates good practices by exclusively using prepared statements for SQL queries and has no known critical or high-severity vulnerabilities, several concerning patterns emerge from the static analysis. A significant portion of the plugin's attack surface, specifically 10 out of 13 AJAX handlers, lacks authentication checks. This is further compounded by the presence of 9 flows with unsanitized paths, indicating a potential for injection vulnerabilities if these paths are user-controllable. Although no critical or high-severity taint flows were detected, the high number of unsanitized paths is a notable concern. The plugin's vulnerability history shows a past medium-severity CSRF vulnerability, suggesting a need for continued vigilance regarding input validation and access control, especially given the unprotected AJAX endpoints. Overall, the plugin benefits from secure database interaction but requires immediate attention to its exposed AJAX endpoints and the identified unsanitized code paths to mitigate potential security risks.
Key Concerns
- Unprotected AJAX handlers
- Flows with unsanitized paths
- Low output escaping percentage
- Medium severity vulnerability history
FraudLabs Pro SMS Verification Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
FraudLabs Pro SMS Verification <= 1.10.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting
FraudLabs Pro SMS Verification Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
FraudLabs Pro SMS Verification Attack Surface
AJAX Handlers 13
Shortcodes 3
WordPress Hooks 20
Maintenance & Trust
FraudLabs Pro SMS Verification Maintenance & Trust
Maintenance Signals
Community Trust
FraudLabs Pro SMS Verification Alternatives
TextMe SMS
textme-sms-integration
Send custom SMS messages from your WordPress site to your customers using the TextMe SMS gateway.
eSMS
esms-gui-tin-nhan-sms
eSMS - là plugin dành riêng cho khách hàng sử dụng dịch vụ của eSMS, giúp quý khách gửi tin nhắn vào số điện thoại của khách hàng khi sử dụng Contact …
Contact Form 7 OTP SMS Verification
cf7-otp-sms-verification
SMS API: Buy Sms On All Bulk SMS
G Online SMS
g-online-sms
Send automated SMS notifications from WordPress — user registration, WooCommerce orders, Contact Form 7, Gravity Forms and more.
Sendit Israel
sendit-israel
Sendit Israel provides a simple SMS integration for WordPress and WooCommerce. Supports order status SMS notifications and Contact Form 7 submissions.
FraudLabs Pro SMS Verification Developer Profile
3 plugins · 1K total installs
How We Detect FraudLabs Pro SMS Verification
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/fraudlabs-pro-sms-verification/assets/css/style.css/wp-content/plugins/fraudlabs-pro-sms-verification/assets/js/script.js/wp-content/plugins/fraudlabs-pro-sms-verification/assets/js/frontend.js/wp-content/plugins/fraudlabs-pro-sms-verification/assets/js/admin.js/wp-content/plugins/fraudlabs-pro-sms-verification/assets/js/script.js/wp-content/plugins/fraudlabs-pro-sms-verification/assets/js/frontend.js/wp-content/plugins/fraudlabs-pro-sms-verification/assets/js/admin.jsfraudlabs-pro-sms-verification/assets/css/style.css?ver=fraudlabs-pro-sms-verification/assets/js/script.js?ver=fraudlabs-pro-sms-verification/assets/js/frontend.js?ver=fraudlabs-pro-sms-verification/assets/js/admin.js?ver=HTML / DOM Fingerprints
fraudlabs-pro-sms-verification-wrapperfraudlabs-pro-sms-verification-buttonfraudlabs-pro-sms-verification-form<!-- SMS Verification Form Start --><!-- SMS Verification Form End --><!-- FraudLabs Pro SMS Verification Admin Footer Text -->data-flp-sms-verification-api-keydata-flp-sms-verification-noncefraudlabs_pro_sms_verification_params/wp-json/fraudlabs-pro-sms-verification/v1/send_otp/wp-json/fraudlabs-pro-sms-verification/v1/verify_otp[flp_sms_verification][flp-sms-verification-edd]