
GatewayAPI Security & Risk Analysis
wordpress.org/plugins/gatewayapiSend SMS notifications for WooCommerce orders, create SMS campaigns, manage contacts, and add two-factor authentication - powered by GatewayAPI.com.
Is GatewayAPI Safe to Use in 2026?
Generally Safe
Score 100/100GatewayAPI has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The gatewayapi plugin v2.1.4 exhibits a mixed security posture. On the positive side, it has no known vulnerabilities (CVEs) and a low number of potentially dangerous functions or critical taint flows. The high percentage of properly escaped output is also a good sign, suggesting developers are mindful of preventing cross-site scripting (XSS). The plugin also demonstrates a reasonable number of capability checks, indicating some level of access control is implemented.
However, significant concerns arise from the attack surface analysis. With 47 total entry points, a staggering 42 are unprotected AJAX handlers. This represents a substantial risk, as attackers could potentially interact with these handlers without proper authentication or authorization, leading to unintended actions or information disclosure. Furthermore, the single SQL query detected is not using prepared statements, which opens the door to SQL injection vulnerabilities. The presence of unsanitized paths in taint analysis, though not critical, warrants attention as it could be a precursor to path traversal issues if combined with other vulnerabilities.
Given the lack of historical vulnerabilities, it might suggest a diligent development process or that the plugin has not been a significant target. However, the current code analysis reveals critical weaknesses that could be exploited regardless of past vulnerability history. The high number of unprotected AJAX handlers and the non-prepared SQL query are the most pressing issues, creating a substantial attack surface that requires immediate attention.
Key Concerns
- Large attack surface without auth
- Raw SQL without prepare
- Flows with unsanitized paths
- Missing nonce checks on AJAX
GatewayAPI Security Vulnerabilities
GatewayAPI Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
GatewayAPI Attack Surface
AJAX Handlers 45
Shortcodes 2
WordPress Hooks 17
Maintenance & Trust
GatewayAPI Maintenance & Trust
Maintenance Signals
Community Trust
GatewayAPI Alternatives
WSMS (formerly WP SMS) – SMS & MMS Notifications with OTP and 2FA for WooCommerce
wp-sms
Send SMS/MMS notifications, OTP & 2FA messages, and WooCommerce updates with support for multiple gateways and plugin integrations.
NotifSMS – SMS Notifications OTP & 2FA for WordPress & WooCommerce
wp-twilio-core
Send SMS, OTP & 2FA notifications from WordPress via Twilio. Includes automated alerts, bulk messaging, and integrations with popular plugins.
ShopMagic – Twilio SMS
shopmagic-for-twilio
Send WooCommerce SMS notifications, reminders, and text messages to your customers. The plugin is the ShopMagic add-on and it lets you send sms remind …
Ultimate WP Mail
ultimate-wp-mail
Custom email and SMS notifications. Automatic send actions. WPForms SMS integration. WooCommerce notifications for purchases, abandoned cart and more!
TextMe SMS
textme-sms-integration
Send custom SMS messages from your WordPress site to your customers using the TextMe SMS gateway.
GatewayAPI Developer Profile
1 plugin · 400 total installs
How We Detect GatewayAPI
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gatewayapi/assets/css/gatewayapi.css/wp-content/plugins/gatewayapi/assets/js/gatewayapi.js/wp-content/plugins/gatewayapi/assets/js/gatewayapi.jsgatewayapi.css?ver=gatewayapi.js?ver=HTML / DOM Fingerprints
gatewayapi-control-wrappergatewayapi-field-gatewayapi-errorgatewayapi-help-textgatewayapi-recaptchagatewayapi-tagsgatewayapi-labelgatewayapi-checkboxes+1 more<!-- gwapi_template -->data-sitekeyaria-invalidaria-describedbydata-gwapi-form-iddata-gwapi-next-stepdata-gwapi-previous-stepgatewayapi/wp-json/gatewayapi/v1/sms-message/wp-json/gatewayapi/v1/sms-bulk-send<div class="gatewayapi-control-wrapper gatewayapi-field-<div class="g-recaptcha"<div class="gatewayapi-control-wrapper gatewayapi-tags"><div class="gatewayapi-checkbox">