
gk-sms Security & Risk Analysis
wordpress.org/plugins/gk-smsTwilio Integration for WordPress
Is gk-sms Safe to Use in 2026?
Generally Safe
Score 85/100gk-sms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "gk-sms" plugin version 1.0.1 presents a significant security risk due to its substantial unprotected attack surface. All four identified AJAX handlers lack authentication checks, meaning any authenticated user could potentially trigger these actions, leading to unauthorized operations or data manipulation. Compounding this is the complete absence of output escaping for all identified outputs, creating a high likelihood of Cross-Site Scripting (XSS) vulnerabilities. While the plugin demonstrates good practices by using prepared statements for SQL queries and has no recorded vulnerability history, these strengths are overshadowed by the critical weaknesses in handling entry points and output sanitization.
The taint analysis reveals flows with unsanitized paths, which, although not categorized as critical or high severity in this specific analysis, strongly correlate with the lack of output escaping and the unprotected AJAX endpoints. This suggests a potential for malicious input to be processed and rendered in an unsafe manner. The plugin's vulnerability history being clean is positive, but it cannot be relied upon as a guarantee of future security, especially given the clear indicators of poor input handling and output sanitization within the current codebase.
In conclusion, while "gk-sms" v1.0.1 avoids common pitfalls like raw SQL queries and has no known CVEs, its security posture is severely compromised by the unprotected AJAX endpoints and the pervasive lack of output escaping. These issues create a direct pathway for common web attacks like XSS and potentially other vulnerabilities exploitable by authenticated users. Immediate attention is required to address these fundamental security flaws.
Key Concerns
- Unprotected AJAX handlers
- Unescaped output
- Unsanitized paths in taint flows
- Missing nonce checks on AJAX
- Missing capability checks on AJAX
gk-sms Security Vulnerabilities
gk-sms Code Analysis
Output Escaping
Data Flow Analysis
gk-sms Attack Surface
AJAX Handlers 4
WordPress Hooks 3
Maintenance & Trust
gk-sms Maintenance & Trust
Maintenance Signals
Community Trust
gk-sms Alternatives
SMS Abandoned Cart Recovery ✦ CartBoss
cartboss
Boost your sales by recovering abandoned carts with pre-prepared & translated text messages!
text message sms plugin
text-message
text message by biz text lets your website receive and send text messages. reply to text messages from a pc or forward messages to your mobile phone.
Text Message Contact Form
text-message-contact-form-biztext
Receive a Text or email, from your website through the Text Message Contact Form by Biz Text. SMS notification of email received, no third-party apps …
TextP2P Texting Widget
textp2p-texting-widget
Allow site visitors to contact your business the way most prefer, by Texting. Installing the TextP2P Texting Widget plugin into your WordPress site pr …
Texty – SMS Notification for WordPress, WooCommerce, Dokan and more
texty
Texty is a lightweight SMS notification plugin for WordPress.
gk-sms Developer Profile
2 plugins · 30 total installs
How We Detect gk-sms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gk-sms/lib/bootstrap/css/bootstrap.css/wp-content/plugins/gk-sms/css/gk-sms.css/wp-content/plugins/gk-sms/lib/bootstrap/js/bootstrap.min.js/wp-content/plugins/gk-sms/lib/jquery.limit-1.2.source.js/wp-content/plugins/gk-sms/js/gk-sms-options-page.js/wp-content/plugins/gk-sms/js/gk-sms-options-page.jsgk-sms/css/gk-sms.css?ver=gk-sms/js/gk-sms-options-page.js?ver=HTML / DOM Fingerprints
gk-sms-bootstrapdata-gk-sms-options-pagegk_sms_options_page/wp-json/gk-sms/v1/options