Gray SMS – Complete SMS Notificaitons for WordPress, Woocommerce & Multi Features Security & Risk Analysis

wordpress.org/plugins/gray-sms

Send WooCommerce order notifications and individual SMS messages using Twilio, Vonage, Plivo, Clickatell and other SMS gateways.

0 active installs v1.3.3 PHP 7.4+ WP 6.4+ Updated Mar 15, 2026
order-sms-notificationsms-gatewaysms-plugintwilio-smswoocommerce-sms
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Gray SMS – Complete SMS Notificaitons for WordPress, Woocommerce & Multi Features Safe to Use in 2026?

Generally Safe

Score 100/100

Gray SMS – Complete SMS Notificaitons for WordPress, Woocommerce & Multi Features has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The gray-sms plugin v1.3.3 demonstrates a strong security posture based on the static analysis. The absence of any detectable attack surface, such as unprotected AJAX handlers, REST API routes, or shortcodes, is a significant strength. Furthermore, the code shows good practices in handling SQL queries, with 100% using prepared statements, and a high percentage of output escaping, which mitigates common injection vulnerabilities. The limited taint analysis revealing no unsanitized flows further supports a generally secure codebase.

However, there are a few areas that warrant attention. The plugin makes 12 external HTTP requests, which could be a potential vector for various attacks if not handled with proper validation and sanitization on the receiving end. The presence of only one nonce check for what might be a limited number of entry points is concerning, as is the complete absence of capability checks. This could allow unauthorized users to perform actions they shouldn't be able to, especially if any undocumented or future entry points are introduced. The lack of any recorded vulnerabilities in its history is positive, suggesting a history of secure development or diligent patching by maintainers, but it does not guarantee future security.

In conclusion, gray-sms v1.3.3 exhibits excellent foundational security practices, particularly in its handling of common web vulnerabilities like SQL injection and output escaping. The minimal attack surface is commendable. The primary concerns lie in the reliance on external HTTP requests without clear indication of sanitization on the other end, and the limited use of nonce and capability checks, which could leave the plugin vulnerable to privilege escalation or unauthorized actions. While its vulnerability history is clean, the observed code signals suggest a need for greater scrutiny on authorization mechanisms.

Key Concerns

  • Limited nonce checks
  • No capability checks
  • Multiple external HTTP requests
Vulnerabilities
None known

Gray SMS – Complete SMS Notificaitons for WordPress, Woocommerce & Multi Features Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Gray SMS – Complete SMS Notificaitons for WordPress, Woocommerce & Multi Features Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

Gray SMS – Complete SMS Notificaitons for WordPress, Woocommerce & Multi Features Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
2
121 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
12
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

98% escaped123 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
<gr-admin-nav> (includes\gr-admin-tab\gr-admin-nav.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Gray SMS – Complete SMS Notificaitons for WordPress, Woocommerce & Multi Features Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actionadmin_menuincludes\gr-admin-settings.php:13
actionadmin_initincludes\gr-admin-settings.php:20
actionadmin_initincludes\gr-admin-settings.php:87
actionadmin_enqueue_scriptsincludes\gr-assets-file.php:13
actionwp_enqueue_scriptsincludes\gr-assets-file.php:20
actionwoocommerce_order_status_processingincludes\gr-woow-settings.php:14
actionwoocommerce_order_status_completedincludes\gr-woow-settings.php:15
actionwoocommerce_order_status_cancelledincludes\gr-woow-settings.php:16
actionwoocommerce_order_status_refundedincludes\gr-woow-settings.php:17
actionwoocommerce_order_status_on-holdincludes\gr-woow-settings.php:18
Maintenance & Trust

Gray SMS – Complete SMS Notificaitons for WordPress, Woocommerce & Multi Features Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 15, 2026
PHP min version7.4
Downloads227

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Gray SMS – Complete SMS Notificaitons for WordPress, Woocommerce & Multi Features Developer Profile

graywp

3 plugins · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Gray SMS – Complete SMS Notificaitons for WordPress, Woocommerce & Multi Features

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gray-sms/assets/gr-admin/gr-admin-settings.css/wp-content/plugins/gray-sms/assets/gr-admin/gr-admin-settings.js/wp-content/plugins/gray-sms/assets/gr-front/gr-front.css
Script Paths
/wp-content/plugins/gray-sms/assets/gr-admin/gr-admin-settings.js
Version Parameters
gray-sms/assets/gr-admin/gr-admin-settings.css?ver=gray-sms/assets/gr-admin/gr-admin-settings.js?ver=gray-sms/assets/gr-front/gr-front.css?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Gray SMS – Complete SMS Notificaitons for WordPress, Woocommerce & Multi Features