
Gray SMS – Complete SMS Notificaitons for WordPress, Woocommerce & Multi Features Security & Risk Analysis
wordpress.org/plugins/gray-smsSend WooCommerce order notifications and individual SMS messages using Twilio, Vonage, Plivo, Clickatell and other SMS gateways.
Is Gray SMS – Complete SMS Notificaitons for WordPress, Woocommerce & Multi Features Safe to Use in 2026?
Generally Safe
Score 100/100Gray SMS – Complete SMS Notificaitons for WordPress, Woocommerce & Multi Features has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The gray-sms plugin v1.3.3 demonstrates a strong security posture based on the static analysis. The absence of any detectable attack surface, such as unprotected AJAX handlers, REST API routes, or shortcodes, is a significant strength. Furthermore, the code shows good practices in handling SQL queries, with 100% using prepared statements, and a high percentage of output escaping, which mitigates common injection vulnerabilities. The limited taint analysis revealing no unsanitized flows further supports a generally secure codebase.
However, there are a few areas that warrant attention. The plugin makes 12 external HTTP requests, which could be a potential vector for various attacks if not handled with proper validation and sanitization on the receiving end. The presence of only one nonce check for what might be a limited number of entry points is concerning, as is the complete absence of capability checks. This could allow unauthorized users to perform actions they shouldn't be able to, especially if any undocumented or future entry points are introduced. The lack of any recorded vulnerabilities in its history is positive, suggesting a history of secure development or diligent patching by maintainers, but it does not guarantee future security.
In conclusion, gray-sms v1.3.3 exhibits excellent foundational security practices, particularly in its handling of common web vulnerabilities like SQL injection and output escaping. The minimal attack surface is commendable. The primary concerns lie in the reliance on external HTTP requests without clear indication of sanitization on the other end, and the limited use of nonce and capability checks, which could leave the plugin vulnerable to privilege escalation or unauthorized actions. While its vulnerability history is clean, the observed code signals suggest a need for greater scrutiny on authorization mechanisms.
Key Concerns
- Limited nonce checks
- No capability checks
- Multiple external HTTP requests
Gray SMS – Complete SMS Notificaitons for WordPress, Woocommerce & Multi Features Security Vulnerabilities
Gray SMS – Complete SMS Notificaitons for WordPress, Woocommerce & Multi Features Release Timeline
Gray SMS – Complete SMS Notificaitons for WordPress, Woocommerce & Multi Features Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Gray SMS – Complete SMS Notificaitons for WordPress, Woocommerce & Multi Features Attack Surface
WordPress Hooks 10
Maintenance & Trust
Gray SMS – Complete SMS Notificaitons for WordPress, Woocommerce & Multi Features Maintenance & Trust
Maintenance Signals
Community Trust
Gray SMS – Complete SMS Notificaitons for WordPress, Woocommerce & Multi Features Alternatives
SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery
sms-alert
Send WooCommerce SMS notifications, OTP verification, abandoned cart recovery alerts, and real-time order updates to customers and admins.
افزونه پیامک حرفه ای فراز اس ام اس
farazsms
شما می توانید با استفاده از افزونه فراز اس ام اس، سایت خود را با ابزاری خودکار برای ارسال پیامک و ذخیره شماره در دفترچه تلفن، تقویت کنید.
NotifSMS – SMS Notifications OTP & 2FA for WordPress & WooCommerce
wp-twilio-core
Send SMS, OTP & 2FA notifications from WordPress via Twilio. Includes automated alerts, bulk messaging, and integrations with popular plugins.
Alpha SMS
alpha-sms
Connect your WordPress and WooCommerce store to Alpha SMS for OTP verification and order notifications in Bangladesh.
Khudebarta SMS Gateway – SMS Campaing, OTP Login & Order Notification for WooCommerce
kb-sms-gateway
Send SMS order notifications via SMS Gateway for Khudebarta in WooCommerce.
Gray SMS – Complete SMS Notificaitons for WordPress, Woocommerce & Multi Features Developer Profile
3 plugins · 10 total installs
How We Detect Gray SMS – Complete SMS Notificaitons for WordPress, Woocommerce & Multi Features
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gray-sms/assets/gr-admin/gr-admin-settings.css/wp-content/plugins/gray-sms/assets/gr-admin/gr-admin-settings.js/wp-content/plugins/gray-sms/assets/gr-front/gr-front.css/wp-content/plugins/gray-sms/assets/gr-admin/gr-admin-settings.jsgray-sms/assets/gr-admin/gr-admin-settings.css?ver=gray-sms/assets/gr-admin/gr-admin-settings.js?ver=gray-sms/assets/gr-front/gr-front.css?ver=