
Khudebarta SMS Gateway – SMS Campaing, OTP Login & Order Notification for WooCommerce Security & Risk Analysis
wordpress.org/plugins/kb-sms-gatewaySend SMS order notifications via SMS Gateway for Khudebarta in WooCommerce.
Is Khudebarta SMS Gateway – SMS Campaing, OTP Login & Order Notification for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100Khudebarta SMS Gateway – SMS Campaing, OTP Login & Order Notification for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The kb-sms-gateway plugin version 1.5 demonstrates a generally good security posture based on the provided static analysis. The plugin utilizes prepared statements for its SQL queries and has a very high rate of properly escaped output, mitigating common web vulnerabilities. The absence of dangerous functions, file operations, and critical taint flows further reinforces this positive outlook. Furthermore, the lack of any recorded vulnerabilities in its history suggests a commitment to secure development or a lack of targeting by attackers.
However, there are areas that warrant attention. The plugin has zero capability checks implemented across all identified entry points, including its single shortcode. This means any user, regardless of their role, could potentially interact with the plugin's functionality, which could lead to unintended consequences if not properly secured at the application level. While the static analysis did not reveal any direct critical or high severity issues, the absence of capability checks represents a potential weakness that could be exploited in conjunction with other factors or if the plugin's internal logic is complex.
In conclusion, kb-sms-gateway v1.5 is relatively well-secured, excelling in areas like SQL sanitization and output escaping, and boasting a clean vulnerability history. The primary concern is the complete lack of capability checks on its entry points, which, while not a direct vulnerability in this analysis, introduces a significant risk of unauthorized access or manipulation if not addressed. The presence of external HTTP requests also suggests a need for vigilance regarding the security of those external services.
Key Concerns
- No capability checks on entry points
Khudebarta SMS Gateway – SMS Campaing, OTP Login & Order Notification for WooCommerce Security Vulnerabilities
Khudebarta SMS Gateway – SMS Campaing, OTP Login & Order Notification for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Khudebarta SMS Gateway – SMS Campaing, OTP Login & Order Notification for WooCommerce Attack Surface
Shortcodes 1
WordPress Hooks 14
Maintenance & Trust
Khudebarta SMS Gateway – SMS Campaing, OTP Login & Order Notification for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Khudebarta SMS Gateway – SMS Campaing, OTP Login & Order Notification for WooCommerce Alternatives
SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery
sms-alert
Send WooCommerce SMS notifications, OTP verification, abandoned cart recovery alerts, and real-time order updates to customers and admins.
افزونه پیامک حرفه ای فراز اس ام اس
farazsms
شما می توانید با استفاده از افزونه فراز اس ام اس، سایت خود را با ابزاری خودکار برای ارسال پیامک و ذخیره شماره در دفترچه تلفن، تقویت کنید.
NotifSMS – SMS Notifications OTP & 2FA for WordPress & WooCommerce
wp-twilio-core
Send SMS, OTP & 2FA notifications from WordPress via Twilio. Includes automated alerts, bulk messaging, and integrations with popular plugins.
SMSQ Notifications for WooCommerce
smsq-notifications-for-woocommerce
Add to your WooCommerce store SMS notifications to your customers when order status changed.
ExpertTexting Official WordPress Plugin
experttexting-official
ExpertTexting official plugin for WordPress. Send notifications, alerts, and personalized messages using ExpertTexting's API.
Khudebarta SMS Gateway – SMS Campaing, OTP Login & Order Notification for WooCommerce Developer Profile
3 plugins · 10 total installs
How We Detect Khudebarta SMS Gateway – SMS Campaing, OTP Login & Order Notification for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/kb-sms-gateway/assets/kb-admin/kb-admin-settings.css/wp-content/plugins/kb-sms-gateway/assets/kb-admin/kd-admin-settings/wp-content/plugins/kb-sms-gateway/assets/kb-front/kb-front.csskb-sms-gateway/assets/kb-admin/kb-admin-settings.css?ver=1.0kb-sms-gateway/assets/kb-admin/kd-admin-settings?ver=1.0kb-sms-gateway/assets/kb-front/kb-front.css?ver=1.0HTML / DOM Fingerprints
kb-login-wrapperkb-login-wrapper__columnkb-login-wrapper__loginkb-login-formkb-login-form__titlekb-login-form__fieldskb-login-form__groupkb-login-form__forget+4 morename="kbsgp_login_username"name="kbsgp_login_pass"name="kbsgp_email_login_submit"name="kbsgp_login_otp_action"name="kbsgp_login_otp_nonce"name="kbsgp_enter_OTP"+8 more<div class="kb-login-wrapper">