Khudebarta SMS Gateway – SMS Campaing, OTP Login & Order Notification for WooCommerce Security & Risk Analysis

wordpress.org/plugins/kb-sms-gateway

Send SMS order notifications via SMS Gateway for Khudebarta in WooCommerce.

10 active installs v1.5 PHP 7.4+ WP 6.8+ Updated Aug 13, 2025
bangladesh-sms-gatewaybulk-sms-gatewaysms-bangladeshsms-pluginwooocmmerce-sms
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Khudebarta SMS Gateway – SMS Campaing, OTP Login & Order Notification for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Khudebarta SMS Gateway – SMS Campaing, OTP Login & Order Notification for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7mo ago
Risk Assessment

The kb-sms-gateway plugin version 1.5 demonstrates a generally good security posture based on the provided static analysis. The plugin utilizes prepared statements for its SQL queries and has a very high rate of properly escaped output, mitigating common web vulnerabilities. The absence of dangerous functions, file operations, and critical taint flows further reinforces this positive outlook. Furthermore, the lack of any recorded vulnerabilities in its history suggests a commitment to secure development or a lack of targeting by attackers.

However, there are areas that warrant attention. The plugin has zero capability checks implemented across all identified entry points, including its single shortcode. This means any user, regardless of their role, could potentially interact with the plugin's functionality, which could lead to unintended consequences if not properly secured at the application level. While the static analysis did not reveal any direct critical or high severity issues, the absence of capability checks represents a potential weakness that could be exploited in conjunction with other factors or if the plugin's internal logic is complex.

In conclusion, kb-sms-gateway v1.5 is relatively well-secured, excelling in areas like SQL sanitization and output escaping, and boasting a clean vulnerability history. The primary concern is the complete lack of capability checks on its entry points, which, while not a direct vulnerability in this analysis, introduces a significant risk of unauthorized access or manipulation if not addressed. The presence of external HTTP requests also suggests a need for vigilance regarding the security of those external services.

Key Concerns

  • No capability checks on entry points
Vulnerabilities
None known

Khudebarta SMS Gateway – SMS Campaing, OTP Login & Order Notification for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Khudebarta SMS Gateway – SMS Campaing, OTP Login & Order Notification for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
2
66 escaped
Nonce Checks
5
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

97% escaped68 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
<kb-admin-nav> (includes\kb-admin-tab\kb-admin-nav.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Khudebarta SMS Gateway – SMS Campaing, OTP Login & Order Notification for WooCommerce Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[kb-custom-login-form] includes\kb-otp-system\kb-otp-login-form.php:23
WordPress Hooks 14
actionadmin_menuincludes\kb-admin-settings.php:11
actionadmin_initincludes\kb-admin-settings.php:18
actionadmin_initincludes\kb-admin-settings.php:26
actionadmin_enqueue_scriptsincludes\kb-assets-file.php:11
actionwp_enqueue_scriptsincludes\kb-assets-file.php:18
actioninitincludes\kb-otp-system\kb-otp-handler.php:14
actioninitincludes\kb-otp-system\kb-otp-handler.php:54
actioninitincludes\kb-otp-system\kb-otp-handler.php:111
actioninitincludes\kb-otp-system\kb-otp-login-form.php:16
actionwoocommerce_order_status_processingincludes\kb-woow-settings.php:12
actionwoocommerce_order_status_completedincludes\kb-woow-settings.php:13
actionwoocommerce_order_status_cancelledincludes\kb-woow-settings.php:14
actionwoocommerce_order_status_refundedincludes\kb-woow-settings.php:15
actionwoocommerce_order_status_on-holdincludes\kb-woow-settings.php:16
Maintenance & Trust

Khudebarta SMS Gateway – SMS Campaing, OTP Login & Order Notification for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedAug 13, 2025
PHP min version7.4
Downloads373

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Khudebarta SMS Gateway – SMS Campaing, OTP Login & Order Notification for WooCommerce Developer Profile

graywp

3 plugins · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Khudebarta SMS Gateway – SMS Campaing, OTP Login & Order Notification for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/kb-sms-gateway/assets/kb-admin/kb-admin-settings.css/wp-content/plugins/kb-sms-gateway/assets/kb-admin/kd-admin-settings/wp-content/plugins/kb-sms-gateway/assets/kb-front/kb-front.css
Version Parameters
kb-sms-gateway/assets/kb-admin/kb-admin-settings.css?ver=1.0kb-sms-gateway/assets/kb-admin/kd-admin-settings?ver=1.0kb-sms-gateway/assets/kb-front/kb-front.css?ver=1.0

HTML / DOM Fingerprints

CSS Classes
kb-login-wrapperkb-login-wrapper__columnkb-login-wrapper__loginkb-login-formkb-login-form__titlekb-login-form__fieldskb-login-form__groupkb-login-form__forget+4 more
Data Attributes
name="kbsgp_login_username"name="kbsgp_login_pass"name="kbsgp_email_login_submit"name="kbsgp_login_otp_action"name="kbsgp_login_otp_nonce"name="kbsgp_enter_OTP"+8 more
Shortcode Output
<div class="kb-login-wrapper">
FAQ

Frequently Asked Questions about Khudebarta SMS Gateway – SMS Campaing, OTP Login & Order Notification for WooCommerce