
TOUCAN SMS Security & Risk Analysis
wordpress.org/plugins/leductoan-toucan-smsTOUCAN SMS - là plugin dành riêng cho khách hàng sử dụng dịch vụ của TOUCAN, giúp quý khách gửi tin nhắn vào số điện thoại của khách hàng khi sử dụng …
Is TOUCAN SMS Safe to Use in 2026?
Generally Safe
Score 85/100TOUCAN SMS has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The leductoan-toucan-sms plugin, v1.0.0, presents a mixed security posture. On the positive side, it boasts a remarkably small attack surface with zero identified entry points (AJAX, REST API, shortcodes, cron events). Furthermore, all SQL queries are correctly using prepared statements, and there are no file operations or external HTTP requests directly within the analyzed code, which are generally good security practices. However, a significant concern arises from the output escaping, with only 45% of outputs being properly escaped. This suggests a potential for Cross-Site Scripting (XSS) vulnerabilities where user-supplied data, if not adequately sanitized before display, could be injected into the page.
The plugin's vulnerability history is clean, with no recorded CVEs. This is a strong indicator that, historically, it has not been a target for or source of known security flaws. However, the absence of historical vulnerabilities does not guarantee future security, especially in the presence of potential XSS risks due to insufficient output escaping. The taint analysis also shows zero flows, which is positive but could be due to the limited scope of analysis or the lack of complex data flow paths within the plugin.
In conclusion, while the plugin exhibits strengths in minimizing its attack surface and secure database interaction, the high percentage of unescaped output is a notable weakness that could expose users to XSS attacks. The clean vulnerability history is a positive sign, but this should not overshadow the identified code-level risk. Continued vigilance and addressing the output escaping issue are recommended to improve its overall security.
Key Concerns
- Insufficient output escaping (45%)
TOUCAN SMS Security Vulnerabilities
TOUCAN SMS Release Timeline
TOUCAN SMS Code Analysis
Output Escaping
TOUCAN SMS Attack Surface
WordPress Hooks 11
Maintenance & Trust
TOUCAN SMS Maintenance & Trust
Maintenance Signals
Community Trust
TOUCAN SMS Alternatives
eSMS
esms-gui-tin-nhan-sms
eSMS - là plugin dành riêng cho khách hàng sử dụng dịch vụ của eSMS, giúp quý khách gửi tin nhắn vào số điện thoại của khách hàng khi sử dụng Contact …
VHT SMS
vht-sms
VHT SMS - là plugin dành riêng cho khách hàng sử dụng dịch vụ của VHT, giúp quý khách gửi tin nhắn vào số điện thoại của khách hàng khi sử dụng Contac …
MDSCO SMS
mdsco-sms
MDSCO SMS - là plugin dành riêng cho khách hàng sử dụng dịch vụ của MDSCO, giúp quý khách gửi tin nhắn vào số điện thoại của khách hàng khi sử dụng Co …
Newsletters, Email Marketing, SMS and Popups by Omnisend
omnisend
Newsletters, Email Marketing, Email Automation, Forms, Pop Up, SMS by Omnisend
Email Marketing for WooCommerce by Omnisend
omnisend-connect
Email Marketing, Newsletter, Email Automation, Forms, Pop Up, SMS, Abandoned Cart made easy for WordPress & WooCommerce by Omnisend
TOUCAN SMS Developer Profile
1 plugin · 0 total installs
How We Detect TOUCAN SMS
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/leductoan-toucan-sms/assets/css/backend_style.css/wp-content/plugins/leductoan-toucan-sms/assets/js/backend_script.js/wp-content/plugins/leductoan-toucan-sms/assets/js/backend_script.jsleductoan-toucan-sms/assets/css/backend_style.css?ver=leductoan-toucan-sms/assets/js/backend_script.js?ver=HTML / DOM Fingerprints
toucansms-options-groupid="toucansms_options"name="toucansms_options"toucansms_settings