
MDSCO SMS Security & Risk Analysis
wordpress.org/plugins/mdsco-smsMDSCO SMS - là plugin dành riêng cho khách hàng sử dụng dịch vụ của MDSCO, giúp quý khách gửi tin nhắn vào số điện thoại của khách hàng khi sử dụng Co …
Is MDSCO SMS Safe to Use in 2026?
Generally Safe
Score 85/100MDSCO SMS has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "mdsco-sms" v1.1 plugin exhibits a generally good security posture based on the provided static analysis. The absence of identified dangerous functions, SQL injection vulnerabilities, and file operations is a positive indicator. Furthermore, the plugin demonstrates the use of prepared statements for all SQL queries, which is a crucial security practice. The limited attack surface, with no identified AJAX handlers, REST API routes, shortcodes, or cron events, further reduces the potential for exploits. However, a significant concern is the low percentage of properly escaped output (33%), indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. The presence of an external HTTP request without further context also warrants caution, as it could potentially be a vector for various attacks if not handled securely. The vulnerability history shows no recorded CVEs, suggesting a good track record, but this should not be a reason to overlook identified code weaknesses.
Despite the lack of known historical vulnerabilities, the identified output escaping issue presents a clear and present danger. The plugin is highly susceptible to XSS attacks, which could lead to session hijacking, credential theft, or defacement. While the plugin has strengths in its limited attack surface and secure SQL practices, the inadequate output escaping significantly lowers its overall security rating. The single external HTTP request also introduces an unknown risk factor that would need further investigation. Therefore, immediate attention should be given to addressing the output escaping deficiencies to mitigate the XSS risks.
Key Concerns
- Low percentage of properly escaped output
- External HTTP request without context
MDSCO SMS Security Vulnerabilities
MDSCO SMS Code Analysis
Output Escaping
MDSCO SMS Attack Surface
WordPress Hooks 11
Maintenance & Trust
MDSCO SMS Maintenance & Trust
Maintenance Signals
Community Trust
MDSCO SMS Alternatives
eSMS
esms-gui-tin-nhan-sms
eSMS - là plugin dành riêng cho khách hàng sử dụng dịch vụ của eSMS, giúp quý khách gửi tin nhắn vào số điện thoại của khách hàng khi sử dụng Contact …
VHT SMS
vht-sms
VHT SMS - là plugin dành riêng cho khách hàng sử dụng dịch vụ của VHT, giúp quý khách gửi tin nhắn vào số điện thoại của khách hàng khi sử dụng Contac …
Newsletters, Email Marketing, SMS and Popups by Omnisend
omnisend
Newsletters, Email Marketing, Email Automation, Forms, Pop Up, SMS by Omnisend
Email Marketing for WooCommerce by Omnisend
omnisend-connect
Email Marketing, Newsletter, Email Automation, Forms, Pop Up, SMS, Abandoned Cart made easy for WordPress & WooCommerce by Omnisend
افزونه پیامک ووکامرس Persian WooCommerce SMS
persian-woocommerce-sms
افزونه کامل و حرفه ای برای اطلاع رسانی پیامکی سفارشات و رویداد های محصولات ووکامرس
MDSCO SMS Developer Profile
1 plugin · 0 total installs
How We Detect MDSCO SMS
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mdsco-sms/assets/css/admin.css/wp-content/plugins/mdsco-sms/assets/js/admin.js/wp-content/plugins/mdsco-sms/assets/js/admin.js/wp-content/plugins/mdsco-sms/assets/css/admin.css?ver=/wp-content/plugins/mdsco-sms/assets/js/admin.js?ver=HTML / DOM Fingerprints
mdscosms-inputmdscosms-wrapmdscosms-shortcode-wrap<!-- MDSCO SMS --><!-- End MDSCO SMS --><!-- MDSCO SMS Settings --><!-- end MDSCO SMS Settings -->+8 moredata-mdscosms-noncedata-mdscosms-ajaxurlmdscosms_ajax_object/wp-json/mdscosms/v1/send_sms[mdsco_sms_shortcode]