Medical Appointment Calendar SMS Security & Risk Analysis

wordpress.org/plugins/medical-appointment-calendar-sms

Connect Google Calendar with SMS & email notifications for medical appointments. Supports 10+ SMS providers.

0 active installs v1.0.0 PHP 7.4+ WP 5.0+ Updated Nov 12, 2025
appointmentsbookingcalendarmedicalsms
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Medical Appointment Calendar SMS Safe to Use in 2026?

Generally Safe

Score 100/100

Medical Appointment Calendar SMS has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9mo ago
Risk Assessment

The "medical-appointment-calendar-sms" plugin v1.0.0 demonstrates a generally good security posture, particularly in its handling of SQL queries and output escaping, with all SQL queries utilizing prepared statements and all outputs being properly escaped. The absence of known vulnerabilities and critical taint flows further bolsters this positive assessment. However, a significant concern exists within its attack surface. The presence of three AJAX handlers, with one lacking any authentication checks, presents a clear entry point for unauthenticated attackers. While there are a couple of nonce checks and one capability check, the unprotected AJAX handler bypasses these essential security measures. The plugin also makes a notable number of external HTTP requests, which, while not a direct vulnerability in itself, could be a vector for other types of attacks if the target endpoints are compromised or if data transmitted is sensitive and not properly secured.

Despite the identified unprotected AJAX handler, the plugin's strong foundation in secure coding practices regarding database interactions and output sanitization is commendable. The lack of historical vulnerabilities suggests a developer who may be diligent in addressing security issues, or that the plugin has not yet been widely targeted or thoroughly analyzed for advanced vulnerabilities. Nevertheless, the unprotected AJAX handler represents a tangible risk that needs immediate attention. The overall security is decent due to robust core practices, but the one glaring unprotected entry point significantly detracts from its otherwise strong security.

The plugin's vulnerability history is spotless, with no recorded CVEs of any severity. This is a strong positive indicator, suggesting that the code is likely robust or hasn't been a target for exploitation. The absence of critical or high-severity issues in the past aligns with the current static analysis results, which also show no critical or high-severity taint flows. This pattern indicates a developer who, at least historically and in this version, prioritizes secure coding principles, especially concerning direct database manipulation and output rendering, which are common sources of vulnerabilities in WordPress plugins.

Key Concerns

  • AJAX handler without authentication checks
Vulnerabilities
None known

Medical Appointment Calendar SMS Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Medical Appointment Calendar SMS Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

Medical Appointment Calendar SMS Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
14 prepared
Unescaped Output
0
37 escaped
Nonce Checks
2
Capability Checks
1
File Operations
0
External Requests
11
Bundled Libraries
0

SQL Query Safety

100% prepared14 total queries

Output Escaping

100% escaped37 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
save_settings (medical-appointment-sms.php:151)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Medical Appointment Calendar SMS Attack Surface

Entry Points3
Unprotected1

AJAX Handlers 3

authwp_ajax_macsms_save_settingsmedical-appointment-sms.php:38
authwp_ajax_macsms_get_bookingsmedical-appointment-sms.php:40
authwp_ajax_macsms_sync_calendarmedical-appointment-sms.php:42
WordPress Hooks 5
actionadmin_menumedical-appointment-sms.php:34
actionadmin_enqueue_scriptsmedical-appointment-sms.php:35
actioninitmedical-appointment-sms.php:37
actionmacsms_sync_calendar_cronmedical-appointment-sms.php:50
actionplugins_loadedmedical-appointment-sms.php:388

Scheduled Events 1

macsms_sync_calendar_cron
Maintenance & Trust

Medical Appointment Calendar SMS Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 12, 2025
PHP min version7.4
Downloads381

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Medical Appointment Calendar SMS Developer Profile

majdidraouil

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Medical Appointment Calendar SMS

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/medical-appointment-calendar-sms/assets/admin-style.css/wp-content/plugins/medical-appointment-calendar-sms/assets/admin-script.js
Script Paths
/wp-content/plugins/medical-appointment-calendar-sms/assets/admin-script.js
Version Parameters
medical-appointment-calendar-sms/assets/admin-style.css?ver=medical-appointment-calendar-sms/assets/admin-script.js?ver=

HTML / DOM Fingerprints

JS Globals
macsmsAjax
REST Endpoints
/wp-json/admin-ajax.php
FAQ

Frequently Asked Questions about Medical Appointment Calendar SMS