
Melipayamak Security & Risk Analysis
wordpress.org/plugins/melipayamakارسال و دریافت پیامک و پیام صوتی بر روی سیستم وردپرس و پلاگین های ووکامرس، کانتکت فرم، گرویتی فرم و ایزی دیجیتال دانلود
Is Melipayamak Safe to Use in 2026?
Use With Caution
Score 63/100Melipayamak has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The melipayamak plugin v2.2.12 presents a mixed security posture. While the attack surface is notably small with no unprotected entry points and a reasonable number of nonce and capability checks, significant concerns arise from the code analysis. The low percentage of SQL queries using prepared statements (9%) and output escaping (14%) indicates a high risk of SQL injection and cross-site scripting vulnerabilities, especially given the 4 analyzed taint flows with unsanitized paths. The plugin also has a history of vulnerabilities, including a recent medium-severity Cross-Site Scripting (XSS) issue that remains unpatched. This pattern suggests a recurring lack of robust input validation and output sanitization. While the lack of dangerous functions and external HTTP requests is positive, the prevalent issues with SQL prepared statements and output escaping, coupled with the unpatched CVE, point to a need for urgent code review and remediation to improve the plugin's overall security.
Key Concerns
- Unpatched medium severity CVE
- Low rate of prepared SQL statements
- Low rate of properly escaped output
- Flows with unsanitized paths detected
Melipayamak Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Melipayamak <= 2.2.12 - Authenticated (Administrator+) Stored Cross-Site Scripting
Melipayamak Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Melipayamak Attack Surface
Shortcodes 1
WordPress Hooks 52
Maintenance & Trust
Melipayamak Maintenance & Trust
Maintenance Signals
Community Trust
Melipayamak Alternatives
افزونه پیامک ووکامرس Persian WooCommerce SMS
persian-woocommerce-sms
افزونه کامل و حرفه ای برای اطلاع رسانی پیامکی سفارشات و رویداد های محصولات ووکامرس
Akay Digits Add-on
akay-digits
افزونه مکمل دیجیتس آکای برای استفاده با افزونه اورجینال دیجیتس سازگاری با سامانه های پیامکی
افزونه پیامک ووکامرس و وردپرس نیر وب
nirweb-smart-sms
افزونه پیامک ووکامرس و ورودپرس | با این افزونه میتوانید انواع اطلاع رسانی های پیامکی برای ووکامرس و وردپرس خود داشته باشید.
Rahrayan WP SMS PLUGIN
rahrayan-wp-sms
این پلاگین توسط شرکت مهندسی ره رایان برای وردپرس و ووکامرس نوشته شده و به شما اجازه میدهد پنل پیامک را به وب سایت و فروشگاه اینترنتی خود متصل کنید.
Newsletters, Email Marketing, SMS and Popups by Omnisend
omnisend
Newsletters, Email Marketing, Email Automation, Forms, Pop Up, SMS by Omnisend
Melipayamak Developer Profile
1 plugin · 500 total installs
How We Detect Melipayamak
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/melipayamak/js/admin.js/wp-content/plugins/melipayamak/js/jquery.script.js/wp-content/plugins/melipayamak/css/admin.css/wp-content/plugins/melipayamak/css/admin_rtl.css/wp-content/plugins/melipayamak/js/jquery.maskedinput.min.js/wp-content/plugins/melipayamak/js/persian_datepicker.js/wp-content/plugins/melipayamak/js/persian_datepicker_init.js/wp-content/plugins/melipayamak/js/sms.jsMelipayamak v2.2.12js/admin.jsjs/jquery.script.jsjs/jquery.maskedinput.min.jsjs/persian_datepicker.jsjs/persian_datepicker_init.jsjs/sms.jsmelipayamak/css/admin.css?ver=melipayamak/css/admin_rtl.css?ver=melipayamak/js/admin.js?ver=melipayamak/js/jquery.script.js?ver=melipayamak/js/jquery.maskedinput.min.js?ver=melipayamak/js/persian_datepicker.js?ver=melipayamak/js/persian_datepicker_init.js?ver=melipayamak/js/sms.js?ver=HTML / DOM Fingerprints
melipayamak_admin_formmelipayamak_admin_divmelipayamak_panel<!-- check access --><!-- include pluggable.php --><!-- jalali date --><!-- define product version -->+18 moredata-noncedata-actionmelipayamak_ajaxurlmelipayamak_noncemelipayamak_message