
Marketing automation, Email and SMS for Woocommerce and WordPress Security & Risk Analysis
wordpress.org/plugins/message-businessSynchronize your Woocommerce clients and Wordpress visitors with Message Business application for Marketing automation, email marketing, sms marketing …
Is Marketing automation, Email and SMS for Woocommerce and WordPress Safe to Use in 2026?
Generally Safe
Score 100/100Marketing automation, Email and SMS for Woocommerce and WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "message-business" v1.1.1 plugin exhibits a generally good security posture, with all identified entry points (AJAX handlers, cron events) appearing to have appropriate authorization checks. The plugin also demonstrates strong practices in output escaping, with a high percentage of outputs being properly handled, and it does not appear to make external HTTP requests, reducing its attack surface in that regard.
However, several areas raise concerns. The presence of the `unserialize` function is a significant risk, as it can lead to Remote Code Execution if it processes untrusted data. Additionally, the single SQL query found is not using prepared statements, which makes it vulnerable to SQL injection attacks. The taint analysis, while not reporting critical or high severity issues, did identify flows with unsanitized paths, suggesting a potential for vulnerabilities if these paths are exploited by malicious input.
The plugin's vulnerability history is a strong positive, with no recorded CVEs. This indicates a history of stable and secure development. Overall, while the lack of known vulnerabilities is reassuring, the presence of `unserialize` and raw SQL queries represents tangible security risks that should be addressed.
Key Concerns
- Dangerous function "unserialize" found
- SQL query not using prepared statements
- Flows with unsanitized paths identified
Marketing automation, Email and SMS for Woocommerce and WordPress Security Vulnerabilities
Marketing automation, Email and SMS for Woocommerce and WordPress Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Marketing automation, Email and SMS for Woocommerce and WordPress Attack Surface
AJAX Handlers 3
WordPress Hooks 6
Scheduled Events 1
Maintenance & Trust
Marketing automation, Email and SMS for Woocommerce and WordPress Maintenance & Trust
Maintenance Signals
Community Trust
Marketing automation, Email and SMS for Woocommerce and WordPress Alternatives
SG Autorepondeur Comment
sg-autorepondeur-comment
A plugin which makes possible adding to your SG Autorepondeur Lists comment authors.
Missed Schedule Post Publisher
missed-schedule-post-publisher
🎯 Never miss scheduled posts again! Automatically publishes missed scheduled posts on time, every time. Zero bloat, single purpose, reliable.
Drip for WordPress
email-marketing
Do you sell online? If so you need our new Drip for WooCommerce Plugin instead of this one. It includes your entire product catalog, order history int …
SendPulse Email Marketing Newsletter
sendpulse-email-marketing-newsletter
Add a customizable email subscription form to your site, send newsletters, and automate email campaigns with autoresponders using SendPulse.
Simple Membership MailChimp Integration
simple-membership-mailchimp-integration
An addon for the simple membership plugin to signup members to your MailChimp list
Marketing automation, Email and SMS for Woocommerce and WordPress Developer Profile
1 plugin · 30 total installs
How We Detect Marketing automation, Email and SMS for Woocommerce and WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/message-business/admin/css/message-business-admin.css/wp-content/plugins/message-business/admin/css/material-icons-font.css/wp-content/plugins/message-business/woocommerce/css/message-business-woocommerce.css/wp-content/plugins/message-business/admin/js/message-business-admin.js/wp-content/plugins/message-business/woocommerce/js/message-business-woocommerce.js/wp-content/plugins/message-business/admin/js/message-business-admin.js/wp-content/plugins/message-business/woocommerce/js/message-business-woocommerce.jsmessage-business/admin/css/message-business-admin.css?ver=message-business/woocommerce/css/message-business-woocommerce.css?ver=message-business/admin/js/message-business-admin.js?ver=message-business/woocommerce/js/message-business-woocommerce.js?ver=HTML / DOM Fingerprints
message-business-settings-pagedata-message-business-urlmessage_business_woocommerce_ajax_object/wp-json/message-business/v1/get-countries/wp-json/message-business/v1/import-contacts-from-woocommerce/wp-json/message-business/v1/get-available-plans/wp-json/message-business/v1/apply-plan/wp-json/message-business/v1/get-message-business-account-status/wp-json/message-business/v1/send-test-sms