Message Mate Security & Risk Analysis

wordpress.org/plugins/message-mate

Message Mate lets customers text you from their phone or computer. Reply via email, text or dashboard.

20 active installs v1.4 PHP + WP 3.0.1+ Updated Feb 9, 2023
customer-supportecommercemessagingsmssupport
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Message Mate Safe to Use in 2026?

Generally Safe

Score 85/100

Message Mate has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

Based on the static analysis and vulnerability history, the 'message-mate' plugin version 1.4 presents a generally positive security posture with some areas for improvement. The plugin demonstrates good practices by avoiding common attack vectors like unprotected AJAX handlers, REST API routes, shortcodes, and cron events. Furthermore, all SQL queries are prepared, indicating robust database interaction security. The absence of known CVEs and vulnerability history is also a strong positive indicator. However, concerns arise from the low percentage of properly escaped output, suggesting potential for cross-site scripting (XSS) vulnerabilities. The presence of file operations and external HTTP requests, while not inherently risky, warrants careful scrutiny to ensure they are implemented securely and don't introduce new attack surfaces. The lack of nonce and capability checks, especially given the presence of file operations and external requests, is a significant oversight that could allow unauthorized actions if an entry point is discovered.

Key Concerns

  • Low output escaping percentage
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Message Mate Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Message Mate Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
2
External Requests
1
Bundled Libraries
0

Output Escaping

38% escaped8 total outputs
Attack Surface

Message Mate Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionplugins_loadedincludes\class-message-mate.php:139
actionadmin_enqueue_scriptsincludes\class-message-mate.php:154
actionadmin_enqueue_scriptsincludes\class-message-mate.php:155
actionadmin_menuincludes\class-message-mate.php:158
actionadmin_initincludes\class-message-mate.php:164
actionwp_enqueue_scriptsincludes\class-message-mate.php:181
actionwp_enqueue_scriptsincludes\class-message-mate.php:182
actionwp_enqueue_scriptsincludes\class-message-mate.php:183
filterscript_loader_tagincludes\class-message-mate.php:184
Maintenance & Trust

Message Mate Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedFeb 9, 2023
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Message Mate Developer Profile

nivcaner

1 plugin · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Message Mate

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/message-mate/css/message-mate-admin.css/wp-content/plugins/message-mate/js/message-mate-admin.js
Script Paths
/wp-content/plugins/message-mate/js/message-mate-admin.js
Version Parameters
message-mate-admin.css?ver=message-mate-admin.js?ver=

HTML / DOM Fingerprints

HTML Comments
The code that runs during plugin activation. The code that runs during plugin deactivation. The core plugin class that is used to define internationalization, admin-specific hooks, and public-facing site hooks. +34 more
JS Globals
window.jQuery
FAQ

Frequently Asked Questions about Message Mate