
msg91 by vasim shaikh Security & Risk Analysis
wordpress.org/plugins/msg91-by-vasim-shaikhIf you’ve ever wanted to add text messaging functionality to your website or app, Twilio is one of the best solutions on the market.
Is msg91 by vasim shaikh Safe to Use in 2026?
Generally Safe
Score 85/100msg91 by vasim shaikh has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The msg91-by-vasim-shaikh plugin, in version 1.0.3, presents a mixed security posture. On the positive side, the plugin demonstrates good practice by not utilizing dangerous functions, avoiding file operations, and ensuring all SQL queries are prepared statements, which mitigates the risk of SQL injection vulnerabilities. Its vulnerability history is also clean, with no known CVEs, suggesting a generally stable codebase in that regard.
However, significant concerns arise from the static analysis. The plugin has a notable attack surface with four entry points, and critically, three of these are unprotected by authentication checks. This means any unauthenticated user could potentially interact with these AJAX handlers, posing a significant risk. Furthermore, the taint analysis identified two flows with unsanitized paths, which, while not classified as critical or high severity in this report, still represent potential vulnerabilities that could be exploited if data enters these paths without proper sanitization. The absence of nonce checks on AJAX handlers is another major security oversight, making these entry points susceptible to Cross-Site Request Forgery (CSRF) attacks.
In conclusion, while the plugin avoids common pitfalls like raw SQL and dangerous functions, its reliance on unprotected AJAX handlers and the presence of unsanitized paths are substantial weaknesses. The lack of authentication and nonce checks on multiple entry points is the most pressing concern, demanding immediate attention. The clean vulnerability history is a positive sign, but it doesn't negate the risks exposed by the current code analysis.
Key Concerns
- Unprotected AJAX handlers
- AJAX handlers without auth checks
- Flows with unsanitized paths
- No nonce checks
- No capability checks
- Outputs not properly escaped (38%)
msg91 by vasim shaikh Security Vulnerabilities
msg91 by vasim shaikh Code Analysis
Output Escaping
Data Flow Analysis
msg91 by vasim shaikh Attack Surface
AJAX Handlers 3
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
msg91 by vasim shaikh Maintenance & Trust
Maintenance Signals
Community Trust
msg91 by vasim shaikh Alternatives
WSMS (formerly WP SMS) – SMS & MMS Notifications with OTP and 2FA for WooCommerce
wp-sms
Send SMS/MMS notifications, OTP & 2FA messages, and WooCommerce updates with support for multiple gateways and plugin integrations.
miniOrange OTP Login, Verification and SMS Notifications
miniorange-otp-verification
OTP Verification via Email/SMS/WhatsApp,SMS Notifications for WooCommerce,OTP Login with Phone,PasswordLess Login.Custom Gateway for OTP Verification
SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery
sms-alert
Send WooCommerce SMS notifications, OTP verification, abandoned cart recovery alerts, and real-time order updates to customers and admins.
OTP Login With Phone Number, OTP Verification
login-with-phone-number
OTP login with phone, SMS, or WhatsApp. OTP verification for WordPress & WooCommerce using custom gateways. GDPR-compliant. Login with otp
TextMe SMS
textme-sms-integration
Send custom SMS messages from your WordPress site to your customers using the TextMe SMS gateway.
msg91 by vasim shaikh Developer Profile
2 plugins · 40 total installs
How We Detect msg91 by vasim shaikh
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/msg91-by-vasim-shaikh/css/msg91-by-vasim-shaikh-admin.css/wp-content/plugins/msg91-by-vasim-shaikh/css/bootstrap.css/wp-content/plugins/msg91-by-vasim-shaikh/js/bootstrap.min.js/wp-content/plugins/msg91-by-vasim-shaikh/js/msg91-by-vasim-shaikh-admin.js/wp-content/plugins/msg91-by-vasim-shaikh/js/zt-common.js/wp-content/plugins/msg91-by-vasim-shaikh/js/bootstrap.min.js/wp-content/plugins/msg91-by-vasim-shaikh/js/msg91-by-vasim-shaikh-admin.js/wp-content/plugins/msg91-by-vasim-shaikh/js/zt-common.jsmsg91-by-vasim-shaikh-admin.css?ver=bootstrap.css?ver=bootstrap.min.js?ver=msg91-by-vasim-shaikh-admin.js?ver=zt-common.js?ver=HTML / DOM Fingerprints
alert-dangeralert-successdata-urlajax_object/wp-json/wp/v2/posts/wp-json/wp/v2/users/wp-json/wp/v2/media/wp-json/wp/v2/categories/wp-json/wp/v2/tags/wp-json/wp/v2/pages/wp-json/wp/v2/comments/wp-json/wp/v2/types/wp-json/wp/v2/taxonomies/wp-json/wp/v2/settings