Msg91 for WooCommerce Security & Risk Analysis

wordpress.org/plugins/msg91-for-woocommerce

AI-powered shopping assistant with WhatsApp, Web, Facebook & Instagram chatbots, product search, cart management, COD-to-prepaid conversion, refun …

70 active installs v3.0.0 PHP + WP 5.0+ Updated Jun 26, 2026
chatbotmsg91notificationssmswoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Msg91 for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Msg91 for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The msg91-for-woocommerce plugin v1.0.0 exhibits a generally strong security posture, with excellent practices in output escaping and a high percentage of SQL queries using prepared statements. The absence of any known vulnerabilities in its history is also a positive indicator. However, a significant concern arises from the presence of 16 AJAX handlers, two of which lack authentication checks. This directly exposes potential entry points for unauthorized actions. While there are 16 nonce checks for AJAX handlers, the absence of capability checks on any of the entry points is a notable weakness. This means that even if a nonce is present, an attacker might still be able to leverage it if they have any authenticated user role, depending on the specific functionality of the unprotected AJAX actions. The plugin's static analysis shows no critical or high severity issues in taint flows, and no dangerous functions are used, which are good signs. The limited file operations and external HTTP requests, along with the absence of bundled libraries, further contribute to a smaller attack surface in those areas. Overall, the plugin is well-coded in many aspects, but the unprotected AJAX handlers present a clear and actionable security risk that requires immediate attention.

Key Concerns

  • AJAX handlers without authentication checks
  • No capability checks on any entry points
Vulnerabilities
None known

Msg91 for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Msg91 for WooCommerce Release Timeline

v3.0.0Current
v2.1.0
v2.0.0
v1.0.0
Code Analysis
Analyzed Mar 16, 2026

Msg91 for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
26 prepared
Unescaped Output
0
99 escaped
Nonce Checks
16
Capability Checks
0
File Operations
4
External Requests
4
Bundled Libraries
0

SQL Query Safety

93% prepared28 total queries

Output Escaping

100% escaped99 total outputs
Attack Surface
2 unprotected

Msg91 for WooCommerce Attack Surface

Entry Points16
Unprotected2

AJAX Handlers 16

authwp_ajax_msg91_woocommerce_create_automationincludes\core\class-automation.php:16
authwp_ajax_msg91_woocommerce_get_automationsincludes\core\class-automation.php:17
authwp_ajax_msg91_woocommerce_update_automationincludes\core\class-automation.php:18
authwp_ajax_msg91_woocommerce_delete_automationincludes\core\class-automation.php:19
authwp_ajax_msg91_woocommerce_delete_bulk_automationsincludes\core\class-automation.php:20
authwp_ajax_msg91_woocommerce_create_or_update_authkeyincludes\core\class-settings.php:15
authwp_ajax_msg91_woocommerce_get_campaignsincludes\services\CampaignService.php:12
authwp_ajax_msg91_woocommerce_fetch_campaign_fieldsincludes\services\CampaignService.php:13
authwp_ajax_msg91_woocommerce_update_activationincludes\services\OTPService.php:8
authwp_ajax_msg91_woocommerce_retry_otpincludes\services\OTPService.php:9
authwp_ajax_msg91_woocommerce_save_user_infoincludes\services\UserService.php:10
authwp_ajax_msg91_woocommerce_filter_error_logsincludes\services\UserService.php:11
authwp_ajax_msg91_woocommerce_save_error_logsincludes\services\UserService.php:12
authwp_ajax_msg91_woocommerce_delete_error_logs_fileincludes\services\UserService.php:13
authwp_ajax_msg91_woocommerce_schedule_delete_error_logs_fileincludes\services\UserService.php:14
authwp_ajax_msg91_woocommerce_fetch_trigger_logsincludes\services\UserService.php:16
WordPress Hooks 20
actionadmin_footerhelpers.php:368
actionadmin_menuincludes\core\class-admin-menu.php:16
actionmsg91_cleanup_logsincludes\core\class-exception-handler.php:26
actionmsg91_woocommerce_delete_error_logs_file_eventincludes\services\UserService.php:15
actionwoocommerce_created_customerincludes\services\WebhookService.php:21
actionwoocommerce_update_customerincludes\services\WebhookService.php:22
actionwoocommerce_new_orderincludes\services\WebhookService.php:25
actionwoocommerce_order_status_changedincludes\services\WebhookService.php:26
actionwoocommerce_order_status_pendingincludes\services\WebhookService.php:27
actionwoocommerce_order_status_processingincludes\services\WebhookService.php:28
actionwoocommerce_order_status_on-holdincludes\services\WebhookService.php:29
actionwoocommerce_order_status_completedincludes\services\WebhookService.php:30
actionwoocommerce_order_status_cancelledincludes\services\WebhookService.php:31
actionwoocommerce_order_status_failedincludes\services\WebhookService.php:32
actionwoocommerce_order_status_refundedincludes\services\WebhookService.php:33
actionwoocommerce_add_to_cartincludes\services\WebhookService.php:36
actionwoocommerce_removed_cart_itemincludes\services\WebhookService.php:37
actionmsg91_woocommerce_check_abandoned_cartsincludes\services\WebhookService.php:43
actionadmin_noticesmsg91-for-woocommerce.php:22
actionadmin_enqueue_scriptsmsg91-for-woocommerce.php:88

Scheduled Events 3

msg91_cleanup_logs
msg91_woocommerce_delete_error_logs_file_event
msg91_woocommerce_check_abandoned_carts
Maintenance & Trust

Msg91 for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested7.0.2
Last updatedJun 26, 2026
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs70
Developer Profile

Msg91 for WooCommerce Developer Profile

MSG91

1 plugin · 70 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Msg91 for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/msg91-for-woocommerce/assets/css/user-info.css/wp-content/plugins/msg91-for-woocommerce/assets/js/user-info.js
Script Paths
/wp-content/plugins/msg91-for-woocommerce/assets/js/user-info.js

HTML / DOM Fingerprints

JS Globals
msg91_user_info
FAQ

Frequently Asked Questions about Msg91 for WooCommerce