
Netgsm Security & Risk Analysis
wordpress.org/plugins/netgsmNetgsm wordpress eklentisi ile kullanıcılarınıza sms uzaklığında kalın.
Is Netgsm Safe to Use in 2026?
Mostly Safe
Score 72/100Netgsm is generally safe to use. 4 past CVEs were resolved. Keep it updated.
The "netgsm" plugin v2.9.69 presents a mixed security posture. While it demonstrates strengths in general code quality with a high percentage of properly escaped outputs and a good practice of using prepared statements for most SQL queries, significant concerns arise from its attack surface and vulnerability history. The presence of 4 unprotected AJAX handlers represents a direct pathway for potential unauthorized actions if exploited. Furthermore, the taint analysis reveals a critical flow with unsanitized paths, indicating a potential for severe security issues like code injection or execution. The plugin's history of 4 known CVEs, particularly with 1 still unpatched and a recent vulnerability in late 2025, suggests a recurring pattern of security weaknesses, specifically related to Cross-site Scripting and Missing Authorization. This history, combined with the identified code signals, paints a picture of a plugin that, despite some good coding practices, has demonstrated a propensity for vulnerabilities, requiring vigilant monitoring and prompt patching.
Key Concerns
- Unprotected AJAX handlers
- Critical taint flow with unsanitized paths
- Currently unpatched CVE
- Medium severity CVEs in history (4 total)
- Missing Authorization vulnerability pattern
- Cross-site Scripting vulnerability pattern
Netgsm Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
Netgsm <= 2.9.63 - Reflected Cross-Site Scripting
Netgsm <= 2.9.58 - Missing Authorization
Netgsm <= 2.9.32 - Missing Authorization
Netgsm <= 2.8 - Reflected Cross-Site Scripting
Netgsm Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Netgsm Attack Surface
AJAX Handlers 7
WordPress Hooks 31
Scheduled Events 1
Maintenance & Trust
Netgsm Maintenance & Trust
Maintenance Signals
Community Trust
Netgsm Alternatives
VatanSMS.NET
vatansms-net
Kullanım Detayları
MobiKoB
mobikob
MobiKoB eklentisi ile, MobiKoB hesabınızla;
WSMS (formerly WP SMS) – SMS & MMS Notifications with OTP and 2FA for WooCommerce
wp-sms
Send SMS/MMS notifications, OTP & 2FA messages, and WooCommerce updates with support for multiple gateways and plugin integrations.
SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery
sms-alert
Send WooCommerce SMS notifications, OTP verification, abandoned cart recovery alerts, and real-time order updates to customers and admins.
افزونه پیامک حرفه ای فراز اس ام اس
farazsms
شما می توانید با استفاده از افزونه فراز اس ام اس، سایت خود را با ابزاری خودکار برای ارسال پیامک و ذخیره شماره در دفترچه تلفن، تقویت کنید.
Netgsm Developer Profile
1 plugin · 1K total installs
How We Detect Netgsm
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/netgsm/lib/css/bootstrap.css/wp-content/plugins/netgsm/lib/fonts/css/font-awesome.min.css/wp-content/plugins/netgsm/lib/css/style.css/wp-content/plugins/netgsm/lib/js/sweetalert2/dist/sweetalert2.css/wp-content/plugins/netgsm/lib/css/bootstrap-table.min.css/wp-content/plugins/netgsm/bootstrap.min.js/wp-content/plugins/netgsm/sweetalert2.all.js/wp-content/plugins/netgsm/bootstrap-table.min.jsHTML / DOM Fingerprints
netgsm-wp-pluginNETGSM - Yeni Nesil Telekom Operatörü - www.netgsm.com.trNETGSM - Toplu SMS - Başlıklı SMS - Sabit Telefon - Sanal Santral - 0850li Numara