Notify.lk SMS for WooCommerce Security & Risk Analysis

wordpress.org/plugins/notifylk-sms-for-woocommerce

Notify.lk is a popular SMS gateway for Sri Lanka which you can use to send transactional or bulk SMS to your customers. This plugin allows you to inte …

100 active installs v1.1.2 PHP + WP 6.0+ Updated Jan 27, 2026
notify-smsnotify-lksmssri-lankawoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Notify.lk SMS for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Notify.lk SMS for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "notifylk-sms-for-woocommerce" plugin version 1.1.2 presents a seemingly strong security posture based on the static analysis. The absence of any detected AJAX handlers, REST API routes, shortcodes, or cron events with improper authorization checks indicates a minimal attack surface. Furthermore, the code signals are generally positive, with no dangerous functions identified, all SQL queries using prepared statements, and all output being properly escaped. The plugin also avoids bundling external libraries, which can often introduce their own vulnerabilities.

However, a closer look reveals some areas that warrant caution. The presence of file operations and an external HTTP request, without any explicit mention of sanitization or authentication checks related to these actions, could represent potential weak points if not handled securely within the plugin's logic. The complete absence of nonce checks and capability checks across all entry points, though currently zero, is a significant concern. If any new entry points are introduced in future versions or if existing functionality implicitly creates them, this lack of fundamental security measures could be easily exploited.

The vulnerability history of zero recorded CVEs is a positive indicator, suggesting a history of stable and secure development. However, this could also be a consequence of the plugin's limited attack surface and the lack of deep security analysis rather than a guaranteed ongoing security. In conclusion, while the current version appears to have a clean bill of health regarding known vulnerabilities and basic code security practices like prepared statements and output escaping, the lack of authorization checks on critical operations (file operations, HTTP requests) and the absence of general security mechanisms like nonces and capability checks represent notable weaknesses that could be exploited under different circumstances.

Key Concerns

  • No nonce checks on entry points
  • No capability checks on entry points
  • File operations without explicit auth check context
  • External HTTP requests without explicit auth check context
Vulnerabilities
None known

Notify.lk SMS for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Notify.lk SMS for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
2
External Requests
1
Bundled Libraries
0
Attack Surface

Notify.lk SMS for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
filterwoocommerce_settings_tabs_arrayincludes\NotifyLKSMS.php:19
actionwoocommerce_settings_tabs_settings_tab_notifylkincludes\NotifyLKSMS.php:20
actionwoocommerce_update_options_settings_tab_notifylkincludes\NotifyLKSMS.php:21
actionwoocommerce_order_status_processingincludes\NotifyLKSMS.php:26
actionwoocommerce_order_status_changedincludes\NotifyLKTrigger.php:39
actionwoocommerce_new_customer_noteincludes\NotifyLKTrigger.php:40
Maintenance & Trust

Notify.lk SMS for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 27, 2026
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings3
Active installs100
Developer Profile

Notify.lk SMS for WooCommerce Developer Profile

Notify (Private) Limited

1 plugin · 100 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Notify.lk SMS for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/notifylk-sms-for-woocommerce/css/notify-sms-style.css/wp-content/plugins/notifylk-sms-for-woocommerce/js/notify-sms-script.js
Version Parameters
notifylk-sms-for-woocommerce/css/notify-sms-style.css?ver=notifylk-sms-for-woocommerce/js/notify-sms-script.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Notify.lk SMS for WooCommerce