Order SMS For WooCommerce Security & Risk Analysis

wordpress.org/plugins/order-sms-for-woocommerce

Send WooCommerce order SMS notifications and custom SMS messages using popular SMS gateways.

0 active installs v1.0.0 PHP 7.2+ WP 5.5+ Updated Feb 15, 2026
order-notificationorder-smssmswoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Order SMS For WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Order SMS For WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "order-sms-for-woocommerce" v1.0.0 plugin exhibits a generally strong security posture based on the provided static analysis. The complete absence of unprotected AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the potential attack surface. Furthermore, the code demonstrates good practices with 100% of SQL queries using prepared statements and a high percentage of properly escaped output. The limited taint analysis shows no critical or high severity flows, suggesting a low risk of arbitrary code execution or data compromise originating from user input. The plugin also reports zero known vulnerabilities (CVEs), which is a positive indicator of its security maturity.

However, there are areas for improvement. The presence of one external HTTP request, while not inherently risky, should be monitored for potential vulnerabilities in the target service or if the request is constructed in an insecure manner. The existence of only two nonce checks, despite the overall limited attack surface, might be a missed opportunity to further secure any interaction points that might exist beyond the analyzed entry points. Crucially, the lack of any capability checks is a notable concern. While the static analysis indicates no *direct* vulnerabilities, it doesn't confirm that all sensitive actions are properly authorized. This could leave the plugin open to privilege escalation if an attacker can trigger administrative functions without proper permission.

Key Concerns

  • No capability checks found
  • External HTTP request present
Vulnerabilities
None known

Order SMS For WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Order SMS For WooCommerce Release Timeline

v1.0.0Current
Code Analysis
Analyzed Mar 17, 2026

Order SMS For WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
14
69 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

83% escaped83 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
global_wc_sms_send_page (order-sms-for-woocommerce.php:1007)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Order SMS For WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_enqueue_scriptsorder-sms-for-woocommerce.php:85
actionadmin_menuorder-sms-for-woocommerce.php:704
actionadmin_initorder-sms-for-woocommerce.php:757
actionwoocommerce_order_status_changedorder-sms-for-woocommerce.php:1455
Maintenance & Trust

Order SMS For WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 15, 2026
PHP min version7.2
Downloads154

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Order SMS For WooCommerce Developer Profile

Md Arafat Islam

2 plugins · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Order SMS For WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/order-sms-for-woocommerce/assets/css/admin.css/wp-content/plugins/order-sms-for-woocommerce/assets/js/admin.js
Script Paths
/wp-content/plugins/order-sms-for-woocommerce/assets/js/admin.js
Version Parameters
order-sms-for-woocommerce/assets/css/admin.css?ver=order-sms-for-woocommerce/assets/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
global-wc-sms-admin-wrap
Data Attributes
data-gatewaydata-options
JS Globals
global_wc_sms_admin_params
FAQ

Frequently Asked Questions about Order SMS For WooCommerce