Order SMS Notification – WooCommerce Security & Risk Analysis

wordpress.org/plugins/order-sms-notification-woocommerce

A plugin for sending SMS notification after placing orders using WooCommerce

20 active installs v2.0 PHP + WP 3.5+ Updated Sep 9, 2015
notificationorderorder-notificationorder-smssms-order
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Order SMS Notification – WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

Order SMS Notification – WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The "order-sms-notification-woocommerce" plugin version 2.0 exhibits a generally good security posture based on the provided static analysis. The absence of identified dangerous functions, SQL queries that are 100% prepared, file operations, external HTTP requests, and taint flows suggests a well-developed codebase. Furthermore, the plugin has no recorded vulnerabilities or CVEs, which is a strong positive indicator of its historical security and maintenance.

However, there are significant concerns that temper this positive outlook. The complete lack of nonce checks and capability checks, especially with 0 unprotected entry points identified in the attack surface, is a major red flag. This indicates that the plugin may not be adequately protecting its functionalities from unauthorized access or manipulation. Additionally, the low percentage of properly escaped output (22%) presents a risk of cross-site scripting (XSS) vulnerabilities, as user-supplied data might be rendered directly in the browser without proper sanitization.

In conclusion, while the plugin benefits from a clean history and absence of common risky code patterns, the lack of essential security checks like nonces and capability checks, coupled with poor output escaping, creates significant potential security weaknesses. These are critical areas that need to be addressed to ensure robust security.

Key Concerns

  • No nonce checks implemented
  • No capability checks implemented
  • Low output escaping (22%)
Vulnerabilities
None known

Order SMS Notification – WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Order SMS Notification – WooCommerce Release Timeline

No version history available.
Code Analysis
Analyzed Mar 16, 2026

Order SMS Notification – WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

22% escaped9 total outputs
Attack Surface

Order SMS Notification – WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 13
actionadmin_initclasses\setting-options.php:17
actionadmin_menuclasses\setting-options.php:18
actionwsa_form_bottom_satosms_gatewayclasses\setting-options.php:308
actioninitsat-wc-order-sms.php:109
actionadmin_enqueue_scriptssat-wc-order-sms.php:112
actionwoocommerce_checkout_after_customer_detailssat-wc-order-sms.php:119
actionwoocommerce_checkout_processsat-wc-order-sms.php:120
actionwoocommerce_checkout_update_order_metasat-wc-order-sms.php:121
actionwoocommerce_admin_order_data_after_billing_addresssat-wc-order-sms.php:122
actionwoocommerce_order_status_changedsat-wc-order-sms.php:123
actionadmin_noticessat-wc-order-sms.php:124
filterplugin_row_metasat-wc-order-sms.php:125
actionplugins_loadedsat-wc-order-sms.php:357
Maintenance & Trust

Order SMS Notification – WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested4.0.38
Last updatedSep 9, 2015
PHP min version
Downloads13K

Community Trust

Rating68/100
Number of ratings5
Active installs20
Developer Profile

Order SMS Notification – WooCommerce Developer Profile

Sabbir Ahmed

1 plugin · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Order SMS Notification – WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/order-sms-notification-woocommerce/css/admin.css/wp-content/plugins/order-sms-notification-woocommerce/js/admin.js
Version Parameters
order-sms-notification-woocommerce/css/admin.css?ver=order-sms-notification-woocommerce/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
buyer-sms-notify
HTML Comments
<!-- Begin: Sabbir Ahmed --><!-- End: Sabbir Ahmed --><!-- Begin: Sabbir Ahmed --><!-- End: Sabbir Ahmed -->+2 more
Data Attributes
data-satosms-options
JS Globals
satosms
FAQ

Frequently Asked Questions about Order SMS Notification – WooCommerce