
Orion SMS OTP Verification. Security & Risk Analysis
wordpress.org/plugins/orion-sms-otp-verificationSMS/OTP verification and Notification for all forms via Twilio or MSG91. So user can't submit form without verifying mobile number.
Is Orion SMS OTP Verification. Safe to Use in 2026?
Generally Safe
Score 94/100Orion SMS OTP Verification. has a strong security track record. Known vulnerabilities have been patched promptly.
The "orion-sms-otp-verification" plugin, version 2.0.0, exhibits a mixed security posture. While the static analysis shows a promising lack of dangerous functions, raw SQL queries, and unprotected entry points, there are significant concerns regarding output escaping and a history of critical vulnerabilities. The fact that 33% of outputs are not properly escaped presents a potential cross-site scripting (XSS) risk if user-controlled data is rendered directly without sufficient sanitization.
The plugin's vulnerability history is a major red flag. The presence of a past critical vulnerability, specifically an "Authentication Bypass Using an Alternate Path or Channel," coupled with the reported "Last vulnerability" date in the future (which is likely a data anomaly but highlights historical critical issues), indicates that the plugin has previously suffered from severe security flaws. The absence of currently unpatched CVEs is positive, but the pattern of past critical issues necessitates a cautious approach.
In conclusion, while the plugin has improved in certain areas like securing its entry points and using prepared statements for SQL, the unescaped output and historical critical vulnerabilities prevent a fully confident security assessment. Users should be aware of the potential for XSS and the plugin's past susceptibility to authentication bypass, urging them to ensure the plugin is updated to the latest stable version and to monitor for future security advisories.
Key Concerns
- Significant portion of output not properly escaped
- History of 1 critical vulnerability (Auth Bypass)
Orion SMS OTP Verification. Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Orion SMS OTP Verification <= 1.1.7 - Authentication Bypass via Account Takeover
Orion SMS OTP Verification. Code Analysis
Output Escaping
Orion SMS OTP Verification. Attack Surface
AJAX Handlers 6
WordPress Hooks 4
Maintenance & Trust
Orion SMS OTP Verification. Maintenance & Trust
Maintenance Signals
Community Trust
Orion SMS OTP Verification. Alternatives
ShopMagic – Twilio SMS
shopmagic-for-twilio
Send WooCommerce SMS notifications, reminders, and text messages to your customers. The plugin is the ShopMagic add-on and it lets you send sms remind …
Gray SMS – Complete SMS Notificaitons for WordPress, Woocommerce & Multi Features
gray-sms
Send WooCommerce order notifications and individual SMS messages using Twilio, Vonage, Plivo, Clickatell and other SMS gateways.
Texty – SMS Notification for WordPress, WooCommerce, Dokan and more
texty
Texty is a lightweight SMS notification plugin for WordPress.
WSMS (formerly WP SMS) – SMS & MMS Notifications with OTP and 2FA for WooCommerce
wp-sms
Send SMS/MMS notifications, OTP & 2FA messages, and WooCommerce updates with support for multiple gateways and plugin integrations.
miniOrange OTP Login, Verification and SMS Notifications
miniorange-otp-verification
OTP Verification via Email/SMS/WhatsApp,SMS Notifications for WooCommerce,OTP Login with Phone,PasswordLess Login.Custom Gateway for OTP Verification
Orion SMS OTP Verification. Developer Profile
3 plugins · 210 total installs
How We Detect Orion SMS OTP Verification.
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/orion-sms-otp-verification/style.css/wp-content/plugins/orion-sms-otp-verification/vendor/js/main.js/wp-content/plugins/orion-sms-otp-verification/vendor/js/main.jsorion-sms-otp-verification/style.css?ver=1.0orion-sms-otp-verification/vendor/js/main.js?ver=1.0HTML / DOM Fingerprints
ihs-otp-verify-wrapihs-otp-verify-mobile-wrapihs-otp-verify-input-wrapihs-otp-verify-mobileihs-otp-verify-otp-wrapihs-otp-verify-otp-inputihs-otp-verify-btn-wrapihs-otp-verify-send-otp-btn+3 moredata-form-selectordata-submit-btn-selectordata-input-requireddata-mobile-input-namedata-country-codedata-mobile-length+2 moreotp_obj