
Otpfy your Website Security & Risk Analysis
wordpress.org/plugins/otpfy-your-websitePremium Email & SMS service for OTP based authentication
Is Otpfy your Website Safe to Use in 2026?
Generally Safe
Score 100/100Otpfy your Website has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "otpfy-your-website" plugin v1.2.0 exhibits a mixed security posture. On the positive side, it demonstrates excellent practices regarding SQL queries, exclusively using prepared statements, and a very high percentage of properly escaped output. The absence of known CVEs and recorded vulnerability history is also a strong indicator of a well-maintained and secure codebase in the past. However, a significant concern arises from the substantial attack surface exposed without proper authentication checks. With 19 out of 20 total entry points lacking authentication, this plugin presents a considerable risk of unauthorized access and potential manipulation of its functionalities by unauthenticated users. The taint analysis, while showing no critical or high severity flows, did identify two flows with unsanitized paths, which, when combined with the unauthenticated entry points, could potentially be exploited.
Key Concerns
- Large attack surface without auth checks
- Flows with unsanitized paths (Taint Analysis)
Otpfy your Website Security Vulnerabilities
Otpfy your Website Release Timeline
Otpfy your Website Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Otpfy your Website Attack Surface
AJAX Handlers 19
Shortcodes 1
WordPress Hooks 17
Maintenance & Trust
Otpfy your Website Maintenance & Trust
Maintenance Signals
Community Trust
Otpfy your Website Alternatives
WSMS (formerly WP SMS) – SMS & MMS Notifications with OTP and 2FA for WooCommerce
wp-sms
Send SMS/MMS notifications, OTP & 2FA messages, and WooCommerce updates with support for multiple gateways and plugin integrations.
Email OTP Authenticator – Login, Register, 2FA & Session Lock
email-otp-authenticator
An advanced OTP-powered plugin for Login, Registration, 2FA Protection and Dynamic Session Security. It is FAST, FRIENDLY, SMART, SMOOTH & SECURE.
Ultimate SMS Notifications – Messaging, Alerts & OTP
ultimate-sms
Send SMS/MMS notifications, OTP & 2FA messages, and WooCommerce updates with support for multiple gateways and plugin integrations.
Two Factor
two-factor
Enable Two-Factor Authentication (2FA) using time-based one-time passwords (TOTP), email, and backup verification codes.
miniOrange OTP Login, Verification and SMS Notifications
miniorange-otp-verification
OTP Verification via Email/SMS/WhatsApp,SMS Notifications for WooCommerce,OTP Login with Phone,PasswordLess Login.Custom Gateway for OTP Verification
Otpfy your Website Developer Profile
1 plugin · 0 total installs
How We Detect Otpfy your Website
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/otpfy-your-website/admin/css/bulma.min.css/wp-content/plugins/otpfy-your-website/admin/css/otpfy-deactivation-popup.css/wp-content/plugins/otpfy-your-website/admin/css/otpfy-for-wordpress-admin.css/wp-content/plugins/otpfy-your-website/admin/js/otpfy-for-wordpress-admin.js/wp-content/plugins/otpfy-your-website/admin/js/otpfy-for-wordpress-admin-topbar.js/wp-content/plugins/otpfy-your-website/admin/js/jquery.dataTables.min.js/wp-content/plugins/otpfy-your-website/admin/css/jquery.dataTables.min.css/wp-content/plugins/otpfy-your-website/admin/js/otpfy-for-wordpress-admin.js/wp-content/plugins/otpfy-your-website/admin/js/otpfy-for-wordpress-admin-topbar.jsotpfy-for-wordpress-admin.css?ver=otpfy-for-wordpress-admin.js?ver=otpfy-for-wordpress-admin-topbar.js?ver=HTML / DOM Fingerprints
otpfy-deactivation-popup-containerdata-nonce_request_for_api_keydata-nonce_get_message_log_listdata-nonce_remove_api_keydata-nonce_credits_buy_pricingdata-nonce_send_test_otpdata-nonce_mess_delivery_report+1 morebitss_otpfybitss_otpfy_topbar