پیامک پستی سفارشات ووکامرس Security & Risk Analysis
wordpress.org/plugins/postage-tracking-code-smsاین افزونه ارسال کد مرسوله های پستی سفارشات ووکامرس را راحت تر می کند
Is پیامک پستی سفارشات ووکامرس Safe to Use in 2026?
Generally Safe
Score 85/100پیامک پستی سفارشات ووکامرس has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'postage-tracking-code-sms' plugin, in version 1.0.1, exhibits a concerning security posture primarily due to its exposed attack surface. All three identified AJAX handlers lack authentication checks, presenting a significant risk of unauthorized access and potential manipulation of plugin functionality. While the plugin demonstrates good practices by using prepared statements for all SQL queries and having a history free of known vulnerabilities, this is overshadowed by the critical flaw in its entry points. The absence of nonce checks and capability checks on these AJAX handlers further exacerbates the risk, allowing unauthenticated users to potentially trigger actions intended only for logged-in administrators or authorized users. The lack of taint analysis results and the absence of dangerous functions are positive signs, suggesting that the core logic might be sound, but the exposed AJAX handlers are a critical oversight that needs immediate attention. The plugin's clean vulnerability history is a positive indicator, but it does not negate the present, exploitable weaknesses in its current implementation.
Key Concerns
- AJAX handlers without auth checks
- AJAX handlers without nonce checks
- AJAX handlers without capability checks
- Unescaped output (27% not properly escaped)
پیامک پستی سفارشات ووکامرس Security Vulnerabilities
پیامک پستی سفارشات ووکامرس Code Analysis
SQL Query Safety
Output Escaping
پیامک پستی سفارشات ووکامرس Attack Surface
AJAX Handlers 3
WordPress Hooks 4
Maintenance & Trust
پیامک پستی سفارشات ووکامرس Maintenance & Trust
Maintenance Signals
Community Trust
پیامک پستی سفارشات ووکامرس Alternatives
افزونه پیامک حرفه ای فراز اس ام اس
farazsms
شما می توانید با استفاده از افزونه فراز اس ام اس، سایت خود را با ابزاری خودکار برای ارسال پیامک و ذخیره شماره در دفترچه تلفن، تقویت کنید.
Alpha SMS
alpha-sms
Connect your WordPress and WooCommerce store to Alpha SMS for OTP verification and order notifications in Bangladesh.
miniOrange OTP Verification and SMS Notification for WooCommerce
miniorange-sms-order-notification-otp-verification
OTP Verification via SMS, Email,or WhatsApp, and SMS Order Notifications, Vendor Notifications for WooCommerce.OTP Login and registration with Phone →
MoceanAPI Order SMS Notification for WooCommerce
moceansms-order-sms-notification-for-woocommerce
A plugin to send SMS notification to both buyer and seller after an order is placed in WooCommerce. SMS notification can be sent on all order statuses …
SMS for WooCommerce
wc-sms
Order SMS Notifications for Woocommerce
پیامک پستی سفارشات ووکامرس Developer Profile
2 plugins · 40 total installs
How We Detect پیامک پستی سفارشات ووکامرس
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/postage-tracking-code-sms/assets/bootstrap.bundle.min.js/wp-content/plugins/postage-tracking-code-sms/assets/script.js/wp-content/plugins/postage-tracking-code-sms/assets/bootstrap.rtl.min.css/wp-content/plugins/postage-tracking-code-sms/assets/style.css/wp-content/plugins/postage-tracking-code-sms/assets/bootstrap.bundle.min.js/wp-content/plugins/postage-tracking-code-sms/assets/script.jsHTML / DOM Fingerprints
dashicons-woo-tros-ic/wp-json/postage-tracking-code-sms/v1/get-order-details/wp-json/postage-tracking-code-sms/v1/send-sms/wp-json/postage-tracking-code-sms/v1/latest-list