
Powerful SMS Security & Risk Analysis
wordpress.org/plugins/powerful-smsPlugin para enviar notificação por SMS após fazer pedidos usando WooCommerce e outras integrações do Woocommerce
Is Powerful SMS Safe to Use in 2026?
Generally Safe
Score 85/100Powerful SMS has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "powerful-sms" plugin v1.0.0 exhibits a mixed security posture. While it demonstrates good practices in SQL query handling and output escaping, indicating some developer awareness of security, significant concerns arise from the lack of authentication and capability checks on entry points. The presence of the `unserialize` function without clear sanitization or context is a critical risk. The plugin's vulnerability history, being entirely clean, is a positive sign. However, this cleanliness might be coincidental rather than indicative of robust security testing, especially given the identified code signals. In conclusion, while the plugin avoids common pitfalls like raw SQL and unpatched CVEs, the potential for remote code execution via `unserialize` and the complete absence of authorization checks on its limited attack surface present a notable risk that should not be overlooked. The lack of taint analysis results is also a weakness, as it prevents a deeper understanding of potential data flow vulnerabilities.
Key Concerns
- Dangerous function 'unserialize' used
- No nonce checks on entry points
- No capability checks on entry points
Powerful SMS Security Vulnerabilities
Powerful SMS Release Timeline
Powerful SMS Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Powerful SMS Attack Surface
WordPress Hooks 17
Scheduled Events 2
Maintenance & Trust
Powerful SMS Maintenance & Trust
Maintenance Signals
Community Trust
Powerful SMS Alternatives
Newsletters, Email Marketing, SMS and Popups by Omnisend
omnisend
Newsletters, Email Marketing, Email Automation, Forms, Pop Up, SMS by Omnisend
Email Marketing for WooCommerce by Omnisend
omnisend-connect
Email Marketing, Newsletter, Email Automation, Forms, Pop Up, SMS, Abandoned Cart made easy for WordPress & WooCommerce by Omnisend
افزونه پیامک ووکامرس Persian WooCommerce SMS
persian-woocommerce-sms
افزونه کامل و حرفه ای برای اطلاع رسانی پیامکی سفارشات و رویداد های محصولات ووکامرس
Brevo for WooCommerce
woocommerce-sendinblue-newsletter-subscription
All-in-one WooCommerce email marketing, automation, SMS, and CRM by Brevo. Grow your store with powerful marketing tools.
Texty – SMS Notification for WordPress, WooCommerce, Dokan and more
texty
Texty is a lightweight SMS notification plugin for WordPress.
Powerful SMS Developer Profile
4 plugins · 10 total installs
How We Detect Powerful SMS
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/powerful-sms-wp/admin/css/jquery-ui.min.css/wp-content/plugins/powerful-sms-wp/admin/css/powerful-sms-wp-admin.css/wp-content/plugins/powerful-sms-wp/admin/js/powerful-sms-wp-admin.jspowerful-sms-wp/admin/css/powerful-sms-wp-admin.css?ver=powerful-sms-wp/admin/js/powerful-sms-wp-admin.js?ver=HTML / DOM Fingerprints
notice-successnotice-errorname="psms_notify"name="psms_notify_update_flag"name="psms-disparopro-token"