Powerful SMS Security & Risk Analysis

wordpress.org/plugins/powerful-sms

Plugin para enviar notificação por SMS após fazer pedidos usando WooCommerce e outras integrações do Woocommerce

0 active installs v1.0.0 PHP + WP 3.0.1+ Updated Jul 18, 2022
disparoprosms
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Powerful SMS Safe to Use in 2026?

Generally Safe

Score 85/100

Powerful SMS has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "powerful-sms" plugin v1.0.0 exhibits a mixed security posture. While it demonstrates good practices in SQL query handling and output escaping, indicating some developer awareness of security, significant concerns arise from the lack of authentication and capability checks on entry points. The presence of the `unserialize` function without clear sanitization or context is a critical risk. The plugin's vulnerability history, being entirely clean, is a positive sign. However, this cleanliness might be coincidental rather than indicative of robust security testing, especially given the identified code signals. In conclusion, while the plugin avoids common pitfalls like raw SQL and unpatched CVEs, the potential for remote code execution via `unserialize` and the complete absence of authorization checks on its limited attack surface present a notable risk that should not be overlooked. The lack of taint analysis results is also a weakness, as it prevents a deeper understanding of potential data flow vulnerabilities.

Key Concerns

  • Dangerous function 'unserialize' used
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

Powerful SMS Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Powerful SMS Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

Powerful SMS Code Analysis

Dangerous Functions
2
Raw SQL Queries
0
2 prepared
Unescaped Output
1
16 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Dangerous Functions Found

unserialize$codigos = unserialize ( $rData['wc_any_shipping_notify_tracking_code'] );includes/add-ons/class-powerful-sms-wp-woocommerce.php:282
unserialize$data = @unserialize($rData['wc_shipment_tracking_items']);includes/add-ons/class-powerful-sms-wp-woocommerce.php:312

SQL Query Safety

100% prepared2 total queries

Output Escaping

94% escaped17 total outputs
Attack Surface

Powerful SMS Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 17
actionadmin_noticesadmin/class-powerful-sms-wp-admin.php:131
actionadmin_noticesadmin/class-powerful-sms-wp-admin.php:133
actionadmin_noticesadmin/class-powerful-sms-wp-admin.php:148
filterpsms_replace_modeloincludes/add-ons/class-powerful-sms-wp-woocommerce.php:69
actionplugins_loadedincludes/class-powerful-sms-wp.php:152
actionadmin_enqueue_scriptsincludes/class-powerful-sms-wp.php:167
actionadmin_enqueue_scriptsincludes/class-powerful-sms-wp.php:168
actionadmin_menuincludes/class-powerful-sms-wp.php:171
actionwoocommerce_admin_order_data_after_shipping_addressincludes/class-powerful-sms-wp.php:174
actionsave_postincludes/class-powerful-sms-wp.php:175
actioninitincludes/class-powerful-sms-wp.php:192
actionpac_send_failpublic/class-powerful-sms-wp-public.php:83
actionwoocommerce_order_status_changedpublic/class-powerful-sms-wp-public.php:101
actionpsms_reminder_actionpublic/class-powerful-sms-wp-public.php:111
actionwoocommerce_review_order_before_paymentpublic/class-powerful-sms-wp-public.php:115
actionwoocommerce_after_order_notespublic/class-powerful-sms-wp-public.php:117
actionwoocommerce_checkout_update_order_metapublic/class-powerful-sms-wp-public.php:119

Scheduled Events 2

psms_reminder_action
psms_reminder_action
Maintenance & Trust

Powerful SMS Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedJul 18, 2022
PHP min version
Downloads629

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Powerful SMS Developer Profile

Felipe Peixoto

4 plugins · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Powerful SMS

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/powerful-sms-wp/admin/css/jquery-ui.min.css/wp-content/plugins/powerful-sms-wp/admin/css/powerful-sms-wp-admin.css/wp-content/plugins/powerful-sms-wp/admin/js/powerful-sms-wp-admin.js
Version Parameters
powerful-sms-wp/admin/css/powerful-sms-wp-admin.css?ver=powerful-sms-wp/admin/js/powerful-sms-wp-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
notice-successnotice-error
Data Attributes
name="psms_notify"name="psms_notify_update_flag"name="psms-disparopro-token"
FAQ

Frequently Asked Questions about Powerful SMS