
Rahrayan WP SMS PLUGIN Security & Risk Analysis
wordpress.org/plugins/rahrayan-wp-smsاین پلاگین توسط شرکت مهندسی ره رایان برای وردپرس و ووکامرس نوشته شده و به شما اجازه میدهد پنل پیامک را به وب سایت و فروشگاه اینترنتی خود متصل کنید.
Is Rahrayan WP SMS PLUGIN Safe to Use in 2026?
Generally Safe
Score 85/100Rahrayan WP SMS PLUGIN has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "rahrayan-wp-sms" plugin v0.5.1 exhibits a mixed security posture. While it boasts no known CVEs and a seemingly small attack surface with no unprotected entry points, the static analysis reveals significant concerns. The presence of the `unserialize` function is a critical red flag, especially without clear indications of sanitization around its usage. Furthermore, a low percentage of SQL queries using prepared statements (12%) and a similarly low rate of proper output escaping (15%) suggest a high likelihood of vulnerabilities such as SQL injection and cross-site scripting (XSS). The taint analysis, while reporting no critical or high severity flows, did find four flows with unsanitized paths, indicating potential for data manipulation if these paths are reachable and not properly handled by other security mechanisms. The plugin's vulnerability history being entirely clean could be a positive sign of diligence or simply an artifact of limited public scrutiny or past audits. However, the code signals strongly suggest inherent risks that could be exploited in the absence of further, more granular security testing.
Key Concerns
- Use of unserialize function
- Low percentage of prepared SQL statements
- Low percentage of properly escaped output
- Unsanitized paths in taint analysis
Rahrayan WP SMS PLUGIN Security Vulnerabilities
Rahrayan WP SMS PLUGIN Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Rahrayan WP SMS PLUGIN Attack Surface
Shortcodes 1
WordPress Hooks 51
Maintenance & Trust
Rahrayan WP SMS PLUGIN Maintenance & Trust
Maintenance Signals
Community Trust
Rahrayan WP SMS PLUGIN Alternatives
No alternatives data available yet.
Rahrayan WP SMS PLUGIN Developer Profile
1 plugin · 10 total installs
How We Detect Rahrayan WP SMS PLUGIN
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/rahrayan-wp-sms/includes/js/script.js/wp-content/plugins/rahrayan-wp-sms/includes/css/style.css/wp-content/plugins/rahrayan-wp-sms/includes/css/admin.css/wp-content/plugins/rahrayan-wp-sms/includes/css/admin_message.css/wp-content/plugins/rahrayan-wp-sms/includes/css/admin_group.css/wp-content/plugins/rahrayan-wp-sms/includes/css/admin_setting.css/wp-content/plugins/rahrayan-wp-sms/includes/css/admin_widget.css/wp-content/plugins/rahrayan-wp-sms/includes/js/script.jsrahrayan-wp-sms/includes/js/script.js?ver=rahrayan-wp-sms/includes/css/style.css?ver=rahrayan-wp-sms/includes/css/admin.css?ver=rahrayan-wp-sms/includes/css/admin_message.css?ver=rahrayan-wp-sms/includes/css/admin_group.css?ver=rahrayan-wp-sms/includes/css/admin_setting.css?ver=rahrayan-wp-sms/includes/css/admin_widget.css?ver=HTML / DOM Fingerprints
rahrayan_sms<!--rahrayan-->data-rahrayan-idrahrayan_ajaxurl[rahrayan-sms][rahrayan-sms-widget]