
refatbd Advanced SMS for WooCommerce Security & Risk Analysis
wordpress.org/plugins/refatbd-advanced-sms-for-woocommerceEnhanced SMS notifications for WooCommerce orders with product rules, history, and a debug log.
Is refatbd Advanced SMS for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100refatbd Advanced SMS for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "refatbd-advanced-sms-for-woocommerce" plugin v2.0.2 exhibits a generally good security posture with several positive indicators. A high percentage of SQL queries use prepared statements and output escaping is robust, significantly mitigating common web application vulnerabilities like SQL injection and XSS. The absence of known CVEs and a clean vulnerability history further suggest a well-maintained and secure codebase. The plugin also demonstrates good practice by including nonce checks for its AJAX handlers.
However, there are specific areas that present a notable risk. The presence of two AJAX handlers that lack authentication checks is a significant concern, potentially allowing unauthenticated users to trigger sensitive actions. While the taint analysis found no critical or high severity issues, the attack surface is relatively small, and these unprotected entry points become more impactful. The use of bundled libraries like Select2 also warrants attention, as outdated versions of such libraries can introduce vulnerabilities if not kept current.
In conclusion, while the plugin demonstrates strong foundational security practices, the unprotected AJAX endpoints are a critical weakness that needs immediate attention. Addressing these unauthenticated entry points would substantially improve the plugin's overall security. The lack of recorded vulnerabilities is positive, but it does not negate the risks identified in the static analysis.
Key Concerns
- AJAX handlers without auth checks
- Bundled library (Select2)
refatbd Advanced SMS for WooCommerce Security Vulnerabilities
refatbd Advanced SMS for WooCommerce Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
refatbd Advanced SMS for WooCommerce Attack Surface
AJAX Handlers 5
WordPress Hooks 17
Scheduled Events 1
Maintenance & Trust
refatbd Advanced SMS for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
refatbd Advanced SMS for WooCommerce Alternatives
SMSDojo
smsdojo
FREE SMSDojo lets you send instant WooCommerce SMS alerts to keep customers informed and engaged throughout their order process.
WSMS (formerly WP SMS) – SMS & MMS Notifications with OTP and 2FA for WooCommerce
wp-sms
Send SMS/MMS notifications, OTP & 2FA messages, and WooCommerce updates with support for multiple gateways and plugin integrations.
افزونه پیامک حرفه ای فراز اس ام اس
farazsms
شما می توانید با استفاده از افزونه فراز اس ام اس، سایت خود را با ابزاری خودکار برای ارسال پیامک و ذخیره شماره در دفترچه تلفن، تقویت کنید.
NotifSMS – SMS Notifications OTP & 2FA for WordPress & WooCommerce
wp-twilio-core
Send SMS, OTP & 2FA notifications from WordPress via Twilio. Includes automated alerts, bulk messaging, and integrations with popular plugins.
ShopMagic – Twilio SMS
shopmagic-for-twilio
Send WooCommerce SMS notifications, reminders, and text messages to your customers. The plugin is the ShopMagic add-on and it lets you send sms remind …
refatbd Advanced SMS for WooCommerce Developer Profile
2 plugins · 0 total installs
How We Detect refatbd Advanced SMS for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/refatbd-advanced-sms-for-woocommerce/assets/css/admin.css/wp-content/plugins/refatbd-advanced-sms-for-woocommerce/assets/js/admin.js/wp-content/plugins/refatbd-advanced-sms-for-woocommerce/assets/js/frontend.jsrefatbd-advanced-sms-for-woocommerce/assets/css/admin.css?ver=refatbd-advanced-sms-for-woocommerce/assets/js/admin.js?ver=refatbd-advanced-sms-for-woocommerce/assets/js/frontend.js?ver=HTML / DOM Fingerprints
refaadsm-admin-settings-wrapperrefaadsm-sms-history-tablerefaadsm-logs-tablerefaadsm-provider-settings<!-- Advanced SMS for WooCommerce --><!-- refaadsm settings start --><!-- refaadsm settings end --><!-- refaadsm logs start -->+1 moredata-refaadsm-ajax-urldata-refaadsm-noncedata-provider-settings-iddata-order-idrefaadsm_ajax_objectrefaadsm_settings_params/wp-json/refatbd-advanced-sms-for-woocommerce/v1/settings/wp-json/refatbd-advanced-sms-for-woocommerce/v1/history/wp-json/refatbd-advanced-sms-for-woocommerce/v1/logs