
Sell eSIM Security & Risk Analysis
wordpress.org/plugins/sell-esimEmpower your business by seamlessly selling eSIMs with our user-friendly WordPress plugin
Is Sell eSIM Safe to Use in 2026?
Generally Safe
Score 92/100Sell eSIM has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The sell-esim plugin v1.0.33 exhibits a generally strong security posture based on the provided static analysis. The plugin has a relatively large attack surface of 29 REST API routes, but importantly, all of these routes include permission callbacks, indicating that access control is being considered. The absence of unprotected AJAX handlers, shortcodes, cron events, and file operations is a positive sign. Furthermore, the plugin demonstrates good coding practices by using prepared statements for a significant majority (73%) of its SQL queries and properly escaping a high percentage (93%) of its output. The lack of reported vulnerabilities in its history and the absence of critical or high-severity taint flows further contribute to its good security profile.
However, there are areas for improvement that introduce minor risks. The complete absence of nonce checks across all entry points (AJAX and REST API) is a notable weakness. While the REST API routes have permission checks, nonce checks are a crucial defense against Cross-Site Request Forgery (CSRF) attacks, especially for actions that modify data. Similarly, the complete lack of capability checks, even with permission callbacks on REST API routes, leaves a gap in ensuring that authenticated users have the appropriate permissions to perform specific actions. The presence of external HTTP requests without clear context about their security implications also warrants attention.
In conclusion, the sell-esim plugin v1.0.33 is built with several secure coding practices, particularly in SQL query handling and output escaping, and benefits from a clean vulnerability history. The main concerns stem from the lack of nonce and capability checks, which are fundamental security mechanisms for WordPress plugins. Addressing these omissions would significantly enhance its overall security posture and reduce potential attack vectors.
Key Concerns
- Missing nonce checks across all entry points
- Missing capability checks across all entry points
- 73% of SQL queries using prepared statements (27% not)
- 6 external HTTP requests without clear context
Sell eSIM Security Vulnerabilities
Sell eSIM Release Timeline
Sell eSIM Code Analysis
SQL Query Safety
Output Escaping
Sell eSIM Attack Surface
REST API Routes 29
WordPress Hooks 12
Maintenance & Trust
Sell eSIM Maintenance & Trust
Maintenance Signals
Community Trust
Sell eSIM Alternatives
DataPlans eSIMs for WooCommerce
dataplans-esims-for-woocommerce
Sell eSIMs for digital delivery with WooCommerce and DataPlans.io
OXeSIM Partners
oxesim-partners
WooCommerce connector for approved OXeSIM partners.
SimVox eSIM Integration
simvox
Integrate SimVox eSIM products with WooCommerce, allowing customers to purchase and activate data packages for travel.
Airalo
airalo
The Airalo plugin allows you to seamlessly sync our products with your store.
Yesim – eSIM Plan Importer (EPI)
yesimteam-esim-plan-importer
Import eSIM plans into WooCommerce, auto-create products, and deliver localized QR code and eSIM Passport emails after purchase.
Sell eSIM Developer Profile
1 plugin · 10 total installs
How We Detect Sell eSIM
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sell-esim/assets/sell-esim-style.css/wp-content/plugins/sell-esim/assets/sell-esim-script.js/wp-content/plugins/sell-esim/assets/sell-esim-script.jsHTML / DOM Fingerprints
/wp-json/sellesim/v1/package/package_list//wp-json/sellesim/v1/package/package_detail//wp-json/sellesim/v1/product/category//wp-json/sellesim/v1/product/product_list//wp-json/sellesim/v1/product/product_detail//wp-json/sellesim/v1/product/banner//wp-json/sellesim/v1/order/place_order//wp-json/sellesim/v1/order/order_list//wp-json/sellesim/v1/order/order_detail//wp-json/sellesim/v1/order/query_order_status//wp-json/sellesim/v1/test//wp-json/sellesim/v1/user/send_register_email_verify//wp-json/sellesim/v1/user/send_change_email_verify//wp-json/sellesim/v1/user/change_email//wp-json/sellesim/v1/user/register//wp-json/sellesim/v1/user/reset_password_link_send/