Sendit Israel Security & Risk Analysis

wordpress.org/plugins/sendit-israel

Sendit Israel provides a simple SMS integration for WordPress and WooCommerce. Supports order status SMS notifications and Contact Form 7 submissions.

0 active installs v1.0.0 PHP + WP 5.0+ Updated Dec 22, 2025
contact-form-7israelnotificationssmswoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Sendit Israel Safe to Use in 2026?

Generally Safe

Score 100/100

Sendit Israel has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The sendit-israel plugin v1.0.0 exhibits a strong security posture in several key areas. The static analysis reveals no critical vulnerabilities, including no dangerous functions, file operations, or unsanitized taint flows. The complete absence of raw SQL queries, with all queries utilizing prepared statements, is a significant strength. Furthermore, the plugin makes no external HTTP requests, which eliminates a common attack vector. The lack of historical vulnerabilities further supports its current perceived security.

However, there are several areas for improvement. The plugin has zero capability checks and zero nonce checks for its entry points, which are entirely absent. This indicates a potentially large attack surface that is not being adequately secured, especially if any functionality is added later. While the current static analysis shows no unprotected entry points, this is largely due to the absence of any entry points at all. The 75% output escaping rate, while decent, means that 25% of outputs are potentially vulnerable to XSS attacks.

In conclusion, sendit-israel v1.0.0 is currently in a good security state due to the absence of known severe flaws and the use of secure coding practices for database interactions. However, the lack of authentication and authorization checks on potential future entry points, combined with incomplete output escaping, presents a latent risk that should be addressed proactively.

Key Concerns

  • 0 capability checks
  • 0 nonce checks
  • 25% of outputs unescaped
  • 1 external HTTP request
Vulnerabilities
None known

Sendit Israel Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Sendit Israel Release Timeline

v1.0.0Current
Code Analysis
Analyzed Mar 17, 2026

Sendit Israel Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
12 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

75% escaped16 total outputs
Attack Surface

Sendit Israel Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_initsendit-israel.php:79
actionadmin_menusendit-israel.php:92
actionwoocommerce_order_status_changedsendit-israel.php:300
actionwpcf7_mail_sentsendit-israel.php:366
Maintenance & Trust

Sendit Israel Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 22, 2025
PHP min version
Downloads145

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Sendit Israel Developer Profile

UP System

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Sendit Israel

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sendit-israel/sendit-israel.php

HTML / DOM Fingerprints

Data Attributes
name="sendit_api_token"name="sendit_sender"name="sendit_enable_status_sms"name="sendit_sms_enabled_name="sendit_sms_template_name="sendit_cf7_enable"+3 more
Shortcode Output
<p>תוסף WooCommerce אינו פעיל. אינטגרציית Sendit דורשת WooCommerce פעיל.</p>
FAQ

Frequently Asked Questions about Sendit Israel