Serverclub.Digital SMS for WooCommerce Security & Risk Analysis

wordpress.org/plugins/serverclub-digital-sms-for-woocommerce

Serverclub.Digital is a popular SMS gateway for Sri Lanka which you can use to send transactional or bulk SMS to your customers.

10 active installs v1.0 PHP + WP 3.0.1+ Updated Jun 19, 2021
serverclub-smsserverclub-digitalsmssri-lankawoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Serverclub.Digital SMS for WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

Serverclub.Digital SMS for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The static analysis of serverclub-digital-sms-for-woocommerce v1.0 indicates a strong security posture in several key areas. There are no identified dangerous functions, all SQL queries utilize prepared statements, and output is properly escaped. Furthermore, the absence of file operations and the use of prepared statements suggest a good foundation for preventing common web vulnerabilities. The plugin's vulnerability history is also clean, with no recorded CVEs, which is a positive indicator.

However, the analysis reveals some concerning omissions. The complete lack of any capability checks and nonce checks is a significant weakness. While the attack surface appears small in terms of AJAX, REST API, and shortcodes, the absence of authentication and authorization checks on any potential entry points means that any functionality exposed, even if not directly listed in the attack surface, could be vulnerable to unauthorized access or manipulation. The single external HTTP request also warrants attention, as its purpose and whether it is made securely would need further investigation.

In conclusion, while the plugin demonstrates good coding practices regarding SQL and output handling, the critical lack of authorization checks presents a substantial risk. This oversight can undermine the security of any functionality the plugin provides, regardless of how limited the initial attack surface appears. The absence of historical vulnerabilities is positive but does not mitigate the inherent risks from the current code's structural weaknesses.

Key Concerns

  • No capability checks
  • No nonce checks
  • External HTTP request without analysis
Vulnerabilities
None known

Serverclub.Digital SMS for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Serverclub.Digital SMS for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0
Attack Surface

Serverclub.Digital SMS for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionwoocommerce_order_status_changedincludes\ServerClubDigitalTrigger.php:41
actionwoocommerce_new_customer_noteincludes\ServerClubDigitalTrigger.php:42
filterwoocommerce_settings_tabs_arrayincludes\ServerClubSMS.php:19
actionwoocommerce_settings_tabs_settings_tab_serverclubdigitalincludes\ServerClubSMS.php:20
actionwoocommerce_update_options_settings_tab_serverclubdigitalincludes\ServerClubSMS.php:21
actionwoocommerce_order_status_processingincludes\ServerClubSMS.php:26
Maintenance & Trust

Serverclub.Digital SMS for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.15
Last updatedJun 19, 2021
PHP min version
Downloads814

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Serverclub.Digital SMS for WooCommerce Developer Profile

ServerClub.LK Private Limited

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Serverclub.Digital SMS for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/serverclub-digital-sms-for-woocommerce/assets/css/admin.css/wp-content/plugins/serverclub-digital-sms-for-woocommerce/assets/js/admin.js
Script Paths
/wp-content/plugins/serverclub-digital-sms-for-woocommerce/assets/js/admin.js
Version Parameters
serverclub-digital-sms-for-woocommerce/assets/css/admin.css?ver=serverclub-digital-sms-for-woocommerce/assets/js/admin.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Serverclub.Digital SMS for WooCommerce