
Serverclub.Digital SMS for WooCommerce Security & Risk Analysis
wordpress.org/plugins/serverclub-digital-sms-for-woocommerceServerclub.Digital is a popular SMS gateway for Sri Lanka which you can use to send transactional or bulk SMS to your customers.
Is Serverclub.Digital SMS for WooCommerce Safe to Use in 2026?
Generally Safe
Score 85/100Serverclub.Digital SMS for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of serverclub-digital-sms-for-woocommerce v1.0 indicates a strong security posture in several key areas. There are no identified dangerous functions, all SQL queries utilize prepared statements, and output is properly escaped. Furthermore, the absence of file operations and the use of prepared statements suggest a good foundation for preventing common web vulnerabilities. The plugin's vulnerability history is also clean, with no recorded CVEs, which is a positive indicator.
However, the analysis reveals some concerning omissions. The complete lack of any capability checks and nonce checks is a significant weakness. While the attack surface appears small in terms of AJAX, REST API, and shortcodes, the absence of authentication and authorization checks on any potential entry points means that any functionality exposed, even if not directly listed in the attack surface, could be vulnerable to unauthorized access or manipulation. The single external HTTP request also warrants attention, as its purpose and whether it is made securely would need further investigation.
In conclusion, while the plugin demonstrates good coding practices regarding SQL and output handling, the critical lack of authorization checks presents a substantial risk. This oversight can undermine the security of any functionality the plugin provides, regardless of how limited the initial attack surface appears. The absence of historical vulnerabilities is positive but does not mitigate the inherent risks from the current code's structural weaknesses.
Key Concerns
- No capability checks
- No nonce checks
- External HTTP request without analysis
Serverclub.Digital SMS for WooCommerce Security Vulnerabilities
Serverclub.Digital SMS for WooCommerce Code Analysis
Serverclub.Digital SMS for WooCommerce Attack Surface
WordPress Hooks 6
Maintenance & Trust
Serverclub.Digital SMS for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Serverclub.Digital SMS for WooCommerce Alternatives
Notify.lk SMS for WooCommerce
notifylk-sms-for-woocommerce
Notify.lk is a popular SMS gateway for Sri Lanka which you can use to send transactional or bulk SMS to your customers. This plugin allows you to inte …
Email Marketing for WooCommerce by Omnisend
omnisend-connect
Email Marketing, Newsletter, Email Automation, Forms, Pop Up, SMS, Abandoned Cart made easy for WordPress & WooCommerce by Omnisend
افزونه پیامک ووکامرس Persian WooCommerce SMS
persian-woocommerce-sms
افزونه کامل و حرفه ای برای اطلاع رسانی پیامکی سفارشات و رویداد های محصولات ووکامرس
Brevo for WooCommerce
woocommerce-sendinblue-newsletter-subscription
All-in-one WooCommerce email marketing, automation, SMS, and CRM by Brevo. Grow your store with powerful marketing tools.
WSMS (formerly WP SMS) – SMS & MMS Notifications with OTP and 2FA for WooCommerce
wp-sms
Send SMS/MMS notifications, OTP & 2FA messages, and WooCommerce updates with support for multiple gateways and plugin integrations.
Serverclub.Digital SMS for WooCommerce Developer Profile
1 plugin · 10 total installs
How We Detect Serverclub.Digital SMS for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/serverclub-digital-sms-for-woocommerce/assets/css/admin.css/wp-content/plugins/serverclub-digital-sms-for-woocommerce/assets/js/admin.js/wp-content/plugins/serverclub-digital-sms-for-woocommerce/assets/js/admin.jsserverclub-digital-sms-for-woocommerce/assets/css/admin.css?ver=serverclub-digital-sms-for-woocommerce/assets/js/admin.js?ver=