
Smart Marketing SMS and Newsletters Forms Security & Risk Analysis
wordpress.org/plugins/smart-marketing-for-wpE-commerce Automation Engine: Product sync, Track & Engage, and abandoned cart recovery via Email and SMS for WooCommerce stores.
Is Smart Marketing SMS and Newsletters Forms Safe to Use in 2026?
Generally Safe
Score 99/100Smart Marketing SMS and Newsletters Forms has a strong security track record. Known vulnerabilities have been patched promptly.
The 'smart-marketing-for-wp' v5.1.08 plugin exhibits a concerning security posture primarily due to a large number of unprotected entry points. With 41 out of 44 total entry points lacking authentication checks, the plugin exposes a significant attack surface to unauthorized users. While the plugin utilizes prepared statements for a majority of its SQL queries and has a decent output escaping rate, the sheer volume of unprotected AJAX handlers is a critical weakness. Taint analysis reveals two high-severity flows with unsanitized paths, which could lead to various vulnerabilities if exploited. The vulnerability history shows two medium-severity CVEs, one of which was a Cross-site Scripting (XSS) vulnerability, and the plugin's last known vulnerability was recent, indicating a pattern of security issues. While the plugin demonstrates some good security practices like nonce and capability checks, and a good rate of prepared SQL statements, these are overshadowed by the extensive lack of authorization on its entry points and the presence of high-severity taint flows.
Key Concerns
- Large attack surface without auth checks
- High severity taint flows found
- Uses dangerous function unserialize
- Past vulnerabilities found (medium severity)
- Past XSS vulnerability found
Smart Marketing SMS and Newsletters Forms Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Smart Marketing SMS and Newsletters Forms <= 5.0.4 - Missing Authorization
Smart Marketing SMS and Newsletters Forms < 2.0.0 - Cross-Site Scripting
Smart Marketing SMS and Newsletters Forms Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Smart Marketing SMS and Newsletters Forms Attack Surface
AJAX Handlers 42
Shortcodes 2
WordPress Hooks 74
Scheduled Events 1
Maintenance & Trust
Smart Marketing SMS and Newsletters Forms Maintenance & Trust
Maintenance Signals
Community Trust
Smart Marketing SMS and Newsletters Forms Alternatives
Brevo for WooCommerce
woocommerce-sendinblue-newsletter-subscription
All-in-one WooCommerce email marketing, automation, SMS, and CRM by Brevo. Grow your store with powerful marketing tools.
FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce
wp-marketing-automations
Recover lost revenue with Cart Abandonment Recovery for WooCommerce. Increase retention with Post Purchase Follow-Up Emails.
CleverReach® WP
cleverreach-wp
Connect your WordPress account with our easy-to-use email software and increase the success of your website or blog with newsletter marketing!
Newsletter Sign-Up for CleverReach
cleverreach
Easily integrate a CleverReach Sign-Up form in your website. Supports widget, shortcode, comment integration and template function
Drip for WordPress
email-marketing
Do you sell online? If so you need our new Drip for WooCommerce Plugin instead of this one. It includes your entire product catalog, order history int …
Smart Marketing SMS and Newsletters Forms Developer Profile
3 plugins · 1K total installs
How We Detect Smart Marketing SMS and Newsletters Forms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/smart-marketing-for-wp/public/css/components.css/wp-content/plugins/smart-marketing-for-wp/public/css/smart-forms.css/wp-content/plugins/smart-marketing-for-wp/public/css/egoi-style.css/wp-content/plugins/smart-marketing-for-wp/public/js/egoi-public.js/wp-content/plugins/smart-marketing-for-wp/public/js/egoi-forms.js/wp-content/plugins/smart-marketing-for-wp/public/js/smart-forms.js/wp-content/plugins/smart-marketing-for-wp/public/js/components.js/wp-content/plugins/smart-marketing-for-wp/public/js/egoi-public.js/wp-content/plugins/smart-marketing-for-wp/public/js/egoi-forms.js/wp-content/plugins/smart-marketing-for-wp/public/js/smart-forms.js/wp-content/plugins/smart-marketing-for-wp/public/js/components.js/wp-content/plugins/smart-marketing-for-wp/public/css/components.css?ver=/wp-content/plugins/smart-marketing-for-wp/public/css/smart-forms.css?ver=/wp-content/plugins/smart-marketing-for-wp/public/css/egoi-style.css?ver=/wp-content/plugins/smart-marketing-for-wp/public/js/egoi-public.js?ver=/wp-content/plugins/smart-marketing-for-wp/public/js/egoi-forms.js?ver=/wp-content/plugins/smart-marketing-for-wp/public/js/smart-forms.js?ver=/wp-content/plugins/smart-marketing-for-wp/public/js/components.js?ver=HTML / DOM Fingerprints
egoi-forms-wrapperegoi-forms-containeregoi-forms-titleegoi-forms-labelegoi-forms-inputegoi-forms-textareaegoi-forms-buttonegoi-forms-select+4 more<!-- E-GOI FORM START --><!-- E-GOI FORM END -->data-egoi-form-iddata-egoi-list-iddata-egoi-form-actiondata-egoi-form-methoddata-egoi-input-typedata-egoi-requiredEgoiPublicegoi_dataEgoiForms[egoi-simple-form]