
SmokeSignal Security & Risk Analysis
wordpress.org/plugins/smokesignalSend internal messages between registered users in admin section.
Is SmokeSignal Safe to Use in 2026?
Mostly Safe
Score 84/100SmokeSignal is generally safe to use though it hasn't been updated recently. 2 past CVEs were resolved.
The 'smokesignal' plugin v1.2.7 presents a mixed security posture. While it demonstrates good practices in database interaction with all SQL queries utilizing prepared statements and no file operations or external HTTP requests, significant concerns arise from its attack surface and output handling. The presence of two AJAX handlers, both lacking authentication checks, represents a critical vulnerability, exposing the plugin to potential unauthorized actions. Furthermore, the exceptionally low percentage of properly escaped output (4%) indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into web pages viewed by users.
The plugin's vulnerability history, including two known CVEs, one of which was high severity and related to XSS, reinforces these concerns. Although no CVEs are currently unpatched, the historical pattern of XSS vulnerabilities and the static analysis findings of poor output escaping strongly suggest that XSS remains a significant threat for this plugin. The lack of nonce checks on its AJAX endpoints further exacerbates the risk of Cross-Site Request Forgery (CSRF) attacks.
In conclusion, while the plugin avoids common pitfalls like raw SQL queries and file operations, its unprotected entry points, extensive lack of output escaping, and historical XSS issues create a considerable security risk. The developer should prioritize implementing robust authentication and authorization on AJAX handlers and a comprehensive output escaping strategy to mitigate these vulnerabilities.
Key Concerns
- AJAX handlers without auth checks
- Low percentage of properly escaped output
- Missing nonce checks on AJAX
- High severity historical CVE
- Medium severity historical CVE
SmokeSignal Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
SmokeSignal <= 1.2.6 - Cross-Site Scripting
Smoke Signal < 1.2.7 - Authenticated Stored Cross-Site Scripting
SmokeSignal Release Timeline
SmokeSignal Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
SmokeSignal Attack Surface
AJAX Handlers 2
WordPress Hooks 13
Maintenance & Trust
SmokeSignal Maintenance & Trust
Maintenance Signals
Community Trust
SmokeSignal Alternatives
BuddyPress Default Data
bp-default-data
Plugin will create lots of users, messages, friends connections, groups, topics, activity items, profile data - useful for testing purpose.
Import and export users and customers
import-users-from-csv-with-meta
Bulk import and export WordPress users and WooCommerce customers from CSV, including roles, passwords and any custom meta.
Export and Import Users and Customers
users-customers-import-export-for-wp-woocommerce
Import and export WordPress users and WooCommerce customers using CSV. Migrate to your new site without any data loss.
Import Users from CSV
import-users-from-csv
Import users from a CSV into WordPress
Import Users & Customers with Meta | WP Ultimate CSV Importer Add-on
import-users
Bulk import WordPress users and WooCommerce customers with full user meta, custom fields, billing & shipping details, and membership data from CSV …
SmokeSignal Developer Profile
1 plugin · 10 total installs
How We Detect SmokeSignal
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/smokesignal/js/script.js/wp-content/plugins/smokesignal/js/script.jsHTML / DOM Fingerprints
removeMessagemessage