SMS Gateway Center – Bulk SMS Sender Security & Risk Analysis

wordpress.org/plugins/sms-gateway-center-bulk-sms-sender

You need to be a registered member of www.smsgatewaycenter.com. Install this simple plugin and start sending bulk SMS. This gateway supports India and …

10 active installs v1.3.1 PHP 5.6+ WP 5.0+ Updated Dec 8, 2025
bulk-smsmessagesms-gatewaysms-indiasms-message
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is SMS Gateway Center – Bulk SMS Sender Safe to Use in 2026?

Generally Safe

Score 100/100

SMS Gateway Center – Bulk SMS Sender has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The "sms-gateway-center-bulk-sms-sender" v1.3.1 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by using prepared statements for a significant portion of its SQL queries and properly escaping a high percentage of its output. The absence of known vulnerabilities in its history is also a strong indicator of past security diligence. However, the plugin has a notable weakness in its attack surface, with two out of four AJAX handlers lacking authentication checks. This exposes potential entry points for unauthorized actions. Furthermore, the taint analysis reveals eight flows with unsanitized paths, all categorized as high severity. While not explicitly labeled as vulnerabilities, these unsanitized paths represent potential avenues for injection attacks if malicious data is passed through these flows. The presence of bundled libraries like DataTables v1.12.1 and jQuery, while not inherently problematic, requires awareness of their specific versions and any known vulnerabilities associated with them, though none are highlighted here.

Overall, the plugin has strengths in its handling of SQL and output, and a clean vulnerability history. The primary concerns stem from the unprotected AJAX endpoints and the high number of unsanitized taint flows. These areas require immediate attention to mitigate risks of unauthorized access and potential injection vulnerabilities. The plugin's security can be significantly improved by addressing these identified weaknesses.

Key Concerns

  • Unprotected AJAX handlers
  • High severity unsanitized taint flows
Vulnerabilities
None known

SMS Gateway Center – Bulk SMS Sender Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

SMS Gateway Center – Bulk SMS Sender Code Analysis

Dangerous Functions
0
Raw SQL Queries
11
13 prepared
Unescaped Output
15
347 escaped
Nonce Checks
13
Capability Checks
4
File Operations
0
External Requests
13
Bundled Libraries
2

Bundled Libraries

DataTables1.12.1jQuery

SQL Query Safety

54% prepared24 total queries

Output Escaping

96% escaped362 total outputs
Data Flows
8 unsanitized

Data Flow Analysis

8 flows8 with unsanitized paths
process_bulk_action (includes\class-sgcsms-subscribers-groups-table.php:163)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

SMS Gateway Center – Bulk SMS Sender Attack Surface

Entry Points4
Unprotected2

AJAX Handlers 4

authwp_ajax_send_sgcsms_otpincludes\ajax_handlers_regi.php:170
noprivwp_ajax_send_sgcsms_otpincludes\ajax_handlers_regi.php:171
noprivwp_ajax_validate_sgcsms_otpincludes\ajax_handlers_regi.php:260
authwp_ajax_validate_sgcsms_otpincludes\ajax_handlers_regi.php:261
WordPress Hooks 14
actioninitincludes\form_modifications_regi.php:21
actionuser_registerincludes\form_modifications_regi.php:49
actionregister_formincludes\form_modifications_regi.php:52
actionlogin_enqueue_scriptsincludes\form_modifications_regi.php:110
actionregister_postincludes\form_modifications_regi.php:202
actionshow_user_profileincludes\user_profile.php:32
actionedit_user_profileincludes\user_profile.php:33
filtermanage_users_columnsincludes\user_profile.php:50
actionmanage_users_custom_columnincludes\user_profile.php:71
actionadmin_enqueue_scriptssgcsms.php:109
actionadmin_menusgcsms.php:110
filterhttp_request_timeoutsgcsms.php:111
filterplugin_action_linkssgcsms.php:361
actionadmin_noticessgcsms.php:362
Maintenance & Trust

SMS Gateway Center – Bulk SMS Sender Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 8, 2025
PHP min version5.6
Downloads7K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

SMS Gateway Center – Bulk SMS Sender Developer Profile

smsgatewaycenter

3 plugins · 20 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect SMS Gateway Center – Bulk SMS Sender

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sms-gateway-center-bulk-sms-sender/assets/css/sgcsms.css/wp-content/plugins/sms-gateway-center-bulk-sms-sender/assets/js/sgcsms_js.js
Script Paths
/wp-content/plugins/sms-gateway-center-bulk-sms-sender/assets/js/sgcsms_js.js
Version Parameters
sms-gateway-center-bulk-sms-sender/assets/css/sgcsms.css?ver=sms-gateway-center-bulk-sms-sender/assets/js/sgcsms_js.js?ver=

HTML / DOM Fingerprints

CSS Classes
sgcsms_css_sgcsms
JS Globals
sgcsms_js_sgcsms
FAQ

Frequently Asked Questions about SMS Gateway Center – Bulk SMS Sender