
SMS Manager – SMS Notifications for WooCommerce Security & Risk Analysis
wordpress.org/plugins/sms-managerSMS Manager for WooCommerce allows you to send SMS notifications to your customers.
Is SMS Manager – SMS Notifications for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100SMS Manager – SMS Notifications for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "sms-manager" plugin v1.2.1 demonstrates a strong security posture based on the provided static analysis. The complete absence of identified dangerous functions, raw SQL queries, and unsanitized taint flows, combined with 100% output escaping and the use of prepared statements, indicates robust secure coding practices. The plugin also appears to have a very limited attack surface, with no exposed AJAX handlers, REST API routes, shortcodes, or cron events that lack authentication or permission checks. This is a significant strength.
However, there are a few areas that warrant attention. The presence of an external HTTP request, even if only one, introduces a potential dependency risk. While the analysis shows a capability check is in place for this, the specific nature and sanitization of data sent to this external endpoint are not detailed. Furthermore, the complete absence of nonce checks across all entry points (though there are no entry points listed as unprotected) is a notable omission in a typical WordPress security hardening strategy, especially if any future functionalities are added that might involve user interaction.
Given the lack of any recorded historical vulnerabilities (CVEs), this plugin has a very clean track record, suggesting a commitment to security by its developers. The overall assessment is positive, with the plugin exhibiting many good security practices. The few identified areas for improvement are minor in comparison to the strengths shown, but addressing the external HTTP request's details and considering nonce implementation for future extensibility would further enhance its security.
Key Concerns
- External HTTP request present
- No nonce checks on entry points
SMS Manager – SMS Notifications for WooCommerce Security Vulnerabilities
SMS Manager – SMS Notifications for WooCommerce Release Timeline
SMS Manager – SMS Notifications for WooCommerce Code Analysis
Output Escaping
SMS Manager – SMS Notifications for WooCommerce Attack Surface
WordPress Hooks 8
Maintenance & Trust
SMS Manager – SMS Notifications for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
SMS Manager – SMS Notifications for WooCommerce Alternatives
WSMS (formerly WP SMS) – SMS & MMS Notifications with OTP and 2FA for WooCommerce
wp-sms
Send SMS/MMS notifications, OTP & 2FA messages, and WooCommerce updates with support for multiple gateways and plugin integrations.
Ultimate SMS Notifications – Messaging, Alerts & OTP
ultimate-sms
Send SMS/MMS notifications, OTP & 2FA messages, and WooCommerce updates with support for multiple gateways and plugin integrations.
SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery
sms-alert
Send WooCommerce SMS notifications, OTP verification, abandoned cart recovery alerts, and real-time order updates to customers and admins.
افزونه پیامک حرفه ای فراز اس ام اس
farazsms
شما می توانید با استفاده از افزونه فراز اس ام اس، سایت خود را با ابزاری خودکار برای ارسال پیامک و ذخیره شماره در دفترچه تلفن، تقویت کنید.
NotifSMS – SMS Notifications OTP & 2FA for WordPress & WooCommerce
wp-twilio-core
Send SMS, OTP & 2FA notifications from WordPress via Twilio. Includes automated alerts, bulk messaging, and integrations with popular plugins.
SMS Manager – SMS Notifications for WooCommerce Developer Profile
10 plugins · 260 total installs
How We Detect SMS Manager – SMS Notifications for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.