SMS Manager – SMS Notifications for WooCommerce Security & Risk Analysis

wordpress.org/plugins/sms-manager

SMS Manager for WooCommerce allows you to send SMS notifications to your customers.

0 active installs v1.2.1 PHP 7.4+ WP 5.0+ Updated Mar 4, 2026
smssms-managersms-notificationswoocommercewoocommerce-sms
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is SMS Manager – SMS Notifications for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

SMS Manager – SMS Notifications for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "sms-manager" plugin v1.2.1 demonstrates a strong security posture based on the provided static analysis. The complete absence of identified dangerous functions, raw SQL queries, and unsanitized taint flows, combined with 100% output escaping and the use of prepared statements, indicates robust secure coding practices. The plugin also appears to have a very limited attack surface, with no exposed AJAX handlers, REST API routes, shortcodes, or cron events that lack authentication or permission checks. This is a significant strength.

However, there are a few areas that warrant attention. The presence of an external HTTP request, even if only one, introduces a potential dependency risk. While the analysis shows a capability check is in place for this, the specific nature and sanitization of data sent to this external endpoint are not detailed. Furthermore, the complete absence of nonce checks across all entry points (though there are no entry points listed as unprotected) is a notable omission in a typical WordPress security hardening strategy, especially if any future functionalities are added that might involve user interaction.

Given the lack of any recorded historical vulnerabilities (CVEs), this plugin has a very clean track record, suggesting a commitment to security by its developers. The overall assessment is positive, with the plugin exhibiting many good security practices. The few identified areas for improvement are minor in comparison to the strengths shown, but addressing the external HTTP request's details and considering nonce implementation for future extensibility would further enhance its security.

Key Concerns

  • External HTTP request present
  • No nonce checks on entry points
Vulnerabilities
None known

SMS Manager – SMS Notifications for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

SMS Manager – SMS Notifications for WooCommerce Release Timeline

v1.2.1Current
v1.2.0
v1.1.0
v1.0.0
Code Analysis
Analyzed Apr 16, 2026

SMS Manager – SMS Notifications for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
29 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

100% escaped29 total outputs
Attack Surface

SMS Manager – SMS Notifications for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionadmin_menuincludes/Admin/Admin.php:19
actionadmin_initincludes/Admin/Admin.php:22
filterwoocommerce_order_actionsincludes/Handlers/Notifications.php:20
actionwoocommerce_order_action_smsm_send_order_smsincludes/Handlers/Notifications.php:23
actionwoocommerce_order_status_completedincludes/Handlers/Notifications.php:26
actionadmin_noticesincludes/Plugin.php:116
actionbefore_woocommerce_initincludes/Plugin.php:117
actionwoocommerce_initincludes/Plugin.php:118
Maintenance & Trust

SMS Manager – SMS Notifications for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 4, 2026
PHP min version7.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

SMS Manager – SMS Notifications for WooCommerce Developer Profile

BeautifulPlugins

10 plugins · 260 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect SMS Manager – SMS Notifications for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about SMS Manager – SMS Notifications for WooCommerce