SMS Media4u Login Security & Risk Analysis

wordpress.org/plugins/sms-media4u-login

This plugin adds the functionality to send SMS by use of Media4u in order to login WordPress.

0 active installs v1.0.1 PHP + WP 5.3+ Updated Nov 6, 2022
loginmedia4usendshort-message-servicesms
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is SMS Media4u Login Safe to Use in 2026?

Generally Safe

Score 85/100

SMS Media4u Login has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "sms-media4u-login" v1.0.1 plugin demonstrates a generally good security posture based on the provided static analysis. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events that would significantly expand the attack surface. The code also shows a commitment to secure coding practices with 100% of SQL queries using prepared statements and a high percentage of output being properly escaped. The presence of nonce and capability checks further indicates an effort to protect against common web vulnerabilities. However, the presence of 3 flows with unsanitized paths, even if not categorized as critical or high severity, warrants attention. These flows represent potential vectors for attack if user-controlled input is not adequately validated or sanitized before being used in sensitive operations, despite the absence of direct SQL injection or other critical vulnerabilities indicated by the taint analysis.

The plugin's vulnerability history is completely clear, with no recorded CVEs. This is a strong positive indicator of past security diligence. The lack of any past vulnerabilities, especially of higher severity, suggests that the development team may be proactive or fortunate in their coding. Despite the positive indicators, the existence of unsanitized paths in the taint analysis is the primary concern. While the absence of critical vulnerabilities and a clean history are encouraging, these flows could still lead to unexpected behavior or be exploited in conjunction with other, less obvious issues. Therefore, while the plugin is currently in a relatively safe state, the identified unsanitized paths should be investigated to ensure they do not pose a latent risk.

Key Concerns

  • Flows with unsanitized paths
Vulnerabilities
None known

SMS Media4u Login Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

SMS Media4u Login Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
15 escaped
Nonce Checks
2
Capability Checks
1
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

88% escaped17 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

6 flows3 with unsanitized paths
sms_media4u_login_admin_notices (sms-media4u-login.php:58)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

SMS Media4u Login Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
actionplugins_loadedsms-media4u-login.php:33
actionadmin_menusms-media4u-login.php:34
filterlogin_redirectsms-media4u-login.php:35
actionwp_authenticatesms-media4u-login.php:36
actionlogin_form_smssms-media4u-login.php:37
actionadmin_initsms-media4u-login.php:38
actionshow_user_profilesms-media4u-login.php:39
actionedit_user_profilesms-media4u-login.php:40
actionuser_new_formsms-media4u-login.php:41
actionprofile_updatesms-media4u-login.php:42
actionuser_registersms-media4u-login.php:43
actionadmin_noticessms-media4u-login.php:50
Maintenance & Trust

SMS Media4u Login Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedNov 6, 2022
PHP min version
Downloads763

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

SMS Media4u Login Developer Profile

Hiroaki Miyashita

12 plugins · 43K total installs

71
trust score
Avg Security Score
88/100
Avg Patch Time
223 days
View full developer profile
Detection Fingerprints

How We Detect SMS Media4u Login

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Data Attributes
teluse_sms_media4u
FAQ

Frequently Asked Questions about SMS Media4u Login