
SMS Notifications for WooCommerce Security & Risk Analysis
wordpress.org/plugins/sms-notifications-for-woocommerceSends SMS notifications to your clients for order status changes. You can also receive an SMS message when a new order is received.
Is SMS Notifications for WooCommerce Safe to Use in 2026?
Generally Safe
Score 85/100SMS Notifications for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "sms-notifications-for-woocommerce" plugin v2.0.2 presents a concerning security posture primarily due to a large unprotected attack surface. With 13 out of 14 entry points lacking authentication checks, this plugin is highly vulnerable to unauthorized access and manipulation. While the code analysis shows no critical or high severity taint flows and a good rate of output escaping, the absence of nonce and capability checks on AJAX handlers is a significant oversight that can lead to various client-side and server-side attacks.
The plugin's SQL query usage is also a major concern, with 100% of queries not using prepared statements. This opens the door to SQL injection vulnerabilities, especially given the large number of unprotected AJAX endpoints. The lack of vulnerability history is a positive sign, suggesting past security diligence or a lack of public discovery, but it does not negate the immediate risks identified in the static analysis. The overall assessment highlights a plugin with potential for secure operation if core security practices were implemented, but currently carries substantial risks.
Key Concerns
- Large attack surface without auth checks
- AJAX handlers without auth checks
- SQL queries without prepared statements
- Missing nonce checks
- Missing capability checks
- Unescaped output (20% of total)
SMS Notifications for WooCommerce Security Vulnerabilities
SMS Notifications for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
SMS Notifications for WooCommerce Attack Surface
AJAX Handlers 13
Shortcodes 1
WordPress Hooks 30
Scheduled Events 1
Maintenance & Trust
SMS Notifications for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
SMS Notifications for WooCommerce Alternatives
WSMS (formerly WP SMS) – SMS & MMS Notifications with OTP and 2FA for WooCommerce
wp-sms
Send SMS/MMS notifications, OTP & 2FA messages, and WooCommerce updates with support for multiple gateways and plugin integrations.
ShopMagic – Twilio SMS
shopmagic-for-twilio
Send WooCommerce SMS notifications, reminders, and text messages to your customers. The plugin is the ShopMagic add-on and it lets you send sms remind …
Ultimate WP Mail
ultimate-wp-mail
Custom email and SMS notifications. Automatic send actions. WPForms SMS integration. WooCommerce notifications for purchases, abandoned cart and more!
WC – APG SMS Notifications
woocommerce-apg-sms-notifications
Add to your WooCommerce store SMS notifications to your customers when order status changed.
Alpha SMS
alpha-sms
Connect your WordPress and WooCommerce store to Alpha SMS for OTP verification and order notifications in Bangladesh.
SMS Notifications for WooCommerce Developer Profile
1 plugin · 10 total installs
How We Detect SMS Notifications for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sms-notifications-for-woocommerce/suwcsms-admin.css/wp-content/plugins/sms-notifications-for-woocommerce/suwcsms-admin.js/wp-content/plugins/sms-notifications-for-woocommerce/suwcsms-admin.jssms-notifications-for-woocommerce/suwcsms-admin.css?ver=sms-notifications-for-woocommerce/suwcsms-admin.js?ver=HTML / DOM Fingerprints
suwcsms-admin-wrap<!-- SMS Notifications for WooCommerce Settings -->data-plugin-name="sms-notifications-for-woocommerce"suwcsms_data