
E-goi SMS Orders Alert/Notifications Security & Risk Analysis
wordpress.org/plugins/sms-orders-alertnotifications-for-woocommerceSMS Order Alerts for WooCommerce: Increase conversions by sending status, shipping, and Multibanco/PagSeguro payment reminders via SMS.
Is E-goi SMS Orders Alert/Notifications Safe to Use in 2026?
Generally Safe
Score 100/100E-goi SMS Orders Alert/Notifications has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "sms-orders-alertnotifications-for-woocommerce" v2.0.4 exhibits a mixed security posture. While the majority of SQL queries are prepared and output escaping is generally well-implemented, there are significant concerns regarding its attack surface. A substantial number of AJAX handlers (9 out of 9) lack authentication checks, presenting a direct and easily exploitable avenue for attackers. Additionally, the presence of the `unserialize` function, while not directly flagged in taint analysis, inherently carries risks if user-controlled data is passed to it without proper sanitization, which could lead to serious vulnerabilities.
The plugin's clean vulnerability history is a positive sign, suggesting that the developers have either been diligent in patching issues or have not historically introduced major security flaws. However, the current code analysis reveals a critical weakness in its attack surface that could be exploited even without a historical track record of vulnerabilities. The lack of authorization checks on numerous AJAX endpoints is the most pressing concern, potentially allowing unauthorized users to trigger plugin functionalities. While taint analysis shows no current unsanitized flows, the combination of a large unprotected attack surface and the use of a dangerous function like `unserialize` warrants caution.
Key Concerns
- 9 AJAX handlers without auth checks
- 8 dangerous functions (unserialize)
E-goi SMS Orders Alert/Notifications Security Vulnerabilities
E-goi SMS Orders Alert/Notifications Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
E-goi SMS Orders Alert/Notifications Attack Surface
AJAX Handlers 9
REST API Routes 1
WordPress Hooks 29
Scheduled Events 2
Maintenance & Trust
E-goi SMS Orders Alert/Notifications Maintenance & Trust
Maintenance Signals
Community Trust
E-goi SMS Orders Alert/Notifications Alternatives
Sales Notifications for WooCommerce – Recent Sales Popup
wc-live-sale-notifications
Sales Notifications for WooCommerce - Recent Sales Popup boosts sales by showing recent orders in a popup with customer and product details.
SMS8.io
sms8-io
FREE SMS 8 plugin is a WordPress plugin that allows you to send SMS notifications to your customers instantly when they place an order on your WooComm …
SMSConnectWoo Unify SMS Gateway Center
sms-connect-woo-unify-sms-gateway-center
Enhance your WooCommerce store with instant SMS alerts for order updates and engage customers with automated messages using unify.smsgateway.
Velstack SMS For WooCommerce
velstack-sms-for-woocommerce
Velstack SMS For WooCommerce enables automatic SMS notifications for order updates.
WSMS (formerly WP SMS) – SMS & MMS Notifications with OTP and 2FA for WooCommerce
wp-sms
Send SMS/MMS notifications, OTP & 2FA messages, and WooCommerce updates with support for multiple gateways and plugin integrations.
E-goi SMS Orders Alert/Notifications Developer Profile
3 plugins · 1K total installs
How We Detect E-goi SMS Orders Alert/Notifications
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sms-orders-alertnotifications-for-woocommerce/js/scripts.js/wp-content/plugins/sms-orders-alertnotifications-for-woocommerce/css/style.css/wp-content/plugins/sms-orders-alertnotifications-for-woocommerce/js/scripts.jssms-orders-alertnotifications-for-woocommerce/js/scripts.js?ver=sms-orders-alertnotifications-for-woocommerce/css/style.css?ver=HTML / DOM Fingerprints
egoi-sms-order-settings<!-- To use this plugin, you first need to install<!-- By removing this plugin, you will no longer be able to use the SMS plugindata-egoi-sms-order-iddata-egoi-sms-order-statuswindow.egoi_sms_order_settings