
SMS Partner Security & Risk Analysis
wordpress.org/plugins/sms-partnerActiver l'A2F ou la connexion via Numéro de téléphone sur votre WordPress grâce à SMS Partner
Is SMS Partner Safe to Use in 2026?
Generally Safe
Score 92/100SMS Partner has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "sms-partner" plugin version 2.6 exhibits a concerning security posture primarily due to its unprotected entry points. While the plugin demonstrates good practices in output escaping, SQL query preparation, and avoids dangerous functions and file operations, the presence of four AJAX handlers without authentication checks represents a significant vulnerability. This lack of authorization could allow unauthenticated users to trigger plugin functionality, potentially leading to unintended actions or information disclosure.
The taint analysis reveals two flows with unsanitized paths, flagged as high severity. This indicates that data processed through these flows might not be adequately validated or sanitized before being used, potentially opening the door for cross-site scripting (XSS) or other injection attacks if these unsanitized paths are reachable by unauthenticated users. Despite these identified risks, the plugin has no recorded history of CVEs, suggesting either a lack of past vulnerabilities or a successful track record of patching if they occurred. However, the current static analysis findings highlight immediate areas for improvement.
In conclusion, while the "sms-partner" plugin has strengths in secure coding practices like output escaping and prepared SQL statements, the high number of unprotected AJAX endpoints and critical taint flows demand urgent attention. The absence of past CVEs is positive but does not negate the present risks identified in the code analysis. Addressing these unprotected entry points and sanitizing the identified data flows is crucial for enhancing the plugin's overall security.
Key Concerns
- 4 unprotected AJAX handlers
- 2 unsanitized taint flows (high severity)
SMS Partner Security Vulnerabilities
SMS Partner Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
SMS Partner Attack Surface
AJAX Handlers 4
WordPress Hooks 21
Maintenance & Trust
SMS Partner Maintenance & Trust
Maintenance Signals
Community Trust
SMS Partner Alternatives
All-In-One Security (AIOS) – Security and Firewall
all-in-one-wp-security-and-firewall
Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy to use security plugin designed especially for WordPress.
Wordfence Login Security
wordfence-login-security
Secure your website with Wordfence Login Security, providing two-factor authentication, login and registration CAPTCHA, and XML-RPC protection.
Titan Anti-spam & Security
anti-spam
Block spam comments, defend against login attempts, and strengthen site security with anti-spam, brute-force protection, and two-factor authentication …
IP & Country Blocker Lite
ip-blocker-lite
Advanced WordPress security plugin with IP/country blocking and two-factor authentication for comprehensive website protection.
Two Factor SMS
two-factor-sms
Add SMS support to "Two Factor" feature as a plugin
SMS Partner Developer Profile
1 plugin · 0 total installs
How We Detect SMS Partner
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sms-partner/assets/a2f/style.css/wp-content/plugins/sms-partner/assets/a2f/script.js/wp-content/plugins/sms-partner/assets/css/intlTelInput-17.0.19.css/wp-content/plugins/sms-partner/assets/js/intlTelInput-17.0.19.min.js/wp-content/plugins/sms-partner/assets/js/custom-intl-tel-input.js/wp-content/plugins/sms-partner/assets/js/utils.jsassets/a2f/script.jsassets/js/intlTelInput-17.0.19.min.jsassets/js/custom-intl-tel-input.jsassets/js/utils.jssms-partner/assets/a2f/style.css?ver=1.0.0sms-partner/assets/a2f/script.js?ver=1.0.0sms-partner/assets/css/intlTelInput-17.0.19.css?ver=17.0.19sms-partner/assets/js/intlTelInput-17.0.19.min.js?ver=17.0.19sms-partner/assets/js/custom-intl-tel-input.js?ver=1.0.0HTML / DOM Fingerprints
intl-tel-inputiticountry-listselected-flagdata-countrysms_partnera2f_data/wp-json/sms-partner/v1/send-sms/wp-json/sms-partner/v1/verify-code