SMS send for Africa's Talking Security & Risk Analysis

wordpress.org/plugins/sms-send-for-africas-talking

Send single or bulk SMS via Africa's Talking API with secure WordPress integration. Manage recipients and customize messages.

10 active installs v1.6 PHP 7.4+ WP 5.0+ Updated Oct 17, 2025
afric-smssend-smssmssms-plugin
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is SMS send for Africa's Talking Safe to Use in 2026?

Generally Safe

Score 100/100

SMS send for Africa's Talking has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7mo ago
Risk Assessment

The "sms-send-for-africas-talking" plugin v1.6 exhibits a generally good security posture based on the provided static analysis and vulnerability history. It demonstrates strong adherence to secure coding practices, with a very high percentage of properly escaped outputs and the absence of dangerous functions or file operations. The plugin also utilizes nonce checks effectively and avoids bundled libraries, which can be a source of vulnerabilities. The lack of any recorded vulnerabilities, including critical or high severity issues, further supports this positive assessment, indicating a history of responsible development and maintenance.

However, a few areas warrant attention. While the attack surface is small, the absence of capability checks on the two AJAX handlers is a notable concern. This means that any authenticated user, regardless of their role, could potentially trigger these AJAX actions, which could be exploited if these actions have unintended consequences or can be manipulated. Additionally, one-third of the SQL queries are not using prepared statements, which, while not a critical issue given the low number of queries and the absence of taint flows, does represent a potential risk for SQL injection if the data involved were to become more complex or user-controlled in future updates. The presence of external HTTP requests, while not inherently risky, always introduces an indirect attack vector that should be monitored.

In conclusion, the plugin is well-maintained with no known vulnerabilities, and most security best practices are followed. The primary weakness lies in the lack of capability checks on AJAX endpoints, which could be a point of exploitation. The non-prepared SQL queries are a minor concern but should be addressed proactively. Overall, the risk is relatively low, but these specific areas offer avenues for improvement.

Key Concerns

  • AJAX handlers without capability checks
  • SQL queries without prepared statements
Vulnerabilities
None known

SMS send for Africa's Talking Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

SMS send for Africa's Talking Release Timeline

v1.6Current
v1.5
v1.4
v1.3
Code Analysis
Analyzed Mar 16, 2026

SMS send for Africa's Talking Code Analysis

Dangerous Functions
0
Raw SQL Queries
4
2 prepared
Unescaped Output
1
58 escaped
Nonce Checks
4
Capability Checks
0
File Operations
0
External Requests
3
Bundled Libraries
0

SQL Query Safety

33% prepared6 total queries

Output Escaping

98% escaped59 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

3 flows
BASMS_africastalking_sms_submit (includes\africastalking-sms-class.php:74)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

SMS send for Africa's Talking Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_africastalking_sms_submitincludes\africastalking-sms-class.php:18
noprivwp_ajax_africastalking_sms_submitincludes\africastalking-sms-class.php:19
WordPress Hooks 5
actionadmin_menuincludes\africastalking-send-sms-class.php:11
actionadmin_enqueue_scriptsincludes\africastalking-send-sms-class.php:12
actionadmin_menuincludes\africastalking-sms-class.php:16
actionadmin_enqueue_scriptsincludes\africastalking-sms-class.php:17
actionadmin_menuincludes\africastalking-sms-history.php:15
Maintenance & Trust

SMS send for Africa's Talking Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 17, 2025
PHP min version7.4
Downloads716

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

SMS send for Africa's Talking Developer Profile

C-Metric

6 plugins · 550 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect SMS send for Africa's Talking

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sms-send-for-africas-talking/assets/css/africastalking-sms.css/wp-content/plugins/sms-send-for-africas-talking/assets/js/africastalking-sms-form.min.js/wp-content/plugins/sms-send-for-africas-talking/assets/js/africastalking-sms-ajax.js
Version Parameters
sms-send-for-africas-talking/assets/css/africastalking-sms.css?ver=sms-send-for-africas-talking/assets/js/africastalking-sms-form.min.js?ver=sms-send-for-africas-talking/assets/js/africastalking-sms-ajax.js?ver=

HTML / DOM Fingerprints

JS Globals
africastalking_sms_object
FAQ

Frequently Asked Questions about SMS send for Africa's Talking