
SMSify Security & Risk Analysis
wordpress.org/plugins/smsifyThis amazing WordPress plugin lets you keep your users informed with personalised and automated messages, right to their phones.
Is SMSify Safe to Use in 2026?
Generally Safe
Score 91/100SMSify has a strong security track record. Known vulnerabilities have been patched promptly.
The "smsify" plugin v6.1.2 exhibits a generally good security posture with several positive indicators, including a complete lack of unprotected entry points and robust use of prepared statements for SQL queries. The overwhelming majority of output is properly escaped, and ample capability checks and nonce checks are in place, demonstrating a commitment to secure coding practices. Taint analysis also shows no unsanitized paths, which is a significant strength. However, the presence of two `unserialize` function calls represents a notable concern. While not flagged as vulnerable in the static analysis, `unserialize` is inherently risky and can lead to serious vulnerabilities if not handled with extreme care, especially if the data being unserialized originates from untrusted user input. The plugin's vulnerability history, while currently showing no unpatched CVEs, does include a past medium-severity Cross-Site Scripting (XSS) vulnerability. This suggests that while the current version may be clean, a historical pattern of input sanitization issues warrants vigilance. Overall, the plugin is well-implemented with strong fundamental security controls, but the `unserialize` functions introduce a potential risk that should be closely monitored and ideally mitigated.
Key Concerns
- Dangerous function: unserialize found
- Past medium severity vulnerability recorded
SMSify Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
SMSify <= 6.0.4 - Reflected Cross-Site Scripting
SMSify Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
SMSify Attack Surface
AJAX Handlers 3
WordPress Hooks 48
Maintenance & Trust
SMSify Maintenance & Trust
Maintenance Signals
Community Trust
SMSify Alternatives
Email & SMS Marketing Automations powered by MessengerOS
messengeros
Collect subscribers and send them automated welcome emails or newsletters using the MessengerOS Email & SMS Marketing Platform.
WSMS (formerly WP SMS) – SMS & MMS Notifications with OTP and 2FA for WooCommerce
wp-sms
Send SMS/MMS notifications, OTP & 2FA messages, and WooCommerce updates with support for multiple gateways and plugin integrations.
Smart Marketing SMS and Newsletters Forms
smart-marketing-for-wp
E-commerce Automation Engine: Product sync, Track & Engage, and abandoned cart recovery via Email and SMS for WooCommerce stores.
ShopMagic – Twilio SMS
shopmagic-for-twilio
Send WooCommerce SMS notifications, reminders, and text messages to your customers. The plugin is the ShopMagic add-on and it lets you send sms remind …
Abandoned cart SMS reminders and SMS campaigns – CartFox
cartfox
Dynamic SMS abandoned cart reminders with coupons, post-purchase campaigns and various options for SMS campaigns. Available for 58 languages worldwide …
SMSify Developer Profile
1 plugin · 10 total installs
How We Detect SMSify
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/smsify/images/sms_icon.png/wp-content/plugins/smsify/js/smsify-custom.jssmsify-custom.js?ver=HTML / DOM Fingerprints
smsify-appsmsify-send-user-modalsmsify-user-trackingsmsify-tracking-optinCopyright: © 2024SMSify.coded in AustraliaReleased under the terms of the GNU General Public License.+4 moredata-smsify-tracking-idsmsify_params