SMSPILOT.RU WooCommerce Security & Risk Analysis

wordpress.org/plugins/smspilot-ru-woocommerce

SMS уведомления о заказах WooCommerce через шлюз SMSPILOT.RU

60 active installs v1.50 PHP + WP 3.8+ Updated Dec 3, 2025
ecommercesmssms-notificationwoo-commercewoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is SMSPILOT.RU WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

SMSPILOT.RU WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The static analysis of the "smspilot-ru-woocommerce" plugin v1.50 reveals a generally good security posture with several positive indicators. The absence of dangerous functions, the exclusive use of prepared statements for SQL queries, and a high percentage of properly escaped output are commendable practices. Furthermore, the plugin does not appear to have any known vulnerabilities in its history, suggesting a history of stable and secure development. The limited attack surface with zero AJAX handlers, REST API routes, shortcodes, and cron events, further contributes to a reduced risk profile.

However, there are a couple of areas that warrant attention. The taint analysis shows two flows with unsanitized paths, although they are not flagged as critical or high severity. This indicates a potential for certain types of vulnerabilities if input is not handled meticulously, even if the current impact is deemed low. Additionally, the plugin makes one external HTTP request, which, while not inherently a vulnerability, can introduce risks if the external service is compromised or if the request itself is not secured against certain attacks. The lack of nonce checks and capability checks on any entry points (though there are none) also means that if any new entry points were introduced in the future without these security measures, they would be immediately vulnerable.

In conclusion, the "smspilot-ru-woocommerce" plugin v1.50 demonstrates a strong foundation in secure coding practices, especially concerning database interactions and output handling. Its lack of historical vulnerabilities is a significant positive. The primary concerns stem from the two identified taint flows with unsanitized paths and the single external HTTP request, which, while not currently exploited or critical, represent areas where future issues could potentially arise. The absence of any entry points with nonce or capability checks means that vigilance is required if the plugin is ever extended.

Key Concerns

  • Taint flow with unsanitized path
  • Taint flow with unsanitized path
  • External HTTP request made
Vulnerabilities
None known

SMSPILOT.RU WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

SMSPILOT.RU WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
33 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

97% escaped34 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
options (smspilot_woocommerce.php:83)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

SMSPILOT.RU WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionplugins_loadedsmspilot_woocommerce.php:14
actionadmin_menusmspilot_woocommerce.php:31
actionwoocommerce_new_ordersmspilot_woocommerce.php:32
actionwoocommerce_order_status_changedsmspilot_woocommerce.php:33
Maintenance & Trust

SMSPILOT.RU WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedDec 3, 2025
PHP min version
Downloads7K

Community Trust

Rating0/100
Number of ratings0
Active installs60
Developer Profile

SMSPILOT.RU WooCommerce Developer Profile

shuchkin

1 plugin · 60 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect SMSPILOT.RU WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/smspilot-ru-woocommerce/smspilot-woocommerce.php
Version Parameters
smspilot-ru-woocommerce/smspilot-woocommerce.php?ver=

HTML / DOM Fingerprints

Data Attributes
title="64-символьный ключ доступа к сайту SMSPILOT.RU"title="Замените API-ключ на
FAQ

Frequently Asked Questions about SMSPILOT.RU WooCommerce