
SMSPlus for WooCommerce Security & Risk Analysis
wordpress.org/plugins/smsplus-for-woocommerceSend SMS notifications to your customers when WooCommerce order statuses change, powered by the SMSPlus API.
Is SMSPlus for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100SMSPlus for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The smsplus-for-woocommerce plugin v1.0.0 exhibits a generally positive security posture based on the provided static analysis. The plugin successfully implements output escaping for all identified outputs and has a limited attack surface with only one AJAX handler, which appears to be protected. There are no identified critical or high severity taint flows, and the vulnerability history is clean, suggesting a lack of previously exploited weaknesses.
However, a significant concern arises from the handling of SQL queries. The analysis indicates that 100% of SQL queries are not using prepared statements. This is a critical security weakness that exposes the plugin to potential SQL injection vulnerabilities, even if none have been reported historically. While the plugin demonstrates good practices in other areas, this single flaw represents a substantial risk that should be addressed immediately. The presence of capability checks and nonce checks on the AJAX handler is a positive sign, mitigating the risk of unauthorized execution through that specific entry point.
Key Concerns
- SQL queries not using prepared statements
SMSPlus for WooCommerce Security Vulnerabilities
SMSPlus for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
SMSPlus for WooCommerce Attack Surface
AJAX Handlers 1
WordPress Hooks 7
Maintenance & Trust
SMSPlus for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
SMSPlus for WooCommerce Alternatives
Zibad Smart Notifier
zibad-smart-notifier
Smart Notifier helps WooCommerce stores send automated SMS notifications for order events.
WSMS (formerly WP SMS) – SMS & MMS Notifications with OTP and 2FA for WooCommerce
wp-sms
Send SMS/MMS notifications, OTP & 2FA messages, and WooCommerce updates with support for multiple gateways and plugin integrations.
NotifSMS – SMS Notifications OTP & 2FA for WordPress & WooCommerce
wp-twilio-core
Send SMS, OTP & 2FA notifications from WordPress via Twilio. Includes automated alerts, bulk messaging, and integrations with popular plugins.
ShopMagic – Twilio SMS
shopmagic-for-twilio
Send WooCommerce SMS notifications, reminders, and text messages to your customers. The plugin is the ShopMagic add-on and it lets you send sms remind …
Ultimate WP Mail
ultimate-wp-mail
Custom email and SMS notifications. Automatic send actions. WPForms SMS integration. WooCommerce notifications for purchases, abandoned cart and more!
SMSPlus for WooCommerce Developer Profile
1 plugin · 0 total installs
How We Detect SMSPlus for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/smsplus-for-woocommerce/assets/css/admin.csssmsplus-for-woocommerce/assets/css/admin.css?ver=HTML / DOM Fingerprints
id="tab-smsplus"smsplus_admin