SSL Wireless SMS Notification Security & Risk Analysis

wordpress.org/plugins/ssl-wireless-sms-notification

This is the official Woocommerce SMS Notification Plugin of SSL Wireless.

80 active installs v3.8.1 PHP 7.2+ WP 5.0+ Updated May 12, 2025
bangladeshismsofficialssl-wirelesswoocommerce
95
A · Safe
CVEs total2
Unpatched0
Last CVEJan 3, 2025
Safety Verdict

Is SSL Wireless SMS Notification Safe to Use in 2026?

Generally Safe

Score 95/100

SSL Wireless SMS Notification has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Jan 3, 2025Updated 10mo ago
Risk Assessment

The 'ssl-wireless-sms-notification' v3.8.1 plugin exhibits a mixed security posture. On the positive side, the static analysis reveals a good effort in implementing security measures. The vast majority of SQL queries utilize prepared statements, and output escaping is generally well-handled. Nonce and capability checks are present for a significant number of entry points, and there are no publicly disclosed vulnerabilities that are currently unpatched. This suggests that the developers have a foundational understanding of WordPress security best practices.

However, concerns arise from the vulnerability history. The plugin has a history of critical and high-severity vulnerabilities, specifically related to SQL injection and incorrect privilege assignment. While none are currently unpatched, this pattern indicates a recurring weakness in how user-supplied data is handled or how permissions are managed, especially in past versions. The static analysis also flags one flow with an unsanitized path, which, while not classified as critical or high, warrants attention as it represents a potential vector for vulnerabilities. The presence of bundled libraries like DataTables, while common, can also introduce risks if not kept up-to-date and properly secured.

In conclusion, while the current version demonstrates improvements in some security areas, the historical vulnerability data is a significant red flag. Developers should prioritize a thorough review of past vulnerabilities to ensure that the underlying causes have been permanently addressed and that all user inputs are rigorously validated and sanitized. The single unsanitized path flow, even without a high severity rating, should be investigated and remediated as a proactive measure.

Key Concerns

  • History of Critical CVEs (1 critical)
  • History of High CVEs (1 high)
  • Flow with unsanitized paths
  • Bundled libraries (DataTables)
Vulnerabilities
2

SSL Wireless SMS Notification Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Critical
1
High
1

2 total CVEs

CVE-2024-56284high · 7.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

SSL Wireless SMS Notification <= 3.5.0 - Unauthenticated SQL Injection

Jan 3, 2025 Patched in 3.6.0 (14d)
CVE-2024-56220critical · 9.8Incorrect Privilege Assignment

SSL Wireless SMS Notification <= 3.6.0 - Unauthenticated Privilege Escalation

Dec 19, 2024 Patched in 3.7.0 (69d)
Code Analysis
Analyzed Mar 16, 2026

SSL Wireless SMS Notification Code Analysis

Dangerous Functions
0
Raw SQL Queries
4
35 prepared
Unescaped Output
12
74 escaped
Nonce Checks
9
Capability Checks
7
File Operations
3
External Requests
2
Bundled Libraries
1

Bundled Libraries

DataTables

SQL Query Safety

90% prepared39 total queries

Output Escaping

86% escaped86 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

8 flows1 with unsanitized paths
display_phone_field_in_user_profile (sslWireless.php:1623)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

SSL Wireless SMS Notification Attack Surface

Entry Points9
Unprotected0

AJAX Handlers 8

authwp_ajax_otp_login_ajax_actionsslWireless.php:711
noprivwp_ajax_otp_login_ajax_actionsslWireless.php:712
authwp_ajax_otp_register_ajax_actionsslWireless.php:714
noprivwp_ajax_otp_register_ajax_actionsslWireless.php:715
authwp_ajax_otp_send_ajax_actionsslWireless.php:717
noprivwp_ajax_otp_send_ajax_actionsslWireless.php:718
authwp_ajax_final_login_ajax_actionsslWireless.php:720
noprivwp_ajax_final_login_ajax_actionsslWireless.php:721

Shortcodes 1

[sslcare_otp_login_register] sslWireless.php:1444
WordPress Hooks 21
actionadmin_initsslWireless.php:87
actionwpsslWireless.php:88
actionbefore_woocommerce_initsslWireless.php:156
actionadmin_enqueue_scriptssslWireless.php:184
actionadmin_menusslWireless.php:220
actionadmin_post_download_csvsslWireless.php:580
actionwp_enqueue_scriptssslWireless.php:709
filterlogin_redirectsslWireless.php:1456
actiontemplate_redirectsslWireless.php:1459
actionwoocommerce_edit_account_formsslWireless.php:1506
actionwoocommerce_save_account_detailssslWireless.php:1542
filterwoocommerce_save_account_details_requires_passwordsslWireless.php:1545
actionuser_new_formsslWireless.php:1550
actionuser_profile_update_errorssslWireless.php:1582
actionuser_registersslWireless.php:1609
actionshow_user_profilesslWireless.php:1620
actionedit_user_profilesslWireless.php:1621
actionpersonal_options_updatesslWireless.php:1657
actionedit_user_profile_updatesslWireless.php:1658
actionwoocommerce_admin_order_data_after_billing_addresssslWireless.php:1711
actionwoocommerce_process_shop_order_metasslWireless.php:1761
Maintenance & Trust

SSL Wireless SMS Notification Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedMay 12, 2025
PHP min version7.2
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs80
Developer Profile

SSL Wireless SMS Notification Developer Profile

sslplugins

1 plugin · 80 total installs

85
trust score
Avg Security Score
95/100
Avg Patch Time
42 days
View full developer profile
Detection Fingerprints

How We Detect SSL Wireless SMS Notification

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ssl-wireless-sms-notification/lib/asset/css/style-backend-sslcare-otp-login-register.css
Version Parameters
ssl-wireless-sms-notification/lib/asset/css/style-backend-sslcare-otp-login-register.css?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about SSL Wireless SMS Notification