
TelSender – Сontact form 7, Events, Wpforms, ninja forms and woocommerce to telegram bot Security & Risk Analysis
wordpress.org/plugins/telsenderTelSender - a plugin that works with contact form 7 and the woocommerce store in wordpress. It sends applications from forms to a chat telegram.
Is TelSender – Сontact form 7, Events, Wpforms, ninja forms and woocommerce to telegram bot Safe to Use in 2026?
Generally Safe
Score 96/100TelSender – Сontact form 7, Events, Wpforms, ninja forms and woocommerce to telegram bot has a strong security track record. Known vulnerabilities have been patched promptly.
The 'telsender' plugin, version 1.14.15, exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and a high percentage of properly escaped output. The limited attack surface with only two entry points, both appearing to be protected by authorization checks, is also a strength. However, the presence of the `unserialize` function is a significant concern, as it can lead to remote code execution if used with untrusted input. Although the taint analysis did not reveal critical or high severity flows in this specific scan, the potential for exploiting `unserialize` remains high, especially if inputs are not strictly validated before being passed to it. The vulnerability history shows a concerning pattern of past issues, including a high-severity vulnerability related to missing authorization and cross-site scripting. The presence of a "high" severity vulnerability in the past, coupled with the potential risk of `unserialize`, suggests a history of security oversights that could resurface if not meticulously addressed. While the plugin currently has no unpatched CVEs, its past record warrants vigilance.
Key Concerns
- Dangerous function unserialize present
- High severity vulnerability in history (Missing Auth)
- Medium severity vulnerability in history (XSS)
- Taint flow with unsanitized paths
TelSender – Сontact form 7, Events, Wpforms, ninja forms and woocommerce to telegram bot Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
TelSender <= 1.14.14 - Unauthenticated Stored Cross-Site Scripting via Telegram Chat Title
TelSender <= 1.14.11 - Missing Authorization
TelSender – Сontact form 7, Events, Wpforms, ninja forms and woocommerce to telegram bot Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
TelSender – Сontact form 7, Events, Wpforms, ninja forms and woocommerce to telegram bot Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 14
Maintenance & Trust
TelSender – Сontact form 7, Events, Wpforms, ninja forms and woocommerce to telegram bot Maintenance & Trust
Maintenance Signals
Community Trust
TelSender – Сontact form 7, Events, Wpforms, ninja forms and woocommerce to telegram bot Alternatives
Đẩy Thông Báo Woocommerce tới Telegram
wc-telegram-bot
Đây là plugin giúp đẩy thông báo đơn hàng Woocommerce qua Telegram BOT. Phát triển bởi Tám Tinh Tế.
Joinchat
creame-whatsapp-me
WhatsApp, Messenger, Telegram, Phone call… capture users through their favorite Apps and turn into clients
WP Telegram (Auto Post and Notifications)
wptelegram
Integrate your WordPress site perfectly with Telegram with full control.
Message Bridge for Contact Form 7 and Telegram
cf7-telegram
Deliver Contact Form 7 submissions to Telegram instantly via a bot.
WP Contact Slider – Contact Form Slider Widget
wp-contact-slider
Helps you to show slide out contact form to display CF7, Gravity forms, Ninja Forms, WP Forms, display random text/HTML and support some other forms.
TelSender – Сontact form 7, Events, Wpforms, ninja forms and woocommerce to telegram bot Developer Profile
2 plugins · 5K total installs
How We Detect TelSender – Сontact form 7, Events, Wpforms, ninja forms and woocommerce to telegram bot
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/telsender/assets/icon-plugin.png/wp-content/plugins/telsender/css/multiselect.css/wp-content/plugins/telsender/js/multiselect.js/wp-content/plugins/telsender/js/ajax.js/wp-content/plugins/telsender/css/telsender.css/wp-content/plugins/telsender/js/multiselect.js/wp-content/plugins/telsender/js/ajax.jstelsender/css/multiselect.css?ver=telsender/js/ajax.js?ver=telsender/css/telsender.css?ver=HTML / DOM Fingerprints
data-telsendertscfwc_params