
text message sms plugin Security & Risk Analysis
wordpress.org/plugins/text-messagetext message by biz text lets your website receive and send text messages. reply to text messages from a pc or forward messages to your mobile phone.
Is text message sms plugin Safe to Use in 2026?
Generally Safe
Score 92/100text message sms plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'text-message' plugin v3.1.0 appears to have a generally good security posture based on the provided static analysis and vulnerability history. The absence of any known CVEs, particularly critical or high severity ones, and the lack of any recorded vulnerabilities indicate a mature and well-maintained codebase. The code signals show a positive adoption of security best practices, such as the exclusive use of prepared statements for SQL queries and the presence of nonce and capability checks. The limited attack surface, with only two entry points (shortcodes) and no unprotected AJAX handlers or REST API routes, further contributes to a lower risk profile.
However, there is a significant concern regarding output escaping, with only 34% of outputs being properly escaped. This presents a potential risk of cross-site scripting (XSS) vulnerabilities, especially if any of the shortcode outputs handle user-supplied data without sufficient sanitization or escaping. The taint analysis results of zero flows are encouraging but should be considered within the context of the limited output escaping, as a complex flow might not have been detected, or the existing lack of escaping could be exploited by simpler inputs.
In conclusion, while the plugin demonstrates strengths in SQL security and access control, the poor output escaping is a notable weakness that requires attention. The clean vulnerability history is a positive indicator, but it does not negate the inherent risks posed by unescaped output. Addressing the output escaping issues should be the primary focus for improving the plugin's security.
Key Concerns
- Insufficient output escaping detected
text message sms plugin Security Vulnerabilities
text message sms plugin Code Analysis
Output Escaping
text message sms plugin Attack Surface
Shortcodes 2
WordPress Hooks 5
Maintenance & Trust
text message sms plugin Maintenance & Trust
Maintenance Signals
Community Trust
text message sms plugin Alternatives
SMS Abandoned Cart Recovery ✦ CartBoss
cartboss
Boost your sales by recovering abandoned carts with pre-prepared & translated text messages!
ClickSend SMS Woo Integration
clicksendsms
ClickSend SMS Woo Integration helps to send transactions & promotional sms to wooCommerce store owners.
Text Message Contact Form
text-message-contact-form-biztext
Receive a Text or email, from your website through the Text Message Contact Form by Biz Text. SMS notification of email received, no third-party apps …
Branded SMS Pakistan
branded-sms-pakistan
Branded SMS Pakistan - WooCommerce plugin will allow you to send Branded or Short Code SMS notification automatically for orders placed in WooCommerce …
TextP2P Texting Widget
textp2p-texting-widget
Allow site visitors to contact your business the way most prefer, by Texting. Installing the TextP2P Texting Widget plugin into your WordPress site pr …
text message sms plugin Developer Profile
4 plugins · 220 total installs
How We Detect text message sms plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/text-message/wpbiztext.css/wp-content/plugins/text-message/js/biztezt_script.js/wp-content/plugins/text-message/js/biztezt_script.jswpbiztext.css?ver=biztezt_script.js?ver=HTML / DOM Fingerprints
wpbiztext-buttonwpbiztext-link<!-- Biz Text - Fixed Button Code --><!-- Biz Text - Styles --><!-- Biz Text - Link Styles -->data-btn-colordata-btn-text-colordata-btn-border-colordata-btn-widthdata-btn-aligndata-btn-type+13 morebiztext_script_obj