text message sms extension for contact form 7 Security & Risk Analysis

wordpress.org/plugins/text-message-sms-extension-for-contact-form-7

integrate sms with contact form 7 to send and receive texts. reply directly via online text dashboard or mobile phone. no third-party service needed.

50 active installs v3.1 PHP 7.0+ WP 4.0+ Updated Nov 20, 2024
biz-textcontact-form-7smstexting
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is text message sms extension for contact form 7 Safe to Use in 2026?

Generally Safe

Score 92/100

text message sms extension for contact form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The plugin "text-message-sms-extension-for-contact-form-7" v3.1 exhibits a concerning security posture due to significant weaknesses in its attack surface and data handling. The presence of two AJAX handlers lacking authentication checks is a major red flag, directly exposing potential attack vectors. Furthermore, the plugin's reliance on raw SQL queries without prepared statements and a low percentage of properly escaped output indicate a high risk of injection vulnerabilities and cross-site scripting (XSS) attacks. While the plugin has no recorded vulnerability history or taint flow issues, this does not negate the inherent risks identified in the static analysis. The absence of vulnerability history could indicate a lack of public discovery or an incomplete security audit. Overall, the plugin presents several critical areas for immediate remediation, specifically concerning the unprotected AJAX endpoints and insecure data handling practices, despite a seemingly clean historical record.

Key Concerns

  • Unprotected AJAX handlers
  • SQL queries without prepared statements
  • Low percentage of properly escaped output
  • No nonce checks on AJAX handlers
Vulnerabilities
None known

text message sms extension for contact form 7 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

text message sms extension for contact form 7 Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
24
6 escaped
Nonce Checks
0
Capability Checks
1
File Operations
1
External Requests
3
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

20% escaped30 total outputs
Attack Surface
2 unprotected

text message sms extension for contact form 7 Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_wpbiztextc7_verify_idadmin\admin_global_settings.php:145
noprivwp_ajax_wpbiztextc7_verify_idadmin\admin_global_settings.php:146
WordPress Hooks 10
actionadmin_menuadmin\admin_global_settings.php:18
actionadmin_initadmin\admin_global_settings.php:119
filterwpcf7_editor_panelsadmin\wpbiztextc7_tab_form_settings.php:4
filterwpcf7_copyadmin\wpbiztextc7_tab_form_settings.php:224
actionwpcf7_save_contact_formadmin\wpbiztextc7_tab_form_settings.php:255
filterwpcf7_feedback_responseadmin\wpbiztextc7_tab_form_settings.php:421
actionwpcf7_before_send_mailadmin\wpbiztextc7_tab_form_settings.php:514
actionadmin_print_scriptscf7-text-message-integration.php:66
actionadmin_headcf7-text-message-integration.php:67
actionadmin_headcf7-text-message-integration.php:69
Maintenance & Trust

text message sms extension for contact form 7 Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedNov 20, 2024
PHP min version7.0
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs50
Developer Profile

text message sms extension for contact form 7 Developer Profile

biz text

4 plugins · 220 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect text message sms extension for contact form 7

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/text-message-sms-extension-for-contact-form-7/admin/js/script_biztextc7admin.js/wp-content/plugins/text-message-sms-extension-for-contact-form-7/admin/css/biztextc7admin-style.css
Script Paths
admin/js/script_biztextc7admin.js
Version Parameters
script_biztextc7admin.js?ver=biztextc7admin-style.css?ver=

HTML / DOM Fingerprints

CSS Classes
wpbiztextc7-successwpbiztextc7-errorwpbiztextc7-tagswpbiztextc7-tooltipwpbiztextc7-tooltiptextbiztext
HTML Comments
visitor sms information and messageUsed to collect user infocontent inside biz text tabadd tab in contact 7 form settings+4 more
Data Attributes
wpbiztextc7-inquirer-phone-numberwpbiztextc7-inquirer-messagewpbiztextc7-visitor-nicknamewpbiztextc7-admin-messagewpbiztextc7-email-notification-activationwpbiztextc7-send-autoreply-only+1 more
Shortcode Output
Biz Text SMS
FAQ

Frequently Asked Questions about text message sms extension for contact form 7