
Text Message SMS Extension for WooCommerce Security & Risk Analysis
wordpress.org/plugins/text-message-sms-extension-for-woocommerceIntegrate SMS with WooCommerce to send order Text notifications that allow for replies sent to an online Texting Dashboard or mobile phone(s).
Is Text Message SMS Extension for WooCommerce Safe to Use in 2026?
Generally Safe
Score 92/100Text Message SMS Extension for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "text-message-sms-extension-for-woocommerce" v1.5.0 exhibits several concerning security practices that warrant careful consideration. A significant weakness lies in its attack surface, with two AJAX handlers, both lacking authentication checks. This opens the door for unauthenticated users to potentially interact with these handlers, leading to unintended actions or information disclosure. Furthermore, the plugin uses raw SQL queries without prepared statements, which, combined with potentially unsanitized input from the identified taint flow, presents a risk of SQL injection vulnerabilities. The lack of nonce and capability checks on its entry points further exacerbates these risks, as it allows for unauthorized access and execution. While the plugin has no recorded vulnerability history, this does not guarantee its current security. The absence of past CVEs could be due to its limited scope, recent development, or simply a lack of public scrutiny. The current static analysis findings, particularly the unprotected AJAX handlers and raw SQL queries, are significant indicators of potential security weaknesses that require immediate attention.
Key Concerns
- AJAX handlers without auth checks
- SQL queries not using prepared statements
- Flow with unsanitized paths
- Missing nonce checks
- Missing capability checks
- Output escaping: 58% properly escaped
Text Message SMS Extension for WooCommerce Security Vulnerabilities
Text Message SMS Extension for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Text Message SMS Extension for WooCommerce Attack Surface
AJAX Handlers 2
WordPress Hooks 24
Maintenance & Trust
Text Message SMS Extension for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Text Message SMS Extension for WooCommerce Alternatives
WSMS (formerly WP SMS) – SMS & MMS Notifications with OTP and 2FA for WooCommerce
wp-sms
Send SMS/MMS notifications, OTP & 2FA messages, and WooCommerce updates with support for multiple gateways and plugin integrations.
ShopMagic – Twilio SMS
shopmagic-for-twilio
Send WooCommerce SMS notifications, reminders, and text messages to your customers. The plugin is the ShopMagic add-on and it lets you send sms remind …
Ultimate WP Mail
ultimate-wp-mail
Custom email and SMS notifications. Automatic send actions. WPForms SMS integration. WooCommerce notifications for purchases, abandoned cart and more!
SB SMS Sender
sb-sms-sender
Send SMS to client using SMS club.
Jusibe SMS Notifications for WooCommerce
jusibe-wc-sms-notifications
Jusibe SMS Notifications for WooCommerce allow you to Send SMS order notifications to store admins and customers from your WooCommerce store.
Text Message SMS Extension for WooCommerce Developer Profile
4 plugins · 220 total installs
How We Detect Text Message SMS Extension for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/text-message-sms-extension-for-woocommerce/assets/css/bootstrap.min.css/wp-content/plugins/text-message-sms-extension-for-woocommerce/assets/css/wpbiztextwc-admin-style.css/wp-content/plugins/text-message-sms-extension-for-woocommerce/assets/js/wpbiztextwc-admin-script.js/wp-content/plugins/text-message-sms-extension-for-woocommerce/assets/js/wpbiztextwc-admin-script.jstext-message-sms-extension-for-woocommerce/assets/css/bootstrap.min.css?ver=text-message-sms-extension-for-woocommerce/assets/css/wpbiztextwc-admin-style.css?ver=text-message-sms-extension-for-woocommerce/assets/js/wpbiztextwc-admin-script.js?ver=HTML / DOM Fingerprints
wpbiztextwc-order-sms-metaboxdata-sms-templatewpbiztextwc_select_templatewpbiztextwc_selectplaceholder