
TextMe SMS Security & Risk Analysis
wordpress.org/plugins/textme-sms-integrationSend custom SMS messages from your WordPress site to your customers using the TextMe SMS gateway.
Is TextMe SMS Safe to Use in 2026?
Generally Safe
Score 96/100TextMe SMS has a strong security track record. Known vulnerabilities have been patched promptly.
The 'textme-sms-integration' plugin version 2.0.3 presents a mixed security posture. While it demonstrates good practices like a high percentage of prepared SQL statements and robust nonce and capability checks on entry points, several areas warrant attention. The static analysis reveals a significant attack surface with 42 AJAX handlers, although reassuringly, all appear to have authentication checks. However, only 75% of output escaping is properly handled, leaving a portion of outputs potentially vulnerable to Cross-Site Scripting (XSS) if specific user-controlled data is present in those unescaped locations. Furthermore, the plugin's history of three known CVEs, including a high-severity missing authorization vulnerability and two medium-severity XSS issues, is a notable concern. The fact that there are no currently unpatched vulnerabilities is positive, but the recurring nature of these vulnerability types suggests a pattern that developers should address proactively to prevent future occurrences.
Key Concerns
- Notable CVE history (1 High, 2 Medium)
- Significant portion of outputs not properly escaped
- Large number of AJAX handlers
TextMe SMS Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
TextMe SMS <= 1.9.1 - Missing Authorization
TextMe SMS <= 1.9.0 - Missing Authorization via tetxme_update_option_page()
TextMe SMS <= 1.8.8 - Authenticated Stored Cross-Site Scripting
TextMe SMS Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
TextMe SMS Attack Surface
AJAX Handlers 42
Shortcodes 2
WordPress Hooks 73
Scheduled Events 1
Maintenance & Trust
TextMe SMS Maintenance & Trust
Maintenance Signals
Community Trust
TextMe SMS Alternatives
SMS Contact Form 7 Notifications by ClickSend
clicksend-contactform7
Reliable and global SMS notifications for Contact Form 7. ClickSend brings instant SMS communication to the mix. By integrating these tools, you eleva …
G Online SMS
g-online-sms
Send automated SMS notifications from WordPress — user registration, WooCommerce orders, Contact Form 7, Gravity Forms and more.
Sendit Israel
sendit-israel
Sendit Israel provides a simple SMS integration for WordPress and WooCommerce. Supports order status SMS notifications and Contact Form 7 submissions.
WSMS (formerly WP SMS) – SMS & MMS Notifications with OTP and 2FA for WooCommerce
wp-sms
Send SMS/MMS notifications, OTP & 2FA messages, and WooCommerce updates with support for multiple gateways and plugin integrations.
NotifSMS – SMS Notifications OTP & 2FA for WordPress & WooCommerce
wp-twilio-core
Send SMS, OTP & 2FA notifications from WordPress via Twilio. Includes automated alerts, bulk messaging, and integrations with popular plugins.
TextMe SMS Developer Profile
3 plugins · 1K total installs
How We Detect TextMe SMS
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/textme-sms-integration/css/admin-style.css/wp-content/plugins/textme-sms-integration/js/admin-script.js/wp-content/plugins/textme-sms-integration/js/admin-script.jstextme-sms-integration/css/admin-style.css?ver=textme-sms-integration/js/admin-script.js?ver=HTML / DOM Fingerprints
data-textme-api-keydata-textme-api-secretdata-textme-migrate-v1-urldata-textme-api-urldata-textme-sms-test-connection-urldata-textme-sms-get-balance-url+9 moretextme_admin_params/wp-json/textme/v1/test-connection/wp-json/textme/v1/get-balance/wp-json/textme/v1/send-test-sms/wp-json/textme/v1/migrate-from-v1/wp-json/textme/v1/test-migration-connection/wp-json/textme/v1/auto-generate-token/wp-json/textme/v1/manual-migrate-v1/wp-json/textme/v1/test-balance-monitor/wp-json/textme/v1/enable-balance-monitor/wp-json/textme/v1/disable-balance-monitor/wp-json/textme/v1/reset-all-settings