Texty – SMS Notification for WordPress, WooCommerce, Dokan and more Security & Risk Analysis

wordpress.org/plugins/texty

Texty is a lightweight SMS notification plugin for WordPress.

9K active installs v1.1.5 PHP 7.4+ WP 6.8+ Updated Feb 3, 2026
nexmonotificationsmstexttwilio
100
A · Safe
CVEs total1
Unpatched0
Last CVEDec 16, 2022
Safety Verdict

Is Texty – SMS Notification for WordPress, WooCommerce, Dokan and more Safe to Use in 2026?

Generally Safe

Score 100/100

Texty – SMS Notification for WordPress, WooCommerce, Dokan and more has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Dec 16, 2022Updated 3mo ago
Risk Assessment

The 'texty' plugin v1.1.5 demonstrates a generally good security posture with several strengths. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events in the attack surface significantly reduces the potential for external exploitation. Furthermore, the plugin consistently uses prepared statements for all SQL queries, and has a reasonable number of nonce and capability checks, indicating a conscious effort to secure its operations. However, there are areas for concern. A significant portion (39%) of output escaping is not properly handled, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is directly outputted. The plugin also makes a notable number of external HTTP requests, which can introduce risks if the target URLs are compromised or if the plugin doesn't properly validate the responses. The vulnerability history, while showing no currently unpatched CVEs, reveals a past medium severity vulnerability related to missing authorization. This pattern, combined with the less-than-perfect output escaping, suggests that while the core functionality might be robust, specific interaction points could still be susceptible to manipulation or unauthorized access if not meticulously handled.

Key Concerns

  • Output escaping is not properly handled (39%)
  • Significant number of external HTTP requests
  • Past medium severity vulnerability (Missing Authorization)
Vulnerabilities
1 published

Texty – SMS Notification for WordPress, WooCommerce, Dokan and more Security Vulnerabilities

CVEs by Year

1 CVE in 2022
2022
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

WF-84003388-c47c-41db-8d2d-4643aa375a89-textymedium · 4.3Missing Authorization

Appsero <= 1.2.1 - Missing Authorization

Dec 16, 2022 Patched in 1.1.2 (699d)
Version History

Texty – SMS Notification for WordPress, WooCommerce, Dokan and more Release Timeline

Code Analysis
Analyzed Mar 16, 2026

Texty – SMS Notification for WordPress, WooCommerce, Dokan and more Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
3 prepared
Unescaped Output
22
34 escaped
Nonce Checks
4
Capability Checks
5
File Operations
0
External Requests
9
Bundled Libraries
0

SQL Query Safety

100% prepared3 total queries

Output Escaping

61% escaped56 total outputs
Attack Surface

Texty – SMS Notification for WordPress, WooCommerce, Dokan and more Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 19
actionswitch_themedependencies\Appsero\Insights.php:135
actionswitch_themedependencies\Appsero\Insights.php:136
actionadmin_footerdependencies\Appsero\Insights.php:146
actionadmin_noticesdependencies\Appsero\Insights.php:161
actionadmin_initdependencies\Appsero\Insights.php:164
filtercron_schedulesdependencies\Appsero\Insights.php:168
actionadmin_menudependencies\Appsero\License.php:219
actionafter_switch_themedependencies\Appsero\License.php:781
actionswitch_themedependencies\Appsero\License.php:782
actionadmin_menuincludes\Admin\Menu.php:14
filteruser_contactmethodsincludes\Admin\Profile.php:16
actionrest_api_initincludes\Api.php:29
actionuser_registerincludes\Dispatcher.php:19
actioncomment_postincludes\Dispatcher.php:20
actionwoocommerce_order_status_changedincludes\Integrations\Dokan.php:14
actiondokan_new_seller_createdincludes\Integrations\Dokan.php:15
actiondokan_store_profile_savedincludes\Integrations\Dokan.php:16
actionwoocommerce_order_status_changedincludes\Integrations\WooCommerce.php:14
actionplugins_loadedtexty.php:49
Maintenance & Trust

Texty – SMS Notification for WordPress, WooCommerce, Dokan and more Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 3, 2026
PHP min version7.4
Downloads173K

Community Trust

Rating100/100
Number of ratings2
Active installs9K
Developer Profile

Texty – SMS Notification for WordPress, WooCommerce, Dokan and more Developer Profile

weDevs

20 plugins · 102K total installs

74
trust score
Avg Security Score
93/100
Avg Patch Time
344 days
View full developer profile
Detection Fingerprints

How We Detect Texty – SMS Notification for WordPress, WooCommerce, Dokan and more

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/texty/dist/runtime.js/wp-content/plugins/texty/dist/vendors.js/wp-content/plugins/texty/dist/app.js/wp-content/plugins/texty/dist/vendors.css/wp-content/plugins/texty/dist/app.css
Script Paths
http://localhost:8080/runtime.jshttp://localhost:8080/vendors.jshttp://localhost:8080/app.jshttp://localhost:8080/vendors.csshttp://localhost:8080/app.css
Version Parameters
texty/dist/runtime.js?ver=texty/dist/vendors.js?ver=texty/dist/app.js?ver=texty/dist/vendors.css?ver=texty/dist/app.css?ver=

HTML / DOM Fingerprints

JS Globals
texty
REST Endpoints
/wp-json/texty/v1/notifications
Shortcode Output
<div id="texty-app"></div>
FAQ

Frequently Asked Questions about Texty – SMS Notification for WordPress, WooCommerce, Dokan and more