Text Local SMS Security & Risk Analysis

wordpress.org/plugins/tl-sms

Best SMS plugin for WordPress, send SMS in WordPress easily, all countries support.

20 active installs v1.0.0 PHP + WP 2.8.0+ Updated Unknown
ajaxformmessagesendsms
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Text Local SMS Safe to Use in 2026?

Generally Safe

Score 100/100

Text Local SMS has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The static analysis of tl-sms v1.0.0 reveals a generally good security posture with no identified critical or high-severity code signals. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is a positive indicator. The output escaping rate of 82% is acceptable, though there's room for improvement to reach 100%. The lack of any recorded vulnerabilities in its history further suggests a robust development approach to security.

However, a significant concern arises from the complete absence of nonce checks and capability checks across all entry points. While the attack surface is currently reported as zero, this indicates a potential blind spot. If any entry points were to be introduced or discovered in future versions, they would likely lack crucial security mechanisms to prevent unauthorized actions or cross-site request forgery. The plugin's sole external HTTP request, while not inherently a vulnerability, warrants attention to ensure it's used securely and doesn't introduce third-party risks.

In conclusion, tl-sms v1.0.0 exhibits strengths in its clean code and lack of historical vulnerabilities. The primary weakness lies in the foundational security checks like nonces and capabilities, which are entirely missing. This presents a latent risk that could be exploited if the attack surface expands or if vulnerabilities are introduced in later versions that leverage these missing protections. Users should be aware of this potential, albeit currently theoretical, risk.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
  • Low output escaping rate
Vulnerabilities
None known

Text Local SMS Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Text Local SMS Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
9 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

82% escaped11 total outputs
Attack Surface

Text Local SMS Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionwp_dashboard_setupdashboard-widget.php:9
actionadmin_initdashboard-widget.php:142
actionadmin_initsettings.php:10
filterplugin_row_metatl-sms.php:44
actionadmin_enqueue_scriptstl-sms.php:51
Maintenance & Trust

Text Local SMS Maintenance & Trust

Maintenance Signals

WordPress version tested4.6.30
Last updatedUnknown
PHP min version
Downloads4K

Community Trust

Rating100/100
Number of ratings1
Active installs20
Developer Profile

Text Local SMS Developer Profile

Alobaidi

22 plugins · 33K total installs

81
trust score
Avg Security Score
90/100
Avg Patch Time
52 days
View full developer profile
Detection Fingerprints

How We Detect Text Local SMS

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/tl-sms/css/tlsms-style.css/wp-content/plugins/tl-sms/js/tlsms-ajax.js
Script Paths
/wp-content/plugins/tl-sms/js/tlsms-ajax.js
Version Parameters
tl-sms/css/tlsms-style.css?ver=tl-sms/js/tlsms-ajax.js?ver=

HTML / DOM Fingerprints

CSS Classes
tlsms-style
FAQ

Frequently Asked Questions about Text Local SMS