
Toll Free SMS Security & Risk Analysis
wordpress.org/plugins/toll-free-smsA wordpress plugin that lets you send Free SMS to your subscribers using your Way2SMS account without leaving wordpress admin area.
Is Toll Free SMS Safe to Use in 2026?
Generally Safe
Score 85/100Toll Free SMS has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "toll-free-sms" plugin version 1.0 presents a mixed security posture. On one hand, the static analysis indicates a small attack surface with no apparent AJAX handlers, REST API routes, shortcodes, or cron events that are unprotected. The absence of dangerous functions and a lack of any recorded historical vulnerabilities are positive indicators. Furthermore, all SQL queries are correctly using prepared statements, and taint analysis reveals no critical or high severity issues.
However, significant concerns arise from the output escaping and capability checks. A concerning 0% of outputs are properly escaped, meaning any data displayed to users could potentially be manipulated, leading to cross-site scripting (XSS) vulnerabilities. The complete absence of nonce checks and capability checks on entry points, despite the small reported attack surface, is a critical oversight. This lack of authorization and integrity checks means that even if no direct vulnerabilities are immediately apparent, attackers could leverage the plugin's functionality in unexpected ways or trigger actions without proper user authentication.
While the plugin's history is clean and it avoids common pitfalls like raw SQL or bundled outdated libraries, the fundamental lack of output escaping and authorization is a major weakness. The plugin is strong in its avoidance of known attack vectors and SQL injection, but it leaves itself wide open to XSS and unauthorized actions due to incomplete input validation and output sanitization. This makes the plugin a potentially risky component despite its clean history and limited apparent attack surface.
Key Concerns
- Outputs not properly escaped
- No nonce checks
- No capability checks
Toll Free SMS Security Vulnerabilities
Toll Free SMS Code Analysis
Output Escaping
Toll Free SMS Attack Surface
WordPress Hooks 2
Maintenance & Trust
Toll Free SMS Maintenance & Trust
Maintenance Signals
Community Trust
Toll Free SMS Alternatives
Contact Form SMS Notifications
contact-form-sms-notifications
Works with the Contact Form 7 plugin to send SMS notifications when somebody submits your contact form, using the API Configured By Site Admin
Newsletters, Email Marketing, SMS and Popups by Omnisend
omnisend
Newsletters, Email Marketing, Email Automation, Forms, Pop Up, SMS by Omnisend
Email Marketing for WooCommerce by Omnisend
omnisend-connect
Email Marketing, Newsletter, Email Automation, Forms, Pop Up, SMS, Abandoned Cart made easy for WordPress & WooCommerce by Omnisend
افزونه پیامک ووکامرس Persian WooCommerce SMS
persian-woocommerce-sms
افزونه کامل و حرفه ای برای اطلاع رسانی پیامکی سفارشات و رویداد های محصولات ووکامرس
Brevo for WooCommerce
woocommerce-sendinblue-newsletter-subscription
All-in-one WooCommerce email marketing, automation, SMS, and CRM by Brevo. Grow your store with powerful marketing tools.
Toll Free SMS Developer Profile
4 plugins · 740 total installs
How We Detect Toll Free SMS
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/toll-free-sms/sms.png/wp-content/plugins/toll-free-sms/loading.gif/wp-content/plugins/toll-free-sms/images/btn_donate.gif/wp-content/plugins/toll-free-sms/sms32.pngHTML / DOM Fingerprints
lblerrorid="mobile"id="mobile1"id="user"id="status"id="smsform"id="sendsms"+10 morewindow.jQuery