VatanSMS.NET Security & Risk Analysis

wordpress.org/plugins/vatansms-net

Kullanım Detayları

10 active installs v2.6 PHP 8.1+ WP 5.0+ Updated May 9, 2024
sms-eklentisisms-turkiyetoplu-smsvatansmsnet-wordpresswoocommerce-sms
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is VatanSMS.NET Safe to Use in 2026?

Generally Safe

Score 92/100

VatanSMS.NET has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The vatansms-net plugin version 2.6 presents a moderate security risk, primarily due to a significant lack of security checks on its attack surface. While the plugin demonstrates good practices in output escaping (94%) and has no known vulnerabilities or dangerous function usage, the presence of an unprotected AJAX handler is a critical concern. This unprotected entry point could be exploited by unauthenticated users to execute actions that were likely intended to be restricted. The taint analysis, showing a high number of flows with unsanitized paths (7 out of 8), further exacerbates this risk, suggesting that data passed through these flows might not be properly validated or cleaned, potentially leading to various injection vulnerabilities if an attacker can control the input to these paths. The plugin's history of zero known vulnerabilities is a positive indicator of past security consciousness, but it does not mitigate the immediate risks identified in the current code analysis. The absence of nonce and capability checks on the AJAX handler, coupled with the taint analysis, are the most significant weaknesses that need immediate attention.

Key Concerns

  • Unprotected AJAX handler
  • High unsanitized paths in taint analysis
  • SQL queries without prepared statements
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

VatanSMS.NET Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

VatanSMS.NET Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
7
119 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

94% escaped126 total outputs
Data Flows
7 unsanitized

Data Flow Analysis

8 flows7 with unsanitized paths
getReportDetail (index.php:585)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

VatanSMS.NET Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_get_report_detailindex.php:584
WordPress Hooks 14
actionadmin_initindex.php:40
actionadmin_menuindex.php:113
actionadmin_enqueue_scriptsindex.php:224
filteruser_contactmethodsindex.php:251
actionuser_new_formindex.php:257
actionuser_registerindex.php:270
actionwoocommerce_new_orderindex.php:278
actionwoocommerce_order_status_cancelledindex.php:334
actionwoocommerce_order_status_completedindex.php:365
actionwoocommerce_order_status_processingindex.php:396
actionwoocommerce_order_status_on-holdindex.php:427
actionwpcf7_mail_sentindex.php:459
actionwpforms_process_completeindex.php:525
actionuser_registerindex.php:603
Maintenance & Trust

VatanSMS.NET Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedMay 9, 2024
PHP min version8.1
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

VatanSMS.NET Developer Profile

Vatan Yazılım ve Haberleşme

2 plugins · 30 total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect VatanSMS.NET

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/vatansms-net/assets/app.css/wp-content/plugins/vatansms-net/assets/app.js/wp-content/plugins/vatansms-net/assets/logo.png
Script Paths
https://cdnjs.cloudflare.com/ajax/libs/font-awesome/5.9.0/css/all.min.css

HTML / DOM Fingerprints

Data Attributes
vatansms-api-idvatansms-api-keyvatansms-is-loginvatansms-sendervatansms-fullnamevatansms-kredit+31 more
FAQ

Frequently Asked Questions about VatanSMS.NET