Velstack SMS For WooCommerce Security & Risk Analysis

wordpress.org/plugins/velstack-sms-for-woocommerce

Velstack SMS For WooCommerce enables automatic SMS notifications for order updates.

0 active installs v1.0 PHP + WP 5.0+ Updated Apr 2, 2025
notificationsorderssmswoocommerce
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Velstack SMS For WooCommerce Safe to Use in 2026?

Generally Safe

Score 92/100

Velstack SMS For WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

Based on the static analysis and vulnerability history, the "velstack-sms-for-woocommerce" plugin v1.0 presents a seemingly strong security posture with no identified vulnerabilities in its history and good coding practices within the static analysis. The absence of critical or high-severity taint flows, along with the proper use of prepared statements for SQL queries and output escaping, indicates a conscious effort to prevent common web vulnerabilities. The plugin also has a remarkably small attack surface, with no AJAX handlers, REST API routes, shortcodes, or cron events that would typically serve as entry points for attackers.

However, the analysis does flag a single external HTTP request, which, without further context on its purpose and implementation (e.g., whether it uses SSL/TLS, if the target is trustworthy, and if any data sent is sanitized), represents a potential, albeit isolated, risk. Furthermore, the complete lack of nonce checks and capability checks across all potential entry points (even if there are none listed) is a significant concern. While the current attack surface is zero, any future addition of AJAX, REST API endpoints, or other interactive features without these fundamental WordPress security mechanisms in place would immediately introduce critical vulnerabilities. The plugin's vulnerability history being entirely clear is a positive indicator, suggesting the developers have maintained a secure codebase, but it doesn't mitigate the absence of crucial security checks for future development.

In conclusion, the plugin demonstrates good practices in specific areas like SQL and output handling, and its current attack surface is zero, contributing to its apparent security. The primary weakness lies in the complete absence of built-in security checks like nonces and capability checks, which, if not addressed in future updates or if the attack surface expands, could lead to significant security issues. The external HTTP request also warrants careful review.

Key Concerns

  • External HTTP request without context
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Velstack SMS For WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Velstack SMS For WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0
Attack Surface

Velstack SMS For WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
filterwoocommerce_general_settingsincludes\settings.php:9
actionadmin_noticesvelstack-sms-for-woocommerce.php:24
actionwoocommerce_thankyouvelstack-sms-for-woocommerce.php:35
actionwoocommerce_order_status_changedvelstack-sms-for-woocommerce.php:36
actionplugins_loadedvelstack-sms-for-woocommerce.php:38
Maintenance & Trust

Velstack SMS For WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedApr 2, 2025
PHP min version
Downloads965

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Velstack SMS For WooCommerce Developer Profile

Sammy Fort

1 plugin · 0 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Velstack SMS For WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
notice-error
FAQ

Frequently Asked Questions about Velstack SMS For WooCommerce