
VHT SMS Security & Risk Analysis
wordpress.org/plugins/vht-smsVHT SMS - là plugin dành riêng cho khách hàng sử dụng dịch vụ của VHT, giúp quý khách gửi tin nhắn vào số điện thoại của khách hàng khi sử dụng Contac …
Is VHT SMS Safe to Use in 2026?
Generally Safe
Score 85/100VHT SMS has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "vht-sms" v1.0.2 plugin exhibits a strong security posture in several key areas. The absence of known vulnerabilities, including CVEs, is a significant positive. The static analysis reveals no exploitable attack surface, with zero AJAX handlers, REST API routes, shortcodes, or cron events exposed without proper authentication or permission checks. Furthermore, the code shows a commitment to secure database interactions, with 100% of SQL queries utilizing prepared statements, and no dangerous functions or file operations identified. The lack of taint analysis findings also indicates a careful approach to handling potentially malicious input.
However, there are areas that warrant attention. The output escaping is only properly implemented for 58% of outputs, leaving a considerable portion vulnerable to cross-site scripting (XSS) attacks if user-supplied data is echoed without sanitization. The presence of an external HTTP request without clear context on its purpose or authentication mechanisms could pose a risk if the target service is compromised or the request is manipulated. The complete absence of nonce checks and capability checks across the plugin's code, while seemingly mitigated by the lack of direct entry points, represents a potential weakness should new entry points be introduced in future versions or if the current analysis is incomplete. The overall security is good due to the lack of direct vulnerabilities and secure SQL usage, but the output escaping and external HTTP request represent the primary areas of concern.
Key Concerns
- Output escaping only 58% proper
- External HTTP request without context
- No nonce checks
- No capability checks
VHT SMS Security Vulnerabilities
VHT SMS Code Analysis
Output Escaping
VHT SMS Attack Surface
WordPress Hooks 11
Maintenance & Trust
VHT SMS Maintenance & Trust
Maintenance Signals
Community Trust
VHT SMS Alternatives
eSMS
esms-gui-tin-nhan-sms
eSMS - là plugin dành riêng cho khách hàng sử dụng dịch vụ của eSMS, giúp quý khách gửi tin nhắn vào số điện thoại của khách hàng khi sử dụng Contact …
MDSCO SMS
mdsco-sms
MDSCO SMS - là plugin dành riêng cho khách hàng sử dụng dịch vụ của MDSCO, giúp quý khách gửi tin nhắn vào số điện thoại của khách hàng khi sử dụng Co …
Newsletters, Email Marketing, SMS and Popups by Omnisend
omnisend
Newsletters, Email Marketing, Email Automation, Forms, Pop Up, SMS by Omnisend
Email Marketing for WooCommerce by Omnisend
omnisend-connect
Email Marketing, Newsletter, Email Automation, Forms, Pop Up, SMS, Abandoned Cart made easy for WordPress & WooCommerce by Omnisend
افزونه پیامک ووکامرس Persian WooCommerce SMS
persian-woocommerce-sms
افزونه کامل و حرفه ای برای اطلاع رسانی پیامکی سفارشات و رویداد های محصولات ووکامرس
VHT SMS Developer Profile
8 plugins · 44K total installs
How We Detect VHT SMS
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/vht-sms/vht-sms.php/wp-content/plugins/vht-sms/assets/css/vhtsms-style.css/wp-content/plugins/vht-sms/assets/js/vhtsms-script.js/wp-content/plugins/vht-sms/assets/js/vhtsms-script.jsvht-sms/vht-sms.php?ver=vht-sms/assets/css/vhtsms-style.css?ver=vht-sms/assets/js/vhtsms-script.js?ver=HTML / DOM Fingerprints
vhtsms-settingsCopyright (C) 2018 VHTThis program is free software: you can redistribute it and/or modifyThis program is distributed in the hope that it will be useful,See the+1 moredata-option-name="vhtsms_options"data-option-group="vhtsms-options-group"data-nonce-field="_wpnonce"data-nonce-action="_wpnonce"data-nonce-url="admin_url( 'options-general.php' )"vhtsms_settingsVHT_SMS_ClassDEVVN_VHTSMS_VERSION_NUMDEVVN_VHTSMS_URLDEVVN_VHTSMS_BASENAMEDEVVN_VHTSMS_PLUGIN_DIR+1 more