VHT SMS Security & Risk Analysis

wordpress.org/plugins/vht-sms

VHT SMS - là plugin dành riêng cho khách hàng sử dụng dịch vụ của VHT, giúp quý khách gửi tin nhắn vào số điện thoại của khách hàng khi sử dụng Contac …

10 active installs v1.0.2 PHP + WP 3.0+ Updated Jun 16, 2022
smssms-for-contact-form-7sms-for-ninjaformvhtvht-sms
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is VHT SMS Safe to Use in 2026?

Generally Safe

Score 85/100

VHT SMS has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "vht-sms" v1.0.2 plugin exhibits a strong security posture in several key areas. The absence of known vulnerabilities, including CVEs, is a significant positive. The static analysis reveals no exploitable attack surface, with zero AJAX handlers, REST API routes, shortcodes, or cron events exposed without proper authentication or permission checks. Furthermore, the code shows a commitment to secure database interactions, with 100% of SQL queries utilizing prepared statements, and no dangerous functions or file operations identified. The lack of taint analysis findings also indicates a careful approach to handling potentially malicious input.

However, there are areas that warrant attention. The output escaping is only properly implemented for 58% of outputs, leaving a considerable portion vulnerable to cross-site scripting (XSS) attacks if user-supplied data is echoed without sanitization. The presence of an external HTTP request without clear context on its purpose or authentication mechanisms could pose a risk if the target service is compromised or the request is manipulated. The complete absence of nonce checks and capability checks across the plugin's code, while seemingly mitigated by the lack of direct entry points, represents a potential weakness should new entry points be introduced in future versions or if the current analysis is incomplete. The overall security is good due to the lack of direct vulnerabilities and secure SQL usage, but the output escaping and external HTTP request represent the primary areas of concern.

Key Concerns

  • Output escaping only 58% proper
  • External HTTP request without context
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

VHT SMS Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

VHT SMS Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
43
60 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

58% escaped103 total outputs
Attack Surface

VHT SMS Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionplugins_loadedvht-sms.php:104
actionadmin_menuvht-sms.php:108
actionadmin_initvht-sms.php:109
actionwpcf7_mail_sentvht-sms.php:111
actionninja_forms_after_submissionvht-sms.php:113
actionninja_forms_post_processvht-sms.php:115
actionadmin_enqueue_scriptsvht-sms.php:118
actionwoocommerce_checkout_processvht-sms.php:122
actionwoocommerce_created_customervht-sms.php:124
actionwoocommerce_new_ordervht-sms.php:130
actionwoocommerce_order_status_changedvht-sms.php:140
Maintenance & Trust

VHT SMS Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedJun 16, 2022
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

VHT SMS Developer Profile

Le Van Toan

8 plugins · 44K total installs

84
trust score
Avg Security Score
94/100
Avg Patch Time
85 days
View full developer profile
Detection Fingerprints

How We Detect VHT SMS

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/vht-sms/vht-sms.php/wp-content/plugins/vht-sms/assets/css/vhtsms-style.css/wp-content/plugins/vht-sms/assets/js/vhtsms-script.js
Script Paths
/wp-content/plugins/vht-sms/assets/js/vhtsms-script.js
Version Parameters
vht-sms/vht-sms.php?ver=vht-sms/assets/css/vhtsms-style.css?ver=vht-sms/assets/js/vhtsms-script.js?ver=

HTML / DOM Fingerprints

CSS Classes
vhtsms-settings
HTML Comments
Copyright (C) 2018 VHTThis program is free software: you can redistribute it and/or modifyThis program is distributed in the hope that it will be useful,See the+1 more
Data Attributes
data-option-name="vhtsms_options"data-option-group="vhtsms-options-group"data-nonce-field="_wpnonce"data-nonce-action="_wpnonce"data-nonce-url="admin_url( 'options-general.php' )"
JS Globals
vhtsms_settingsVHT_SMS_ClassDEVVN_VHTSMS_VERSION_NUMDEVVN_VHTSMS_URLDEVVN_VHTSMS_BASENAMEDEVVN_VHTSMS_PLUGIN_DIR+1 more
FAQ

Frequently Asked Questions about VHT SMS