
VoyageSMS Security & Risk Analysis
wordpress.org/plugins/voyagesmsThis is a plugin for existing VoyageSMS clients on WooCommerce to add required scripts for modal display and purchase tracking.
Is VoyageSMS Safe to Use in 2026?
Generally Safe
Score 85/100VoyageSMS has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The VoyagesMS v1.1 plugin exhibits a strong security posture concerning its attack surface and vulnerability history. The absence of AJAX handlers, REST API routes, shortcodes, and cron events, coupled with zero known CVEs and no recorded vulnerabilities, suggests diligent security practices in development and maintenance. The code also demonstrates good practices by using prepared statements for all SQL queries and avoiding file operations and external HTTP requests. However, a significant concern arises from the complete lack of output escaping. With 5 total outputs and 0% properly escaped, this indicates a high potential for cross-site scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the user interface. The absence of nonce checks and capability checks on entry points, while currently not an issue due to the lack of exposed entry points, could become a risk if future versions introduce new features without proper authentication and authorization measures. In conclusion, while the plugin is currently robust due to its limited attack surface and clean history, the critical lack of output escaping represents a notable weakness that should be addressed immediately to prevent potential XSS attacks.
Key Concerns
- No output escaping on any outputs
- No nonce checks on entry points
- No capability checks on entry points
VoyageSMS Security Vulnerabilities
VoyageSMS Release Timeline
VoyageSMS Code Analysis
Output Escaping
VoyageSMS Attack Surface
WordPress Hooks 5
Maintenance & Trust
VoyageSMS Maintenance & Trust
Maintenance Signals
Community Trust
VoyageSMS Alternatives
Smart Marketing SMS and Newsletters Forms
smart-marketing-for-wp
E-commerce Automation Engine: Product sync, Track & Engage, and abandoned cart recovery via Email and SMS for WooCommerce stores.
ShopMagic – Twilio SMS
shopmagic-for-twilio
Send WooCommerce SMS notifications, reminders, and text messages to your customers. The plugin is the ShopMagic add-on and it lets you send sms remind …
Remarkety – eCommerce Marketing Automation Platform for WooCommerce
remarkety-for-woocommerce
Send intelligent emails based on customer purchase history. Recover abandoned carts, send targeted newsletters and more. Free Trial!
Enudge
enudge
Easily integrate your WordPress forms and chosen forms plugin with the Enudge Email and SMS marketing platform API.
Jellyreach
jellyreach
Jellyreach is an email and SMS marketing automation tool. This plugin lets WooCommerce stores import data into Jellyreach, and then enables creating s …
VoyageSMS Developer Profile
1 plugin · 0 total installs
How We Detect VoyageSMS
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
window.voyage