
SMS for WooCommerce Security & Risk Analysis
wordpress.org/plugins/wc-smsOrder SMS Notifications for Woocommerce
Is SMS for WooCommerce Safe to Use in 2026?
Generally Safe
Score 99/100SMS for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The 'wc-sms' plugin v2.8.3 presents a mixed security posture. On the positive side, it demonstrates good practices in handling SQL queries, with all 8 queries utilizing prepared statements, and it includes a nonce check. The attack surface is currently reported as zero for AJAX handlers, REST API routes, shortcodes, and cron events, indicating no readily discoverable public entry points without authentication. However, there are significant concerns that temper this positive outlook. The presence of the 'create_function' dangerous function is a notable red flag, as this function is deprecated and can be a vector for code injection if not handled with extreme care. Furthermore, a substantial 47% of output escaping is not properly handled, suggesting a risk of Cross-Site Scripting (XSS) vulnerabilities where user-controlled data might be rendered directly in the browser without sanitization. The taint analysis shows two flows with unsanitized paths, which, although not classified as critical or high severity in this report, warrant investigation and indicate potential data leakage or manipulation risks. The vulnerability history shows a single medium-severity CVE, which is currently patched, and the common vulnerability type being CSRF is a concern, though the absence of unpatched vulnerabilities is a positive sign. Overall, while the plugin avoids common pitfalls like raw SQL or unprotected AJAX endpoints, the use of dangerous functions and insufficient output escaping create potential security weaknesses that need to be addressed.
Key Concerns
- Dangerous function used (create_function)
- Significant unescaped output (47%)
- Flows with unsanitized paths detected
- Bundled library (Freemius) potentially outdated
SMS for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
SMS for WooCommerce <= 2.8.1 - Cross-Site Request Forgery to Reflected Cross-Site Scripting
SMS for WooCommerce Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
SMS for WooCommerce Attack Surface
WordPress Hooks 10
Maintenance & Trust
SMS for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
SMS for WooCommerce Alternatives
WSMS (formerly WP SMS) – SMS & MMS Notifications with OTP and 2FA for WooCommerce
wp-sms
Send SMS/MMS notifications, OTP & 2FA messages, and WooCommerce updates with support for multiple gateways and plugin integrations.
NotifSMS – SMS Notifications OTP & 2FA for WordPress & WooCommerce
wp-twilio-core
Send SMS, OTP & 2FA notifications from WordPress via Twilio. Includes automated alerts, bulk messaging, and integrations with popular plugins.
ShopMagic – Twilio SMS
shopmagic-for-twilio
Send WooCommerce SMS notifications, reminders, and text messages to your customers. The plugin is the ShopMagic add-on and it lets you send sms remind …
miniOrange OTP Verification and SMS Notification for WooCommerce
miniorange-sms-order-notification-otp-verification
OTP Verification via SMS, Email,or WhatsApp, and SMS Order Notifications, Vendor Notifications for WooCommerce.OTP Login and registration with Phone →
BULK SMS PLANS SMS Notifications
bulksmsplans-sms-notifications
Send custom SMS and WhatsApp notifications for WooCommerce orders, with tracking of sent messages.
SMS for WooCommerce Developer Profile
6 plugins · 8K total installs
How We Detect SMS for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wc-sms/assets/js/admin.js/wp-content/plugins/wc-sms/assets/css/jquery.modal.min.css/wp-content/plugins/wc-sms/assets/js/admin.js/wp-content/plugins/wc-sms/assets/js/jquery.modal.min.jsHTML / DOM Fingerprints
data-freemius-product-id="9965"data-freemius-slug="wc-sms"data-freemius-premium-slug="wc-sms-pro"wcsms_fs