
Wocommerce – Mezco SMS Security & Risk Analysis
wordpress.org/plugins/woo-mezco-smsAdd to your WooCommerce store SMS notifications to your customers when order status changed.
Is Wocommerce – Mezco SMS Safe to Use in 2026?
Generally Safe
Score 85/100Wocommerce – Mezco SMS has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "woo-mezco-sms" v1.0.1 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by not having any known CVEs, using prepared statements exclusively for SQL queries, and avoiding bundled libraries. The attack surface is minimal with no exposed AJAX handlers, REST API routes, or shortcodes that are directly accessible. However, significant concerns arise from the static code analysis. The presence of the `unserialize` function is a critical risk, as it can lead to remote code execution if untrusted data is unserialized without proper sanitization. Furthermore, only 5% of the 38 output instances are properly escaped, leaving a high probability of cross-site scripting (XSS) vulnerabilities. The absence of nonce checks and capability checks on its single cron event is also a notable weakness, potentially allowing unauthorized execution of its scheduled tasks. The lack of any recorded vulnerability history, while seemingly positive, might also suggest insufficient security auditing or analysis in the past, making the current findings more impactful.
Key Concerns
- Unsanitized unserialize() function found
- Low percentage of properly escaped output (5%)
- Missing nonce checks on cron events
- Missing capability checks on cron events
Wocommerce – Mezco SMS Security Vulnerabilities
Wocommerce – Mezco SMS Release Timeline
Wocommerce – Mezco SMS Code Analysis
Dangerous Functions Found
Output Escaping
Wocommerce – Mezco SMS Attack Surface
WordPress Hooks 14
Scheduled Events 1
Maintenance & Trust
Wocommerce – Mezco SMS Maintenance & Trust
Maintenance Signals
Community Trust
Wocommerce – Mezco SMS Alternatives
Product Filter for WooCommerce by WBW
woo-product-filter
Filter products by categories, attributes, prices, and more. Elementor Compatibility. Shoppers easily find products with WooCommerce Product Filter
WCBoost – Wishlist
wcboost-wishlist
WCBoost - Wishlist lets shoppers create wishlists for later purchases, reminding them of desired items, driving repeat visits and boost sales.
Klarna for WooCommerce
klarna-payments-for-woocommerce
Grow your business for increased sales and enhanced shopping experiences at no extra costs.
Conversion Tracking for WooCommerce
woocommerce-conversion-tracking
Adds various conversion tracking codes to cart, checkout, registration success and product page on WooCommerce
Amazon Pay for WooCommerce
woocommerce-gateway-amazon-payments-advanced
Install the Amazon Pay plugin for your WooCommerce store and take advantage of a seamless checkout experience
Wocommerce – Mezco SMS Developer Profile
1 plugin · 0 total installs
How We Detect Wocommerce – Mezco SMS
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/woo-mezco-sms/includes/css/style.css/wp-content/plugins/woo-mezco-sms/includes/js/script.js/wp-content/plugins/woo-mezco-sms/includes/js/script.jswoo-mezco-sms/includes/css/style.css?ver=woo-mezco-sms/includes/js/script.js?ver=HTML / DOM Fingerprints
mezco-sms-admin-wrap<!--Igual no deberías poder abrirme--><!--Comprobamos si está instalado y activo WPML--><!--Cargamos funciones necesarias--><!--Añade en el menú a WooCommerce-->+10 moredata-admin-bar-settings