
WC – APG SMS Notifications Security & Risk Analysis
wordpress.org/plugins/woocommerce-apg-sms-notificationsAdd to your WooCommerce store SMS notifications to your customers when order status changed.
Is WC – APG SMS Notifications Safe to Use in 2026?
Generally Safe
Score 100/100WC – APG SMS Notifications has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the provided static analysis and vulnerability history, the 'woocommerce-apg-sms-notifications' v3.0.0 plugin exhibits a generally good security posture. The absence of known CVEs and critical taint flows is a positive indicator. Furthermore, the code appears to follow several security best practices, including the exclusive use of prepared statements for SQL queries and a high percentage of properly escaped output. The limited attack surface, with no detected AJAX handlers, REST API routes, or shortcodes, also contributes to a reduced risk profile.
However, several areas warrant attention. The most significant concern is the complete lack of nonce checks and capability checks across all entry points. While the static analysis reports zero unprotected entry points, the absence of these fundamental security mechanisms, particularly for the two cron events, creates a significant potential vulnerability. Any interaction with these cron events, if not properly secured internally, could be exploited by authenticated users with malicious intent. Additionally, the high number of external HTTP requests (30) could be a vector for supply chain attacks if any of the endpoints become compromised or if the plugin's handling of responses from these requests is insecure.
In conclusion, the plugin demonstrates strengths in its SQL handling and output sanitization, and its lack of historical vulnerabilities is encouraging. Nevertheless, the complete omission of nonce and capability checks is a critical oversight that significantly increases the risk of privilege escalation or unauthorized actions, especially concerning the cron events. The high volume of external requests also represents a notable, albeit less immediate, risk.
Key Concerns
- Missing Nonce Checks
- Missing Capability Checks
- High number of external HTTP requests
WC – APG SMS Notifications Security Vulnerabilities
WC – APG SMS Notifications Code Analysis
Output Escaping
WC – APG SMS Notifications Attack Surface
WordPress Hooks 12
Scheduled Events 2
Maintenance & Trust
WC – APG SMS Notifications Maintenance & Trust
Maintenance Signals
Community Trust
WC – APG SMS Notifications Alternatives
SMS Notifications for WooCommerce
sms-notifications-for-woocommerce
Sends SMS notifications to your clients for order status changes. You can also receive an SMS message when a new order is received.
New Post SMS Notifications
new-post-sms-notifications
Sends SMS notifications to your clients for new post status changes. You can also receive an SMS message when a new new post is received.
WSMS (formerly WP SMS) – SMS & MMS Notifications with OTP and 2FA for WooCommerce
wp-sms
Send SMS/MMS notifications, OTP & 2FA messages, and WooCommerce updates with support for multiple gateways and plugin integrations.
miniOrange OTP Login, Verification and SMS Notifications
miniorange-otp-verification
OTP Verification via Email/SMS/WhatsApp,SMS Notifications for WooCommerce,OTP Login with Phone,PasswordLess Login.Custom Gateway for OTP Verification
BulkGate SMS Plugin for WooCommerce
woosms-sms-module-for-woocommerce
SMS and Viber plugin for WooCommerce. Order status notifications, personalized Bulk SMS and Viber campaigns, 2-way messaging and admin alerts.
WC – APG SMS Notifications Developer Profile
9 plugins · 19K total installs
How We Detect WC – APG SMS Notifications
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/woocommerce-apg-sms-notifications/css/apg-sms-style.css/wp-content/plugins/woocommerce-apg-sms-notifications/js/apg-sms-script.js/wp-content/plugins/woocommerce-apg-sms-notifications/js/apg-sms-script.jswoocommerce-apg-sms-notifications/css/apg-sms-style.css?ver=woocommerce-apg-sms-notifications/js/apg-sms-script.js?ver=HTML / DOM Fingerprints
apg-sms-settings-fieldapg_sms_settingsapg-sms-containerEqual no deberías poder abrirmeConstante con la version actual del plugin.¿Está activo WooCommerce?Añade compatibilidad con HPOS+12 moredata-apg-sms-phone-countrydata-apg-sms-phone-numberwindow.apg_sms_settingsvar apg_sms_settings