
WP SMS Functions Security & Risk Analysis
wordpress.org/plugins/wp-sms-functionsThis plugin gives you the ability to send SMS to your Wordpress website globally. Install and use SMS functions directly.
Is WP SMS Functions Safe to Use in 2026?
Generally Safe
Score 85/100WP SMS Functions has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-sms-functions plugin version 1.2.8 exhibits a generally strong security posture based on the provided static analysis. The absence of identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points is a significant strength, indicating a minimal attack surface. The code also demonstrates good practices regarding SQL queries, exclusively utilizing prepared statements, and has a high percentage of properly escaped output, which helps mitigate cross-site scripting (XSS) risks. The lack of critical or high-severity taint flows further reinforces this positive assessment. However, the analysis does highlight a couple of areas that warrant attention. The presence of file operations and external HTTP requests, even without explicit security concerns flagged in the taint analysis, represents potential avenues for exploitation if not handled with extreme care. Furthermore, the limited number of nonce checks and the complete absence of capability checks, particularly in conjunction with file operations and external requests, represent a notable weakness. While there are no recorded vulnerabilities, this could be due to a lack of historical analysis or recent discovery. The plugin's strengths lie in its limited exposed functionality and secure SQL handling, but the lack of robust access control mechanisms on its operations is a concern.
Key Concerns
- No capability checks implemented
- Potential risks with file operations
- Potential risks with external HTTP requests
- Low number of nonce checks
- Some output not properly escaped
WP SMS Functions Security Vulnerabilities
WP SMS Functions Code Analysis
Output Escaping
Data Flow Analysis
WP SMS Functions Attack Surface
WordPress Hooks 39
Maintenance & Trust
WP SMS Functions Maintenance & Trust
Maintenance Signals
Community Trust
WP SMS Functions Alternatives
Newsletters, Email Marketing, SMS and Popups by Omnisend
omnisend
Newsletters, Email Marketing, Email Automation, Forms, Pop Up, SMS by Omnisend
Email Marketing for WooCommerce by Omnisend
omnisend-connect
Email Marketing, Newsletter, Email Automation, Forms, Pop Up, SMS, Abandoned Cart made easy for WordPress & WooCommerce by Omnisend
افزونه پیامک ووکامرس Persian WooCommerce SMS
persian-woocommerce-sms
افزونه کامل و حرفه ای برای اطلاع رسانی پیامکی سفارشات و رویداد های محصولات ووکامرس
Brevo for WooCommerce
woocommerce-sendinblue-newsletter-subscription
All-in-one WooCommerce email marketing, automation, SMS, and CRM by Brevo. Grow your store with powerful marketing tools.
Texty – SMS Notification for WordPress, WooCommerce, Dokan and more
texty
Texty is a lightweight SMS notification plugin for WordPress.
WP SMS Functions Developer Profile
5 plugins · 290 total installs
How We Detect WP SMS Functions
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-sms-functions/assets/css/style.css/wp-content/plugins/wp-sms-functions/assets/js/script.js/wp-content/plugins/wp-sms-functions/assets/js/script.jswp-sms-functions/assets/css/style.css?ver=wp-sms-functions/assets/js/script.js?ver=HTML / DOM Fingerprints
Gl_Sms_Settings