
WPC Smart Messages for WooCommerce Security & Risk Analysis
wordpress.org/plugins/wpc-smart-messagesWPC Smart Messages help you display messages throughout your store through smart conditional logic settings.
Is WPC Smart Messages for WooCommerce Safe to Use in 2026?
Mostly Safe
Score 73/100WPC Smart Messages for WooCommerce is generally safe to use. 3 past CVEs were resolved. Keep it updated.
The 'wpc-smart-messages' plugin v4.2.7 exhibits a mixed security posture. On the positive side, static analysis reveals a strong adherence to best practices in several areas, including a complete absence of raw SQL queries (100% prepared statements), a high rate of output escaping (95%), and robust nonce checks and capability checks present on all identified entry points. Taint analysis also shows no unsanitized paths or critical/high severity vulnerabilities, indicating that the developer has likely put effort into preventing common injection flaws. However, the presence of the `unserialize` function is a notable concern, as it can be a vector for deserialization vulnerabilities if not handled with extreme care and proper input validation.
The plugin's vulnerability history is a more significant area of concern. With three known CVEs, one of which remains unpatched, and a recent vulnerability reported in late 2025, this indicates a pattern of past security weaknesses. The types of past vulnerabilities, including Cross-site Scripting, PHP Remote File Inclusion, and Missing Authorization, are serious and have historically led to significant compromises. While the current static analysis doesn't reveal these exact issues, the history suggests that the plugin may be susceptible to complex attacks or that past vulnerabilities may not have been fully eradicated, especially given the unpatched CVE.
In conclusion, while the current version shows improvements in secure coding practices like prepared statements and output escaping, the lingering unpatched vulnerability and the plugin's history of severe security flaws warrant caution. The potential risk from `unserialize` should also be considered, especially in conjunction with the past authorization issues. Users should prioritize updating to a version that addresses the unpatched CVE and remain vigilant for future security advisories.
Key Concerns
- Unpatched CVE present
- Dangerous function: unserialize found
- Past vulnerabilities include RFI and XSS
WPC Smart Messages for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
WPC Smart Messages for WooCommerce <= 4.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
WPC Smart Messages for WooCommerce <= 4.2.1 - Authenticated (Subscriber+) Local File Inclusion
WPC Smart Messages for WooCommerce <= 4.2.1 - Missing Authorization to Authenticated (Subscriber+) Message Activation/Deactivation
WPC Smart Messages for WooCommerce Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
WPC Smart Messages for WooCommerce Attack Surface
AJAX Handlers 9
Shortcodes 19
WordPress Hooks 16
Maintenance & Trust
WPC Smart Messages for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
WPC Smart Messages for WooCommerce Alternatives
Cart & Checkout Notices/Messages for WooCommerce
cart-messages-for-woocommerce
Add and customize WooCommerce cart and checkout notices.
Conditional Cart Messages for WooCommerce – YourPlugins.com
yourplugins-wc-conditional-cart-notices
Show cart messages or notices in your WooCommerce cart by using conditional rules! Made with love by yourplugins.com
Advanced Notifications
advanced-notifications
Advanced Notifications allows you to create beautiful custom notifications that appear on pages or posts of your choice.
Product Completion Emails for WooCommerce
product-completion-emails-for-woocommerce
Send personalized emails for each product after order completion in WooCommerce.
Text Message Contact Form
text-message-contact-form
This is a fully customizable contact form for your website that will send you a text message and e-mail when the form is submitted.
WPC Smart Messages for WooCommerce Developer Profile
71 plugins · 441K total installs
How We Detect WPC Smart Messages for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wpc-smart-messages/assets/css/backend.css/wp-content/plugins/wpc-smart-messages/assets/css/frontend.css/wp-content/plugins/wpc-smart-messages/assets/js/backend.js/wp-content/plugins/wpc-smart-messages/assets/js/frontend.js/wp-content/plugins/wpc-smart-messages/assets/js/backend.js/wp-content/plugins/wpc-smart-messages/assets/js/frontend.jswpc-smart-messages/assets/css/backend.css?ver=wpc-smart-messages/assets/css/frontend.css?ver=wpc-smart-messages/assets/js/backend.js?ver=wpc-smart-messages/assets/js/frontend.js?ver=HTML / DOM Fingerprints
wpcsm-settings-optionwpcsm-custom-locationwpcsm-shortcodewpcsm-shortcode-deswpcsm-shortcode-txtwpcsm-shortcode-inputwpcsm-conditions-notewpcsm-conditions-wrap+4 moredata-idWpcsmAjaxwpcsm_params/wp-json/wpc-smart-messages/v1/settings[wpc_smart_message id=[wpc_smart_message id="