
WPTelMessage Security & Risk Analysis
wordpress.org/plugins/wptelmessageThe WPTelMessage plugin will help you quickly receive messages sent from the contact form on your website or from the WooCommerce plugin in Telegram.
Is WPTelMessage Safe to Use in 2026?
Generally Safe
Score 92/100WPTelMessage has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'wptelmessage' v1.2 plugin exhibits a generally strong security posture based on the provided static analysis. There are no identified vulnerabilities in its history, and the code analysis reveals excellent adherence to secure coding practices, including 100% use of prepared statements for SQL queries and proper output escaping. The lack of file operations and external HTTP requests further reduces the potential attack surface. However, a significant concern arises from the absence of nonce checks. This means that actions performed by the plugin could potentially be triggered by unauthorized users, especially if any AJAX handlers were to be introduced in the future without proper authentication. The taint analysis, while reporting no critical or high severity issues, did identify one flow with an unsanitized path, which warrants careful attention and investigation to understand its potential impact. Overall, while the plugin is built on a solid foundation with good security practices, the lack of nonces and the identified unsanitized path represent the primary areas of risk.
Key Concerns
- Missing nonce checks
- Flow with unsanitized path
WPTelMessage Security Vulnerabilities
WPTelMessage Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WPTelMessage Attack Surface
WordPress Hooks 11
Maintenance & Trust
WPTelMessage Maintenance & Trust
Maintenance Signals
Community Trust
WPTelMessage Alternatives
WP Telegram (Auto Post and Notifications)
wptelegram
Integrate your WordPress site perfectly with Telegram with full control.
Smartarget Telegram – Contact Us
smartarget-telegram-contact-us
Allow customers to contact you using Telegram
WP Telegram Widget and Join Link
wptelegram-widget
Display the Telegram Public Channel or Group Feed in a WordPress widget or anywhere you want using a simple shortcode.
Easy Sticky Buttons
easy-sticky-buttons
With the Easy Sticky Buttons plugin, you can add 1 to 4 sticky buttons at the bottom of your site's mobile view.
Telegram Bot & Channel
telegram-bot
Supercharge your WordPress site with Telegram! Broadcast posts, automate notifications, and build interactive bots for your users, groups, and channel …
WPTelMessage Developer Profile
1 plugin · 30 total installs
How We Detect WPTelMessage
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wptelmessage/assets/css/main.css/wp-content/plugins/wptelmessage/assets/js/main.jswptelmessage/assets/css/main.css?ver=wptelmessage/assets/js/main.js?ver=HTML / DOM Fingerprints
data-wptelmessage-bot-tokendata-wptelmessage-group-id