
Zibad Smart Notifier Security & Risk Analysis
wordpress.org/plugins/zibad-smart-notifierSmart Notifier helps WooCommerce stores send automated SMS notifications for order events.
Is Zibad Smart Notifier Safe to Use in 2026?
Generally Safe
Score 100/100Zibad Smart Notifier has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The zibad-smart-notifier plugin v1.1.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices by having no known CVEs, no critical or high severity taint flows in the analyzed code, and a strong reliance on prepared statements for its SQL queries. The absence of direct entry points like AJAX handlers, REST API routes, and shortcodes further reduces the immediate attack surface. However, there are areas of concern that temper the overall assessment. The taint analysis revealed flows with unsanitized paths, indicating a potential risk, even if no critical or high severity issues were directly identified from these. Additionally, the plugin relies on the Freemius v1.0 bundled library, which could be outdated and a potential vector for vulnerabilities if not kept current. The significant percentage of improperly escaped output is a notable weakness, increasing the risk of Cross-Site Scripting (XSS) vulnerabilities, especially if the unsanitized paths can lead to user-controlled data being outputted without proper sanitization. While the plugin's vulnerability history is clean, this, combined with the static analysis findings, suggests a need for diligent code review and proactive security measures to address the identified weaknesses, particularly around output escaping and unsanitized paths.
Key Concerns
- Flows with unsanitized paths found
- 149 total outputs, 73% properly escaped
- Bundled Freemius v1.0 library
Zibad Smart Notifier Security Vulnerabilities
Zibad Smart Notifier Release Timeline
Zibad Smart Notifier Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Zibad Smart Notifier Attack Surface
WordPress Hooks 26
Scheduled Events 3
Maintenance & Trust
Zibad Smart Notifier Maintenance & Trust
Maintenance Signals
Community Trust
Zibad Smart Notifier Alternatives
SMSPlus for WooCommerce
smsplus-for-woocommerce
Send SMS notifications to your customers when WooCommerce order statuses change, powered by the SMSPlus API.
WSMS (formerly WP SMS) – SMS & MMS Notifications with OTP and 2FA for WooCommerce
wp-sms
Send SMS/MMS notifications, OTP & 2FA messages, and WooCommerce updates with support for multiple gateways and plugin integrations.
NotifSMS – SMS Notifications OTP & 2FA for WordPress & WooCommerce
wp-twilio-core
Send SMS, OTP & 2FA notifications from WordPress via Twilio. Includes automated alerts, bulk messaging, and integrations with popular plugins.
ShopMagic – Twilio SMS
shopmagic-for-twilio
Send WooCommerce SMS notifications, reminders, and text messages to your customers. The plugin is the ShopMagic add-on and it lets you send sms remind …
Ultimate WP Mail
ultimate-wp-mail
Custom email and SMS notifications. Automatic send actions. WPForms SMS integration. WooCommerce notifications for purchases, abandoned cart and more!
Zibad Smart Notifier Developer Profile
1 plugin · 0 total installs
How We Detect Zibad Smart Notifier
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/zibad-smart-notifier/admin/css/style.css/wp-content/plugins/zibad-smart-notifier/admin/js/admin.js/wp-content/plugins/zibad-smart-notifier/assets/css/zibad-smart-notifier.csszibad-smart-notifier/admin/css/style.css?ver=zibad-smart-notifier/admin/js/admin.js?ver=zibad-smart-notifier/assets/css/zibad-smart-notifier.css?ver=HTML / DOM Fingerprints
zibad-smart-notifierzimsn-admin<!-- Zibad Smart Notifier Pro Add-on Notice -->zimsn_admin_ajax_object