Add Plain-Text Email Security & Risk Analysis

wordpress.org/plugins/add-plain-text-email

Adds a text/plain email to text/html emails to decrease the chance of emails being tagged as spam.

100 active installs v1.2.1 PHP + WP 3.1+ Updated Jan 6, 2025
emailhtml-emailspamspamassassintext-email
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Add Plain-Text Email Safe to Use in 2026?

Generally Safe

Score 92/100

Add Plain-Text Email has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "add-plain-text-email" plugin, version 1.2.1, exhibits an exceptionally strong security posture based on the provided static analysis. The absence of any identified entry points, including AJAX handlers, REST API routes, shortcodes, or cron events, significantly limits the plugin's attack surface. Furthermore, the code signals indicate a clean codebase with no dangerous functions, all SQL queries using prepared statements, and proper output escaping. The lack of file operations, external HTTP requests, nonce checks, and capability checks, while potentially indicating a very simple plugin, also means there are no obvious avenues for common web vulnerabilities within these areas. The vulnerability history is entirely clear, with no recorded CVEs, suggesting a history of secure development or effective patching. This plugin appears to be well-developed from a security perspective. However, the complete lack of any detected flows in taint analysis and the absence of any capability or nonce checks could, in scenarios with more complex functionality, indicate that the analysis might not have found areas where such checks would be relevant. Overall, this plugin presents a very low security risk.

Vulnerabilities
None known

Add Plain-Text Email Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Add Plain-Text Email Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Add Plain-Text Email Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionphpmailer_initadd-plain-text-email.php:37
Maintenance & Trust

Add Plain-Text Email Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedJan 6, 2025
PHP min version
Downloads6K

Community Trust

Rating100/100
Number of ratings4
Active installs100
Developer Profile

Add Plain-Text Email Developer Profile

Danny van Kooten

9 plugins · 1.1M total installs

77
trust score
Avg Security Score
97/100
Avg Patch Time
655 days
View full developer profile
Detection Fingerprints

How We Detect Add Plain-Text Email

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/add-plain-text-email/add-plain-text-email.php
Version Parameters
add-plain-text-email/add-plain-text-email.php?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Add Plain-Text Email