
AdMail – Multilingual Back in-Stock Notifier for WooCommerce Security & Risk Analysis
wordpress.org/plugins/admailAdMail is a WooCommerce extension that enables your customers to subscribe to out-of-stock products and receive an email notification when the product …
Is AdMail – Multilingual Back in-Stock Notifier for WooCommerce Safe to Use in 2026?
Mostly Safe
Score 71/100AdMail – Multilingual Back in-Stock Notifier for WooCommerce is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved.
The 'admail' plugin v1.7.0 exhibits a mixed security posture. While it demonstrates good practices in output escaping and the use of prepared statements for SQL queries, significant concerns arise from its extensive attack surface and lack of robust authorization checks. A large proportion of its AJAX handlers, which represent potential entry points for attackers, are not protected by authentication, posing a substantial risk of unauthorized actions. The presence of multiple unsanitized taint flows, particularly those categorized as high severity, further amplifies these concerns, indicating potential for data manipulation or execution of unintended code. The plugin's history of a medium-severity vulnerability, although recently patched, alongside the persistent issue of missing authorization, suggests a recurring weakness in how user privileges and access are managed. The plugin's strengths lie in its careful handling of output and database interactions, but these are overshadowed by significant vulnerabilities in its access control mechanisms. Users should proceed with caution and consider disabling or thoroughly auditing the plugin.
Key Concerns
- Unprotected AJAX handlers
- High severity unsanitized taint flows
- Missing capability checks
- Unpatched CVE
- Use of unserialize function
- Multiple flows with unsanitized paths
- Low number of nonce checks
AdMail – Multilingual Back in-Stock Notifier for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
AdMail – Multilingual Back in-Stock Notifier for WooCommerce <= 1.7.0 - Missing Authorization
AdMail – Multilingual Back in-Stock Notifier for WooCommerce Release Timeline
AdMail – Multilingual Back in-Stock Notifier for WooCommerce Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
AdMail – Multilingual Back in-Stock Notifier for WooCommerce Attack Surface
AJAX Handlers 16
Shortcodes 2
WordPress Hooks 34
Scheduled Events 6
Maintenance & Trust
AdMail – Multilingual Back in-Stock Notifier for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
AdMail – Multilingual Back in-Stock Notifier for WooCommerce Alternatives
WPML Multilingual & Multicurrency for WooCommerce
woocommerce-multilingual
Make your store multilingual and enable multiple currencies.
MoreConvert Wishlist for WooCommerce
smart-wishlist-for-more-convert
Free: WooCommerce Wishlist, Email automation, Elementor and Premium: Back-in-Stock Notifier, Save For Later, Multi-lists, reports, Email Marketing
Hyyan WooCommerce Polylang Integration
woo-poly-integration
Given that I am not using Wordpress these days and I haven't really been using WooPoly for a while. I am looking for maintainers to take over thi …
Linguise – AI Automatic Multilingual Translation
linguise
Linguise is a top-quality automatic AI translation with a front-end translation editor. 5' install, SEO-optimized translations, 85+ languages
MultilingualPress
multilingual-press
Create a fast translation network on WordPress multisite.
AdMail – Multilingual Back in-Stock Notifier for WooCommerce Developer Profile
3 plugins · 100 total installs
How We Detect AdMail – Multilingual Back in-Stock Notifier for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/admail/assets/css/wp_styles.css/wp-content/plugins/admail/assets/css/admin.css/wp-content/plugins/admail/assets/css/admin_overview.css/wp-content/plugins/admail/assets/js/admin_table.js/wp-content/plugins/admail/assets/js/admin_scripts.js/wp-content/plugins/admail/assets/js/settings.js/wp-content/plugins/admail/assets/css/styles.css/wp-content/plugins/admail/assets/js/admin_table.js/wp-content/plugins/admail/assets/js/admin_scripts.js/wp-content/plugins/admail/assets/js/settings.jsadmail/assets/css/wp_styles.css?ver=admail/assets/css/admin.css?ver=admail/assets/css/admin_overview.css?ver=admail/assets/js/admin_table.js?ver=admail/assets/js/admin_scripts.js?ver=admail/assets/css/styles.css?ver=admail/assets/js/settings.js?ver=HTML / DOM Fingerprints
ambisn-subscription-formambisn-wrapperambisn-button-disableddata-plugin-urldata-admin-urlambisn_script_vars