
CC Email Manager for WooCommerce Security & Risk Analysis
wordpress.org/plugins/aisp-cc-email-managerAdd CC (carbon copy) emails per customer and automatically send WooCommerce notifications to additional recipients based on selected order statuses.
Is CC Email Manager for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100CC Email Manager for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "aisp-cc-email-manager" v1.0.0 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of any detected CVEs, critical or high-severity taint flows, and the consistent use of prepared statements for all SQL queries are particularly positive indicators. Furthermore, a high percentage of properly escaped output and the presence of nonce and capability checks on entry points suggest good development practices aimed at preventing common web vulnerabilities. The limited attack surface with no identified unprotected entry points is also a significant strength.
However, the static analysis does reveal a few areas that, while not immediately critical, warrant attention for future improvement. The presence of file operations, although singular, could introduce risks if not handled with extreme care and proper sanitization, especially if user-supplied input is involved. While the output escaping is generally good, the 11% that is not properly escaped could potentially lead to cross-site scripting (XSS) vulnerabilities in specific scenarios, depending on the nature of the unescaped data and how it's rendered.
Overall, this plugin appears to be developed with security in mind. The lack of historical vulnerabilities further reinforces this. The primary focus for enhancement should be on ensuring all file operations are rigorously secured and scrutinizing the unescaped output to eliminate any potential XSS vectors. With these minor adjustments, the plugin's security can be further solidified.
Key Concerns
- Unescaped output detected
- File operations detected
CC Email Manager for WooCommerce Security Vulnerabilities
CC Email Manager for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
CC Email Manager for WooCommerce Attack Surface
WordPress Hooks 23
Maintenance & Trust
CC Email Manager for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
CC Email Manager for WooCommerce Alternatives
PushEngage – Web Push notification, WA Automation & Multi-Channel Chat Widget ( WA, Messenger, X, Telegram, TikTok & More)
pushengage
Send order updates, recover abandoned carts, and boost retention with push notifications, WhatsApp automation + multichannel Chat widget.
WSMS (formerly WP SMS) – SMS & MMS Notifications with OTP and 2FA for WooCommerce
wp-sms
Send SMS/MMS notifications, OTP & 2FA messages, and WooCommerce updates with support for multiple gateways and plugin integrations.
Product Expiry for WooCommerce
product-expiry-for-woocommerce
Set expiration dates for WooCommerce products and variations. Automatically change their status or send notifications when they expire.
NotifSMS – SMS Notifications OTP & 2FA for WordPress & WooCommerce
wp-twilio-core
Send SMS, OTP & 2FA notifications from WordPress via Twilio. Includes automated alerts, bulk messaging, and integrations with popular plugins.
Hippoo Mobile App for WooCommerce
hippoo
Hippoo helps you manage WooCommerce orders, inventory, and analytics from your mobile. Receive real-time notifications and control your store on the g …
CC Email Manager for WooCommerce Developer Profile
6 plugins · 20 total installs
How We Detect CC Email Manager for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/aisp-cc-email-manager/includes/js/admin.jsHTML / DOM Fingerprints
<!-- CC EMAIL 1 (indépendant de CC2) --><!-- CC EMAIL 2 (indépendant de CC1 — NOUVELLE LOGIQUE) --><!-- ========================================================== --><!-- 1) BULK EMAIL & STATUS UPDATE (COMBINÉ CC1 + CC2) -->+1 morename="aisp_cc_email_tools_nonce"name="aisp_cc_email_bulk_old"name="aisp_cc_email_bulk_new"name="aisp_cc_email_status_add[]"name="aisp_cc_email_status_remove[]"