CC Email Manager for WooCommerce Security & Risk Analysis

wordpress.org/plugins/aisp-cc-email-manager

Add CC (carbon copy) emails per customer and automatically send WooCommerce notifications to additional recipients based on selected order statuses.

0 active installs v1.0.0 PHP 7.2+ WP 6.0+ Updated Mar 9, 2026
carbon-copycc-emailnotificationsorder-emailswoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is CC Email Manager for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

CC Email Manager for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 25d ago
Risk Assessment

The "aisp-cc-email-manager" v1.0.0 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of any detected CVEs, critical or high-severity taint flows, and the consistent use of prepared statements for all SQL queries are particularly positive indicators. Furthermore, a high percentage of properly escaped output and the presence of nonce and capability checks on entry points suggest good development practices aimed at preventing common web vulnerabilities. The limited attack surface with no identified unprotected entry points is also a significant strength.

However, the static analysis does reveal a few areas that, while not immediately critical, warrant attention for future improvement. The presence of file operations, although singular, could introduce risks if not handled with extreme care and proper sanitization, especially if user-supplied input is involved. While the output escaping is generally good, the 11% that is not properly escaped could potentially lead to cross-site scripting (XSS) vulnerabilities in specific scenarios, depending on the nature of the unescaped data and how it's rendered.

Overall, this plugin appears to be developed with security in mind. The lack of historical vulnerabilities further reinforces this. The primary focus for enhancement should be on ensuring all file operations are rigorously secured and scrutinizing the unescaped output to eliminate any potential XSS vectors. With these minor adjustments, the plugin's security can be further solidified.

Key Concerns

  • Unescaped output detected
  • File operations detected
Vulnerabilities
None known

CC Email Manager for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

CC Email Manager for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
7
54 escaped
Nonce Checks
3
Capability Checks
4
File Operations
1
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared4 total queries

Output Escaping

89% escaped61 total outputs
Attack Surface

CC Email Manager for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 23
actionplugins_loadedaisp-cc-email-manager.php:21
actionadmin_noticesaisp-cc-email-manager.php:27
filterwoocommerce_email_headersincludes\class-aisp-cc-email-hooks.php:9
actionadmin_menuincludes\class-aisp-cc-email-settings-page.php:11
actionadmin_initincludes\class-aisp-cc-email-settings-page.php:27
actionadmin_initincludes\class-aisp-cc-email-tools.php:9
actionadmin_post_aisp_cc_email_exportincludes\class-aisp-cc-email-tools.php:10
actionadmin_noticesincludes\class-aisp-cc-email-tools.php:72
actionadmin_noticesincludes\class-aisp-cc-email-tools.php:85
actionadmin_noticesincludes\class-aisp-cc-email-tools.php:203
actionadmin_noticesincludes\class-aisp-cc-email-tools.php:215
actionadmin_noticesincludes\class-aisp-cc-email-tools.php:275
actionadmin_noticesincludes\class-aisp-cc-email-tools.php:298
actionadmin_noticesincludes\class-aisp-cc-email-tools.php:317
actionadmin_noticesincludes\class-aisp-cc-email-tools.php:339
actionadmin_noticesincludes\class-aisp-cc-email-tools.php:391
actionshow_user_profileincludes\class-aisp-cc-email-user-fields.php:7
actionedit_user_profileincludes\class-aisp-cc-email-user-fields.php:8
actionpersonal_options_updateincludes\class-aisp-cc-email-user-fields.php:10
actionedit_user_profile_updateincludes\class-aisp-cc-email-user-fields.php:11
filtermanage_users_columnsincludes\class-aisp-cc-email-users-column.php:16
filtermanage_users_custom_columnincludes\class-aisp-cc-email-users-column.php:19
filtermanage_users_sortable_columnsincludes\class-aisp-cc-email-users-column.php:22
Maintenance & Trust

CC Email Manager for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 9, 2026
PHP min version7.2
Downloads150

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

CC Email Manager for WooCommerce Developer Profile

Marco Gagnon

6 plugins · 20 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect CC Email Manager for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/aisp-cc-email-manager/includes/js/admin.js

HTML / DOM Fingerprints

HTML Comments
<!-- CC EMAIL 1 (indépendant de CC2) --><!-- CC EMAIL 2 (indépendant de CC1 — NOUVELLE LOGIQUE) --><!-- ========================================================== --><!-- 1) BULK EMAIL & STATUS UPDATE (COMBINÉ CC1 + CC2) -->+1 more
Data Attributes
name="aisp_cc_email_tools_nonce"name="aisp_cc_email_bulk_old"name="aisp_cc_email_bulk_new"name="aisp_cc_email_status_add[]"name="aisp_cc_email_status_remove[]"
FAQ

Frequently Asked Questions about CC Email Manager for WooCommerce