
BP Email Assign Templates Security & Risk Analysis
wordpress.org/plugins/bp-email-assign-templatesA plugin for use with the BuddyPress Email API
Is BP Email Assign Templates Safe to Use in 2026?
Generally Safe
Score 89/100BP Email Assign Templates has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "bp-email-assign-templates" plugin version 1.8 presents a mixed security posture. While the attack surface appears minimal with no reported AJAX handlers, REST API routes, shortcodes, or cron events, which is a positive sign, the code analysis reveals concerning areas. A significant portion (62%) of output operations are not properly escaped, indicating a potential risk for Cross-Site Scripting (XSS) vulnerabilities. Furthermore, 11 out of 16 analyzed taint flows have unsanitized paths, and while no critical or high severity issues were found in the static analysis, this signals a potential for hidden vulnerabilities that could be exploited if input handling is not robust.
The plugin's vulnerability history, with three medium severity CVEs, including those related to Improper Input Validation and Cross-Site Scripting, reinforces the concerns raised by the static analysis. The fact that these vulnerabilities are in the past and currently unpatched is a strength, suggesting the developers have addressed past issues. However, the recurring nature of input validation and XSS issues in its history, coupled with the current static analysis findings, suggests a persistent area of weakness.
In conclusion, while the plugin has a small attack surface and a clean slate regarding currently unpatched vulnerabilities, the significant percentage of unescaped output and the presence of unsanitized taint flows are notable risks. The historical pattern of input validation and XSS issues warrants careful consideration. The plugin's strengths lie in its limited entry points and lack of critical historical vulnerabilities, but its weaknesses lie in its output escaping and internal data handling.
Key Concerns
- High percentage of unescaped output
- High percentage of unsanitized taint flows
- Medium severity CVEs in history
BP Email Assign Templates Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
BP Email Assign Templates <= 1.7 - Authenticated (Admin+) Arbitrary Option Deletion
BP Email Assign Templates <= 1.6 - Authenticated (Administrator+) Stored Cross-Site Scripting
BP Email Assign Templates <= 1.5 - Reflected Cross-Site Scripting
BP Email Assign Templates <= 1.5 - Reflected Cross-Site Scripting
BP Email Assign Templates Release Timeline
BP Email Assign Templates Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
BP Email Assign Templates Attack Surface
WordPress Hooks 15
Maintenance & Trust
BP Email Assign Templates Maintenance & Trust
Maintenance Signals
Community Trust
BP Email Assign Templates Alternatives
Kadence WooCommerce Email Designer
kadence-woocommerce-email-designer
Customize the default WooCommerce email templates design and text through the native WordPress customizer. Preview emails and send test emails.
YayMail – WooCommerce Email Customizer
yaymail
Customize WooCommerce email templates with an advanced drag-and-drop email builder. Works great with 80+ WooCommerce Email Customizer Addons.
Email Templates Customizer and Designer for WordPress and WooCommerce
email-templates
Design and send custom emails with Email Templates plugin for WordPress and WooCommerce
Connect SendGrid for Emails
connect-sendgrid-for-emails
Connect SendGrid to your WordPress site to send emails using SendGrid's cloud-based email platform.
Email Customizer for WooCommerce – Spark Editor
email-editor-plus
Best WooCommerce email customizer plugin to create professional, branded email templates with intuitive drag-and-drop email editor.
BP Email Assign Templates Developer Profile
9 plugins · 2K total installs
How We Detect BP Email Assign Templates
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bp-email-assign-templates/css/admin.css/wp-content/plugins/bp-email-assign-templates/js/admin.js/wp-content/plugins/bp-email-assign-templates/js/admin.jsbp-email-assign-templates/css/admin.css?ver=bp-email-assign-templates/js/admin.js?ver=HTML / DOM Fingerprints
philopresserror_div<!-- to do --><!-- Exit if accessed directly --><!-- sometimes the WP_Post $obj is not set --><!-- For example: in the members-loop, on a Friendship request -->+5 moreid="eto-name-error"id="eto-file-name-error"id="eto-name"id="eto-file-name"id="eto-editor"id="eto-option-name"+20 morepp_etemplates_scriptspp_etemplates_helpbuddyboss_pp_add_admin_email_tabbuddyboss_pp_admin_email_menuspp_etemplates_edit_formpp_etemplates_update_option+52 more