
Additional Custom Emails & Recipients for WooCommerce Security & Risk Analysis
wordpress.org/plugins/custom-emails-for-woocommerceTake full control over the emails you send and customize your WooCommerce emails with our plugin.
Is Additional Custom Emails & Recipients for WooCommerce Safe to Use in 2026?
Generally Safe
Score 99/100Additional Custom Emails & Recipients for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "custom-emails-for-woocommerce" plugin, version 3.6.8, exhibits a generally strong security posture with no reported critical or high-severity vulnerabilities and a large percentage of properly escaped output. The static analysis shows a minimal attack surface with no exposed AJAX handlers, REST API routes, shortcodes, or cron events that lack authentication or permission checks. Nonce and capability checks are present, albeit limited.
However, a key concern arises from the presence of raw SQL queries without prepared statements. While only one such query was identified, this represents a potential risk for SQL injection if the input feeding it is not meticulously sanitized. The taint analysis also revealed one flow with an unsanitized path, indicating a potential weakness that, while not resulting in a critical or high-severity finding in this analysis, warrants attention. The plugin's history includes one medium-severity CVE related to Cross-Site Scripting, which, although patched, suggests a past susceptibility to input validation issues.
Overall, the plugin has implemented several good security practices, particularly in limiting its attack surface and output escaping. The main areas for improvement are ensuring all SQL queries utilize prepared statements and further investigating and mitigating any identified unsanitized input paths. The single past medium-severity vulnerability should also serve as a reminder to maintain diligent security auditing.
Key Concerns
- SQL queries without prepared statements
- Flows with unsanitized paths
- Medium severity past vulnerability
Additional Custom Emails & Recipients for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Additional Custom Emails & Recipients for WooCommerce <= 3.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
Additional Custom Emails & Recipients for WooCommerce Release Timeline
Additional Custom Emails & Recipients for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Additional Custom Emails & Recipients for WooCommerce Attack Surface
WordPress Hooks 41
Maintenance & Trust
Additional Custom Emails & Recipients for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Additional Custom Emails & Recipients for WooCommerce Alternatives
Smart Product Emails
smart-product-emails
The complete email marketing suite for WooCommerce store owners who want to communicate smarter, not harder.
eGrapes WP EMails Events
egrapes-wp-emails-events
A Plugin or framework for developers to add events to send customised email messages.
MailPoet – Newsletters, Email Marketing, and Automation
mailpoet
Send beautiful newsletters from WordPress. Collect subscribers with signup forms, automate your emails for WooCommerce, blog post notifications & more
YayMail – WooCommerce Email Customizer
yaymail
Customize WooCommerce email templates with an advanced drag-and-drop email builder. Works great with 80+ WooCommerce Email Customizer Addons.
Preview E-mails for WooCommerce
woo-preview-emails
An Extension for WooCommerce that allows you to Preview Email Templates.
Additional Custom Emails & Recipients for WooCommerce Developer Profile
64 plugins · 137K total installs
How We Detect Additional Custom Emails & Recipients for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
[if[clear[site_title[site_address