Custom Sender for Email Before Download Security & Risk Analysis

wordpress.org/plugins/custom-sender-for-email-before-download

The plugin lets you set your custom sender for the Email Before Download (version 3.3) plugin.

70 active installs v0.1 PHP + WP 4.0+ Updated Dec 9, 2014
downloademailsender
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Custom Sender for Email Before Download Safe to Use in 2026?

Generally Safe

Score 85/100

Custom Sender for Email Before Download has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The "custom-sender-for-email-before-download" plugin v0.1 exhibits a generally positive security posture based on the provided static analysis. It has no identified CVEs, an empty vulnerability history, and no dangerous functions or SQL queries that are not using prepared statements. The absence of file operations and external HTTP requests also contributes to a lower risk profile. However, the analysis reveals some areas of concern that warrant attention.

While the attack surface appears to be zero in terms of AJAX handlers, REST API routes, shortcodes, and cron events, this could indicate a very limited plugin functionality or potentially an oversight in the analysis. The critical weakness lies in the output escaping, where only 25% of the identified outputs are properly escaped. This leaves a significant portion of the plugin's output vulnerable to cross-site scripting (XSS) attacks if user-supplied data is not handled with extreme care. The lack of nonce checks, despite having one capability check, is also a weakness, particularly if any form of user interaction is handled, even without explicit AJAX or REST endpoints.

In conclusion, the plugin benefits from a clean vulnerability history and the absence of common dangerous code patterns. However, the poor output escaping is a significant security flaw that could lead to XSS vulnerabilities. The limited attack surface, while seemingly positive, should be further scrutinized to ensure no potential entry points were missed. Addressing the output escaping issues should be the top priority.

Key Concerns

  • Only 25% of outputs properly escaped
  • No nonce checks
Vulnerabilities
None known

Custom Sender for Email Before Download Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Custom Sender for Email Before Download Release Timeline

v0.1.1
Code Analysis
Analyzed Mar 16, 2026

Custom Sender for Email Before Download Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
1 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

25% escaped4 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
csebd_options (custom-sender-for-email-before-download.php:34)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Custom Sender for Email Before Download Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionadmin_menucustom-sender-for-email-before-download.php:15
Maintenance & Trust

Custom Sender for Email Before Download Maintenance & Trust

Maintenance Signals

WordPress version tested4.0.38
Last updatedDec 9, 2014
PHP min version
Downloads5K

Community Trust

Rating92/100
Number of ratings7
Active installs70
Developer Profile

Custom Sender for Email Before Download Developer Profile

András Guseo

3 plugins · 90 total installs

91
trust score
Avg Security Score
95/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Custom Sender for Email Before Download

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
pcm-csebdpcm_csebd
Data Attributes
id='sendername'id='senderemail'
FAQ

Frequently Asked Questions about Custom Sender for Email Before Download