[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fLN-FIVNVlWdkI9BcZaFD_0VSra12fLZjzNOWYdFttTg":3,"$fquP2VlHrT_SRe6smKQ54BU0C1zbVQ4a6WqTJaLxt1Vk":244,"$fmYSO7axipHgEHqKQHEMY26Xpe96dLRoohrDwM-1WKbA":248},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":14,"last_updated":15,"tested_up_to":16,"requires_at_least":17,"requires_php":18,"tags":19,"homepage":23,"download_link":24,"security_score":25,"vuln_count":26,"unpatched_count":26,"last_vuln_date":27,"fetched_at":28,"discovery_status":29,"vulnerabilities":30,"developer":31,"crawl_stats":27,"alternatives":39,"analysis":152,"fingerprints":227},"custom-sender-for-email-before-download","Custom Sender for Email Before Download","0.1","András Guseo","https:\u002F\u002Fprofiles.wordpress.org\u002Faguseo\u002F","\u003Cp>The Custom Sender plugin is an addition to the Email Before Download (version 3.3) plugin. It enables you to easily set up the sender’s name and e-mail address through a simple interface. So instead of ‘WordPress \u003Ca href=\"mailto:wordpress@your-domain.com\" rel=\"nofollow ugc\">wordpress@your-domain.com\u003C\u002Fa>‘ you can set up your or your company’s real name and e-mail address as the sender.\u003C\u002Fp>\n\u003Cp>In order for this plugin to work you will need the Email Before Download (version 3.3) plugin and it’s dependencies. Without that it will not work, and doesn’t even do anything.\u003C\u002Fp>\n","The plugin lets you set your custom sender for the Email Before Download (version 3.3) plugin.",70,5182,92,7,"2014-12-09T10:52:00.000Z","4.0.38","4.0","",[20,21,22],"download","email","sender","http:\u002F\u002Fblog.pc-magus.hu\u002Fcustom-sender-for-email-before-download\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fcustom-sender-for-email-before-download.zip",85,0,null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":32,"display_name":7,"profile_url":8,"plugin_count":33,"total_installs":34,"avg_security_score":35,"avg_patch_time_days":36,"trust_score":37,"computed_at":38},"aguseo",3,90,95,30,91,"2026-08-29T11:08:32.097Z",[40,65,87,112,132],{"slug":41,"name":42,"version":43,"author":44,"author_profile":45,"description":46,"short_description":47,"active_installs":48,"downloaded":49,"rating":50,"num_ratings":51,"last_updated":52,"tested_up_to":53,"requires_at_least":54,"requires_php":55,"tags":56,"homepage":60,"download_link":61,"security_score":62,"vuln_count":63,"unpatched_count":26,"last_vuln_date":64,"fetched_at":28},"site-mailer","Email Deliverability – SMTP Replacement, Email API Deliverability & Email Log","1.4.7","Elementor","https:\u002F\u002Fprofiles.wordpress.org\u002Felemntor\u002F","\u003Cp>\u003Cspan class=\"embed-youtube\" style=\"text-align:center; display: block;\">\u003Ciframe loading=\"lazy\" class=\"youtube-player\" width=\"750\" height=\"422\" src=\"https:\u002F\u002Fwww.youtube.com\u002Fembed\u002F1hOxkEO-22I?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent\" allowfullscreen=\"true\" style=\"border:0;\" sandbox=\"allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox\">\u003C\u002Fiframe>\u003C\u002Fspan>\u003C\u002Fp>\n\u003Cp>Has your WordPress site stopped sending emails? Are emails from your WordPress site landing in spam or not getting delivered? Are customers complaining about missing messages?\u003C\u002Fp>\n\u003Cp>With \u003Cstrong>Email Deliverability\u003C\u002Fstrong> (formally known as Site Mailer), you can say goodbye to email issues. Our easy-to-use tool ensures all emails reach their destination while providing you with a detailed email log to track and resend messages if needed.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Enhance your email management effortlessly\u003C\u002Fstrong>. Email Deliverability eliminates the need for complex SMTP plugins, providing a streamlined solution for reliable email deliverability. Troubleshoot and monitor with ease using our intuitive interface, so you never miss another email.\u003C\u002Fp>\n\u003Ch3>Key features\u003C\u002Fh3>\n\u003Ch4>High deliverability\u003C\u002Fh4>\n\u003Cp>Ensure your emails consistently reach your audience’s inboxes with optimized sending methods that maximize deliverability and minimize spam risk.\u003C\u002Fp>\n\u003Ch4>Use your custom domain\u003C\u002Fh4>\n\u003Cp>Send emails with your custom domain — or get started quickly with our default email so no email will be lost once you start working with Email Deliverability.\u003C\u002Fp>\n\u003Ch4>No integration or SMTP plugin needed\u003C\u002Fh4>\n\u003Cp>Email Deliverability works seamlessly without the need for additional API integration or SMTP plugins. This means less hassle and more efficient email management.\u003C\u002Fp>\n\u003Ch4>Easy setup\u003C\u002Fh4>\n\u003Cp>Get started with Email Deliverability in no time. Our intuitive setup process ensures you can configure and start using the plugin quickly and effortlessly.\u003C\u002Fp>\n\u003Ch4>30-day log retention\u003C\u002Fh4>\n\u003Cp>The plugin includes 30 days of email log retention, allowing you to easily track and review your email activity.\u003C\u002Fp>\n\u003Ch4>Compatibility with popular plugins\u003C\u002Fh4>\n\u003Cp>Email Deliverability has been tested to be fully compatible with most popular WordPress plugins, including Elementor Pro, WooCommerce, Contact Form 7, WPForms and more.\u003C\u002Fp>\n\u003Ch4>Reputation management\u003C\u002Fh4>\n\u003Cp>Safeguard your email sending reputation with intelligent features that enhance your sender score, ensuring consistent inbox placement and reducing the risk of emails being marked as spam.\u003C\u002Fp>\n\u003Ch4>Email testing\u003C\u002Fh4>\n\u003Cp>Send a test email to confirm your site is properly configured for seamless transactional email delivery.\u003C\u002Fp>\n\u003Ch4>Resend failed emails\u003C\u002Fh4>\n\u003Cp>Did an email fail to deliver? Easily resend it with a single click to ensure your message reaches its intended recipient.\u003C\u002Fp>\n\u003Ch4>Suppression list\u003C\u002Fh4>\n\u003Cp>Enable easy unsubscribe options for your emails. Track and manage all unsubscribed recipients directly in the Suppressions tab.\u003C\u002Fp>\n\u003Ch3>Benefits\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>No integration needed\u003C\u002Fstrong>: Use Email Deliverability without the need for additional plugins or integrations.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Troubleshooting\u003C\u002Fstrong>: Efficiently troubleshoot and resend emails when necessary.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Spam reduction\u003C\u002Fstrong>: Our plugin will keeps your emails out of the spam folder, ensuring your important messages reach their intended recipients.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Built by the Elementor team\u003C\u002Fstrong>: Leverage the trust and reliability of a solution developed by Elementor.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Get started today\u003C\u002Fh3>\n\u003Cp>\u003Cstrong>Transform your website’s email management with Email Deliverability!\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>For more information about Email Deliverability, visit our \u003Ca href=\"https:\u002F\u002Fgo.elementor.com\u002Fwp-repo-wp-dash-sm-product-page\u002F\" rel=\"nofollow ugc\">official website\u003C\u002Fa>.\u003Cbr \u002F>\nIf you have any questions or need support, feel free to \u003Ca href=\"https:\u002F\u002Fgo.elementor.com\u002Fwp-repo-wp-dash-sm-contact-us\u002F\" rel=\"nofollow ugc\">contact us\u003C\u002Fa> or visit our \u003Ca href=\"https:\u002F\u002Fgo.elementor.com\u002Fwp-repo-wp-dash-sm-help-center\u002F\" rel=\"nofollow ugc\">help center\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>This plugin requires a connection to an active Elementor account to identify the user and provide the purchased service. This connection is triggered manually by the user via the plugin’s settings panel. Learn more about our \u003Ca href=\"https:\u002F\u002Fgo.elementor.com\u002Fwp-repo-wp-dash-sm-term-and-conditions\u002F\" rel=\"nofollow ugc\">terms and conditions\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>This plugin uses a 3rd party service operated by Elementor, which accepts Email information including but not limited to (from, to, cc,bcc addresses, email body, subject line and attachments). This flow is triggered automatically for every email sent using the native WordPress \u003Ccode>wp_mail\u003C\u002Fcode> function.\u003C\u002Fp>\n\u003Ch3>Related plugins\u003C\u002Fh3>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fimage-optimization\u002F\" rel=\"ugc\">Image Optimization\u003C\u002Fa>: Superior image compression for faster, high-quality website performance.\u003C\u002Fp>\n","Effortlessly manage transactional emails with Email Deliverability. High deliverability, logs and statistics, and no SMTP plugins needed.",200000,2376158,46,16,"2026-07-16T06:53:00.000Z","7.0.2","6.7","7.4",[21,57,58,22,59],"email-api","email-log","smtp","https:\u002F\u002Felementor.com\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fsite-mailer.1.4.7.zip",98,1,"2025-02-27 23:34:36",{"slug":66,"name":67,"version":68,"author":69,"author_profile":70,"description":71,"short_description":72,"active_installs":73,"downloaded":74,"rating":75,"num_ratings":76,"last_updated":77,"tested_up_to":78,"requires_at_least":79,"requires_php":80,"tags":81,"homepage":18,"download_link":86,"security_score":13,"vuln_count":26,"unpatched_count":26,"last_vuln_date":27,"fetched_at":28},"cb-change-mail-sender","Change Mail Sender","1.3.0","Syed Balkhi","https:\u002F\u002Fprofiles.wordpress.org\u002Fsmub\u002F","\u003Cp>\u003Cstrong>Do you want to change the WordPress default from email address and from name?\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>This is the plugin for you! It allows you to change the from email address and name for all emails sent from your WordPress site.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Are your WordPress emails not being delivered?\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>If you have issues with email deliverability, then just changing the from email address and name will usually not resolve the issue.\u003C\u002Fp>\n\u003Cp>In order to fix your WordPress emails not reaching your inbox, we suggest installing the \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fwp-mail-smtp\u002F\" rel=\"ugc\">WP Mail SMTP\u003C\u002Fa> plugin.\u003C\u002Fp>\n\u003Cp>WP Mail SMTP is trusted by more than 3 million websites. It will fix the deliverability problems with one of your favourite email providers: Gmail, Outlook, SendLayer, Mailgun, and many more.\u003C\u002Fp>\n","Easily change the default WordPress from email name and from email address.",20000,189235,88,18,"2025-04-02T06:24:00.000Z","6.7.5","5.2","5.6.20",[82,21,83,84,85],"change-mail-sender","from-email","mail","name","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fcb-change-mail-sender.1.3.0.zip",{"slug":88,"name":89,"version":90,"author":91,"author_profile":92,"description":93,"short_description":94,"active_installs":95,"downloaded":96,"rating":97,"num_ratings":98,"last_updated":99,"tested_up_to":100,"requires_at_least":101,"requires_php":102,"tags":103,"homepage":108,"download_link":109,"security_score":62,"vuln_count":110,"unpatched_count":26,"last_vuln_date":111,"fetched_at":28},"elastic-email-sender","Elastic Email Sender","1.2.22","Elastic Email","https:\u002F\u002Fprofiles.wordpress.org\u002Felasticemail\u002F","\u003Cp>Elastic Email Sender allows you to connect your WordPress with our powerful, low-cost Elastic Email API and start sending marketing or transactional emails!\u003Cbr \u002F>\nPlease follow the information below and find out more about how we can help you send your emails in a more efficient way.\u003Cbr \u002F>\nIn case of any questions or concerns, feel free to contact us anytime.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>What is the Elastic Email Sender plugin?\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>The Elastic Email Sender plugin is an easy way to maintain all the aspects related to your email campaigns. From creating and sending your emails to monitoring and managing campaign stats.\u003Cbr \u002F>\nElastic Email Sender replaces the WordPress default wp_mail() function by using API integration with Elastic Email to send an outgoing email from your WordPress installation.\u003Cbr \u002F>\nThanks to this, you can track all the parameters of your delivery, use Private IP addresses to get full control over your sending, maintain reputation and delivery and secure your data better than ever. You can also use your own domain and analyze your data with ease.\u003C\u002Fp>\n\u003Cp>Elastic Email Sender is compatible with almost every solution available on the market including \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fwoocommerce\u002F\" rel=\"ugc\">WooCommerce\u003C\u002Fa>, \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fcontact-form-7\u002F\" rel=\"ugc\">Contact Form 7\u003C\u002Fa>, \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fninja-forms\u002F\" rel=\"ugc\">Ninja Forms\u003C\u002Fa>, \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fflamingo\u002F\" rel=\"ugc\">Flamingo\u003C\u002Fa>, \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fcaldera-forms\u002F\" rel=\"ugc\">Caldera Forms\u003C\u002Fa>, \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fbbpress\u002F\" rel=\"ugc\">bbPress\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>\u003Cstrong>How to get started?\u003C\u002Fstrong>\u003Cbr \u002F>\nJust sign into your \u003Ca href=\"https:\u002F\u002Fapp.elasticemail.com\u002Fmarketing\u002Fsettings\u002Fnew\u002Fcreate-api\" rel=\"nofollow ugc\">Elastic Email account\u003C\u002Fa>, copy the API Key. Next, please login to your WordPress dashboard, add the \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Felastic-email-sender\u002F\" rel=\"ugc\">Elastic Email Sender\u003C\u002Fa> plugin and paste there the API Key from your Elastic Email account.\u003C\u002Fp>\n\u003Ch3>Translations\u003C\u002Fh3>\n\u003Cp>You can translate Elastic Email Sender on \u003Ca href=\"https:\u002F\u002Ftranslate.wordpress.org\u002Fprojects\u002Fwp-plugins\u002Felastic-email-sender\" rel=\"nofollow ugc\">\u003Cstrong>translate.wordpress.org\u003C\u002Fstrong>\u003C\u002Fa>.\u003C\u002Fp>\n","Reconfigures wp_mail() to send email using Elastic Email API instead of SMTP.",10000,290986,96,10,"2025-12-03T13:29:00.000Z","6.9.5","5.0","7.0",[104,105,106,107],"email-marketing","email-sender","mailer","transactional-email","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Felastic-email-sender\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Felastic-email-sender.zip",2,"2025-10-28 00:00:00",{"slug":113,"name":114,"version":115,"author":116,"author_profile":117,"description":118,"short_description":119,"active_installs":95,"downloaded":120,"rating":97,"num_ratings":121,"last_updated":122,"tested_up_to":100,"requires_at_least":123,"requires_php":55,"tags":124,"homepage":129,"download_link":130,"security_score":131,"vuln_count":26,"unpatched_count":26,"last_vuln_date":27,"fetched_at":28},"stop-wp-emails-going-to-spam","Stop WP Emails Going to Spam","2.2.1","fullworks","https:\u002F\u002Fprofiles.wordpress.org\u002Ffullworks\u002F","\u003Cp>Emails generated from within WordPress often end up in your spam or junk folder, This plugin helps you sort that out. The default settings of this plugin can often be enough to solve your problem.\u003C\u002Fp>\n\u003Cp>When using the default PHP mailer in WordPress, especially on shared servers, emails will often be set to spam or junk by receiving email systems. This can be very frustrating and important notifications can be missed by you or your clients.\u003C\u002Fp>\n\u003Cp>Why does this happen? One problem is the “envelope sender” not being set, and many hosts will recommend that you install a plugin to set the “envelope sender”, this is the main purpose of this plugin.\u003C\u002Fp>\n\u003Cp>Along with setting the “envelope sender” this plugin also displays your Sender Permitted From (SPF) and checks your server IP is in the SPF record, if there is one.\u003C\u002Fp>\n\u003Cp>Optionally this plugin allows you to change the name and email address of the default WordPress notification email easily.\u003C\u002Fp>\n\u003Cp>If you use an SMTP email plugin or use an API based transactional email plugin, this plugin will add no value; it is built to support the default PHP mailer only.\u003C\u002Fp>\n\u003Ch4>PHP 8.0 compatible\u003C\u002Fh4>\n\u003Cp>Tested on PHP 8.4\u003C\u002Fp>\n\u003Ch4>Features Include\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Checks email SPF health\u003C\u002Fli>\n\u003Cli>Checks if your IP is blacklisted\u003C\u002Fli>\n\u003Cli>Set envelope sender when missing\u003C\u002Fli>\n\u003Cli>Allows you to change the default WordPress sending email\u003C\u002Fli>\n\u003Cli>Allows you to change the default WordPress sending email name\u003C\u002Fli>\n\u003Cli>Allows you to set the sending email domain\u003C\u002Fli>\n\u003C\u002Ful>\n","Fixes WordPress emails going to spam\u002Fjunk folders. The default settings often resolve the issue.",168781,51,"2025-12-15T13:14:00.000Z","4.8.1",[21,125,126,127,128],"envelope-sender","phpmail","phpmailer","spam","https:\u002F\u002Ffullworksplugins.com\u002Fproducts\u002Fstop-wp-emails-going-to-spam\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fstop-wp-emails-going-to-spam.2.2.1.zip",100,{"slug":133,"name":134,"version":135,"author":136,"author_profile":137,"description":138,"short_description":139,"active_installs":95,"downloaded":140,"rating":62,"num_ratings":141,"last_updated":142,"tested_up_to":100,"requires_at_least":143,"requires_php":55,"tags":144,"homepage":149,"download_link":150,"security_score":131,"vuln_count":63,"unpatched_count":26,"last_vuln_date":151,"fetched_at":28},"wp-change-email-sender","WP Change Email Sender","3.3.1","Md Aminur Islam","https:\u002F\u002Fprofiles.wordpress.org\u002Faminurislam01\u002F","\u003Cp>This plugin enable you to change mail sender name and email address from WordPress default mail sender name and email.\u003Cbr \u002F>\nAfter installation, navigate to \u003Cstrong>Settings &rarr; Change Email Sender\u003C\u002Fstrong> in the WordPress admin sidebar to open the modern configuration dashboard.\u003C\u002Fp>\n\u003Ch4>Plugin Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>✉️ \u003Cstrong>Custom Sender Details:\u003C\u002Fstrong> Easily replace the default “WordPress” name and “wordpress@yourdomain.com” email address with your own brand.\u003C\u002Fli>\n\u003Cli>🛡️ \u003Cstrong>Force Overrides:\u003C\u002Fstrong> Prevent misbehaving plugins (e.g., contact forms or e-commerce plugins) from hijacking your outbound email sender details.\u003C\u002Fli>\n\u003Cli>↩️ \u003Cstrong>Smart “Reply-To” Protection:\u003C\u002Fstrong> When forcing an email override, the plugin automatically captures the original sender and sets it as the “Reply-To” address so you never miss a customer reply.\u003C\u002Fli>\n\u003Cli>🧪 \u003Cstrong>Built-in Email Tester:\u003C\u002Fstrong> Instantly send a test email directly from the settings page to verify your configuration is working perfectly.\u003C\u002Fli>\n\u003Cli>💾 \u003Cstrong>Import & Export:\u003C\u002Fstrong> Securely back up your custom configurations to a JSON file or restore them instantly with the built-in drag-and-drop uploader.\u003C\u002Fli>\n\u003Cli>⚡ \u003Cstrong>Lightning Fast Dashboard:\u003C\u002Fstrong> Enjoy a stunning, single-page React interface that saves your settings instantly without page reloads.\u003C\u002Fli>\n\u003Cli>🔒 \u003Cstrong>Lightweight & Secure:\u003C\u002Fstrong> Built with the native WordPress REST API and rigorous security standards.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Support\u003C\u002Fh3>\n\u003Cp>If you find this plugin useful, consider supporting its development through a \u003Ca href=\"https:\u002F\u002Fwww.buymeacoffee.com\u002Faiarnob\" rel=\"nofollow ugc\">donation\u003C\u002Fa>.\u003C\u002Fp>\n","Easily change WordPress default mail sender name and email address",75754,9,"2026-05-15T10:36:00.000Z","5.8",[145,146,133,147,148],"wordpress-default-email-sender-change","wp-change-default-email-sender","wp-default-email-change","wp-default-email-sender-name-change","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fwp-change-email-sender\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwp-change-email-sender.3.3.1.zip","2024-03-25 00:00:00",{"attackSurface":153,"codeSignals":165,"taintFlows":179,"riskAssessment":217,"analyzedAt":226},{"hooks":154,"ajaxHandlers":161,"restRoutes":162,"shortcodes":163,"cronEvents":164,"entryPointCount":26,"unprotectedCount":26},[155],{"type":156,"name":157,"callback":158,"file":159,"line":160},"action","admin_menu","csebd_plugin_menu","custom-sender-for-email-before-download.php",15,[],[],[],[],{"dangerousFunctions":166,"sqlUsage":167,"outputEscaping":169,"fileOperations":26,"externalRequests":26,"nonceChecks":26,"capabilityChecks":63,"bundledLibraries":178},[],{"prepared":26,"raw":26,"locations":168},[],{"escaped":63,"rawEcho":33,"locations":170},[171,174,176],{"file":159,"line":172,"context":173},74,"raw output",{"file":159,"line":175,"context":173},79,{"file":159,"line":177,"context":173},83,[],[180,206],{"entryPoint":181,"graph":182,"unsanitizedCount":26,"severity":205},"csebd_options (custom-sender-for-email-before-download.php:34)",{"nodes":183,"edges":201},[184,189,194,197],{"id":185,"type":186,"label":187,"file":159,"line":188},"n0","source","$_POST",44,{"id":190,"type":191,"label":192,"file":159,"line":50,"wp_function":193},"n1","sink","update_option() [Settings Manipulation]","update_option",{"id":195,"type":186,"label":196,"file":159,"line":188},"n2","$_POST (x3)",{"id":198,"type":191,"label":199,"file":159,"line":172,"wp_function":200},"n3","echo() [XSS]","echo",[202,204],{"from":185,"to":190,"sanitized":203},true,{"from":195,"to":198,"sanitized":203},"low",{"entryPoint":207,"graph":208,"unsanitizedCount":26,"severity":205},"\u003Ccustom-sender-for-email-before-download> (custom-sender-for-email-before-download.php:0)",{"nodes":209,"edges":214},[210,211,212,213],{"id":185,"type":186,"label":187,"file":159,"line":188},{"id":190,"type":191,"label":192,"file":159,"line":50,"wp_function":193},{"id":195,"type":186,"label":196,"file":159,"line":188},{"id":198,"type":191,"label":199,"file":159,"line":172,"wp_function":200},[215,216],{"from":185,"to":190,"sanitized":203},{"from":195,"to":198,"sanitized":203},{"summary":218,"deductions":219},"The \"custom-sender-for-email-before-download\" plugin v0.1 exhibits a generally positive security posture based on the provided static analysis. It has no identified CVEs, an empty vulnerability history, and no dangerous functions or SQL queries that are not using prepared statements. The absence of file operations and external HTTP requests also contributes to a lower risk profile.  However, the analysis reveals some areas of concern that warrant attention.\n\nWhile the attack surface appears to be zero in terms of AJAX handlers, REST API routes, shortcodes, and cron events, this could indicate a very limited plugin functionality or potentially an oversight in the analysis. The critical weakness lies in the output escaping, where only 25% of the identified outputs are properly escaped. This leaves a significant portion of the plugin's output vulnerable to cross-site scripting (XSS) attacks if user-supplied data is not handled with extreme care. The lack of nonce checks, despite having one capability check, is also a weakness, particularly if any form of user interaction is handled, even without explicit AJAX or REST endpoints.\n\nIn conclusion, the plugin benefits from a clean vulnerability history and the absence of common dangerous code patterns. However, the poor output escaping is a significant security flaw that could lead to XSS vulnerabilities. The limited attack surface, while seemingly positive, should be further scrutinized to ensure no potential entry points were missed. Addressing the output escaping issues should be the top priority.",[220,223],{"reason":221,"points":222},"Only 25% of outputs properly escaped",8,{"reason":224,"points":225},"No nonce checks",5,"2026-03-16T21:28:25.688Z",{"wat":228,"direct":233},{"assetPaths":229,"generatorPatterns":230,"scriptPaths":231,"versionParams":232},[],[],[],[],{"cssClasses":234,"htmlComments":237,"htmlAttributes":238,"restEndpoints":241,"jsGlobals":242,"shortcodeOutput":243},[235,236],"pcm-csebd","pcm_csebd",[],[239,240],"id='sendername'","id='senderemail'",[],[],[],{"error":203,"url":245,"statusCode":246,"statusMessage":247,"message":247},"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fcustom-sender-for-email-before-download\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":63,"versions":249},[250],{"version":251,"download_url":252,"svn_tag_url":253,"released_at":27,"has_diff":254,"diff_files_changed":255,"diff_lines":27,"trac_diff_url":27,"vulnerabilities":256,"is_current":254},"0.1.1","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fcustom-sender-for-email-before-download.0.1.1.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fcustom-sender-for-email-before-download\u002Ftags\u002F0.1.1\u002F",false,[],[]]