e-mailing service Security & Risk Analysis

wordpress.org/plugins/e-mailing-service

Full plugin management and sending newsletter.The plugin also sending links your new articles and new pages to your subscribers.

10 active installs v10.8 PHP + WP 3.0.1+ Updated Unknown
e-mailinge-mailsemailingnewslettersend-newsletter
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is e-mailing service Safe to Use in 2026?

Generally Safe

Score 100/100

e-mailing service has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The plugin 'e-mailing-service' v10.8 exhibits a mixed security posture. While the plugin has no recorded CVEs and a seemingly low attack surface in terms of direct entry points like AJAX and REST API routes without authentication, the static analysis reveals significant internal code quality concerns. A very low percentage of SQL queries use prepared statements (11%), and an even lower percentage of output is properly escaped (1%). This indicates a high risk of SQL injection and cross-site scripting (XSS) vulnerabilities, despite the absence of known historical exploits. The high number of file operations (103) also presents a potential attack vector if not handled with extreme care. The taint analysis, which found 37 flows with unsanitized paths, including 5 high severity flows, strongly supports the existence of exploitable vulnerabilities within the plugin's code, even if they haven't been publicly disclosed or exploited yet. The limited number of nonce and capability checks, combined with the extensive use of unescaped output and raw SQL queries, suggests a lack of robust security practices in the plugin's development.

Key Concerns

  • Low percentage of prepared statements
  • Very low percentage of properly escaped output
  • High severity taint flows
  • Large number of file operations
  • Limited nonce and capability checks
Vulnerabilities
None known

e-mailing service Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

e-mailing service Code Analysis

Dangerous Functions
0
Raw SQL Queries
373
46 prepared
Unescaped Output
1171
17 escaped
Nonce Checks
1
Capability Checks
2
File Operations
103
External Requests
2
Bundled Libraries
0

SQL Query Safety

11% prepared419 total queries

Output Escaping

1% escaped1188 total outputs
Data Flows
37 unsanitized

Data Flow Analysis

25 flows37 with unsanitized paths
<create> (admin\create.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

e-mailing service Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[sm_form_contact] e-mailing-service.php:905
WordPress Hooks 63
actionphpmailer_initadmin\debug.php:118
actionphpmailer_initadmin\etat.php:40
actionadmin_print_scriptsadmin\index.php:216
actionadmin_print_scriptsadmin\index_user.php:154
actionadmin_noticese-mailing-service.php:31
actioninite-mailing-service.php:63
actionadmin_menue-mailing-service.php:131
actionadmin_menue-mailing-service.php:134
actionadmin_enqueue_scriptse-mailing-service.php:178
actionadmin_enqueue_scriptse-mailing-service.php:198
actioninite-mailing-service.php:205
actioninite-mailing-service.php:787
filtertemplate_includee-mailing-service.php:831
filteredit_post_linke-mailing-service.php:839
filterthe_titlee-mailing-service.php:840
filteredit_post_linke-mailing-service.php:845
filterthe_titlee-mailing-service.php:846
filteredit_post_linke-mailing-service.php:851
filterthe_titlee-mailing-service.php:852
filteredit_post_linke-mailing-service.php:857
filterthe_titlee-mailing-service.php:858
actionadmin_menue-mailing-service.php:890
actioninite-mailing-service.php:903
filterwp_heade-mailing-service.php:1000
actiontemplate_redirecte-mailing-service.php:1138
actionphpmailer_inite-mailing-service.php:1488
filtercron_schedulese-mailing-service.php:1552
filtercron_schedulese-mailing-service.php:1575
filtercron_schedulese-mailing-service.php:1595
filtercron_schedulese-mailing-service.php:1616
filtercron_schedulese-mailing-service.php:1637
actionsm_cronse-mailing-service.php:1671
actionsm_crons15e-mailing-service.php:1679
actionsm_crons_heure1e-mailing-service.php:1685
actionsm_crons_heures4e-mailing-service.php:1693
actionsm_crons_jours1e-mailing-service.php:1700
actionadd_meta_boxese-mailing-service.php:1717
actionsave_poste-mailing-service.php:1777
filterthe_generatore-mailing-service.php:1855
actionadmin_heade-mailing-service.php:2136
actionadmin_heade-mailing-service.php:2138
filterposts_wheree-mailing-service.php:2167
actionmedia_buttonse-mailing-service.php:2186
actionadmin_heade-mailing-service.php:2229
actionadmin_noticese-mailing-service.php:2258
actionphpmailer_initinclude\cron.php:305
actionphpmailer_initinclude\cron.php:308
actionphpmailer_initinclude\cron_serveur.php:300
actionphpmailer_initinclude\cron_serveur.php:303
actionphpmailer_initinclude\cron_v5.php:34
filteradmin_footer_textinclude\entete.php:20
filterupdate_footerinclude\entete.php:24
actionadmin_headinclude\entete.php:28
actionwp_headinclude\entete.php:29
actiontemplate_redirectinclude\export.php:2
actionwp_dashboard_setupsm_dashboard.php:35
actionwp_dashboard_setupsm_dashboard.php:43
actionload-post.phpsm_news.php:11
actionload-post-new.phpsm_news.php:12
actionadd_meta_boxessm_news.php:24
actionsave_postsm_news.php:25
filtermce_buttons_2sm_news.php:125
actionwidgets_initsm_widget.php:279

Scheduled Events 5

sm_crons
sm_crons15
sm_crons_heure1
sm_crons_heures4
sm_crons_jours1
Maintenance & Trust

e-mailing service Maintenance & Trust

Maintenance Signals

WordPress version tested4.4.34
Last updatedUnknown
PHP min version
Downloads22K

Community Trust

Rating82/100
Number of ratings8
Active installs10
Developer Profile

e-mailing service Developer Profile

Jooky

2 plugins · 20 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect e-mailing service

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/e-mailing-service/include/email_edit.png

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about e-mailing service