
Elastic Email Sender Security & Risk Analysis
wordpress.org/plugins/elastic-email-senderReconfigures wp_mail() to send email using Elastic Email API instead of SMTP.
Is Elastic Email Sender Safe to Use in 2026?
Generally Safe
Score 98/100Elastic Email Sender has a strong security track record. Known vulnerabilities have been patched promptly.
The elastic-email-sender plugin exhibits a mixed security posture, with some positive indicators but notable areas of concern. The static analysis reveals a small attack surface with only two entry points, one of which lacks authentication checks. While the taint analysis shows no critical or high severity issues, the presence of two AJAX handlers, one unprotected, represents a significant potential weakness that could be exploited if input validation is insufficient. The vulnerability history, including two past medium-severity vulnerabilities related to missing authorization and cross-site scripting, suggests a recurring pattern of weaknesses in these areas. Although there are currently no unpatched vulnerabilities, the historical pattern is a strong indicator that similar issues could re-emerge. The plugin demonstrates good practices in output escaping and the use of prepared statements for SQL queries, which are strengths. However, the unprotected AJAX handler and the historical vulnerability types are substantial concerns that require attention.
Key Concerns
- Unprotected AJAX handler
- Past medium vulnerabilities (Missing Authorization)
- Past medium vulnerabilities (XSS)
Elastic Email Sender Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Elastic Email Sender <= 1.2.20 - Missing Authorization
Elastic Email Sender <= 1.2.6 - Authenticated (Administrator+) Stored Cross-Site Scripting
Elastic Email Sender Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Elastic Email Sender Attack Surface
AJAX Handlers 2
WordPress Hooks 8
Maintenance & Trust
Elastic Email Sender Maintenance & Trust
Maintenance Signals
Community Trust
Elastic Email Sender Alternatives
Avang Email Sender No Spam
avang-email-sender-no-spam
This plugin reconfigures the wp_mail() function to send email using API (via AvangEmail) instead of SMTP and creates a Settings page that allows you t …
MailerLite – WooCommerce integration
woo-mailerlite
Powerful e-commerce email marketing tools that are easy to use. Grow your store with automated emails, pop-ups, product blocks, sales tracking + more.
Zoho ZeptoMail
transmail
Zoho ZeptoMail Plugin lets you configure your ZeptoMail account on your WordPress site enabling you to send transactional emails of your site via Zept …
Connect SendGrid for Emails
connect-sendgrid-for-emails
Connect SendGrid to your WordPress site to send emails using SendGrid's cloud-based email platform.
Mass Email To users
mass-email-to-users
Mass Email To Users is the plugin for sending a mass email to WordPress users. Admin can send an email to WordPress users together.
Elastic Email Sender Developer Profile
2 plugins · 10K total installs
How We Detect Elastic Email Sender
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/elastic-email-sender/css/ees-bootstrap-grid.css/wp-content/plugins/elastic-email-sender/css/ees-css.csselastic-email-sender/css/ees-bootstrap-grid.css?ver=elastic-email-sender/css/ees-css.css?ver=HTML / DOM Fingerprints
eewp-evmab-frvvreewp-containeree-headeree-pagetitleee-pmargin-p-xssettings-box-formphpcs:ignore WordPress.Security.NonceVerification.Recommended -- settings-updated is added by WordPress Settings API after saving settingsdata-tab="main"data-tab="api"data-tab="woocommerce"data-tab="settings"data-tab="log"data-tab="channels"window.ees_wp_data