
Email Attachment by Order Status & Products Security & Risk Analysis
wordpress.org/plugins/email-attachment-by-order-status-productsSend custom attachments with WooCommerce order emails based on order status and purchased products.
Is Email Attachment by Order Status & Products Safe to Use in 2026?
Mostly Safe
Score 78/100Email Attachment by Order Status & Products is generally safe to use. 1 past CVE were resolved. Keep it updated.
The plugin "email-attachment-by-order-status-products" v1.0.1 exhibits a mixed security posture. While it demonstrates good practices such as using prepared statements for all SQL queries and a high percentage of properly escaped output, significant concerns arise from its attack surface and lack of input validation. All four identified AJAX handlers lack authentication checks, presenting a substantial risk for unauthorized access or manipulation of plugin functionality. Furthermore, the presence of two unsanitized flows in taint analysis, even if not reaching critical severity, indicates potential vulnerabilities that could be exploited if user-supplied data is not properly handled.
The vulnerability history reveals a concerning trend. The plugin has one known medium-severity CVE, which is currently unpatched. This indicates a recurring pattern of security flaws, specifically relating to Cross-Site Scripting. The fact that the last vulnerability was dated in the future (2025-07-14) may suggest an error in the reporting, but the existence of an unpatched CVE is a direct indicator of an existing, known security weakness that could be exploited.
In conclusion, while the plugin has strengths in its data handling for SQL and output, the unprotected AJAX endpoints and past vulnerabilities necessitate caution. The lack of proper authentication on AJAX handlers is a critical oversight, and the unpatched CVE poses an immediate threat. Developers should prioritize addressing these critical areas to improve the overall security of the plugin.
Key Concerns
- Unprotected AJAX handlers
- Unpatched CVE (medium severity)
- Flows with unsanitized paths (taint analysis)
- Missing nonce checks on AJAX
Email Attachment by Order Status & Products Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Email Attachment by Order Status & Products <= 1.0.1 - Reflected Cross-Site Scripting
Email Attachment by Order Status & Products Code Analysis
Output Escaping
Data Flow Analysis
Email Attachment by Order Status & Products Attack Surface
AJAX Handlers 4
WordPress Hooks 7
Maintenance & Trust
Email Attachment by Order Status & Products Maintenance & Trust
Maintenance Signals
Community Trust
Email Attachment by Order Status & Products Alternatives
Essential Addons for Elementor – Popular Elementor Templates & Widgets
essential-addons-for-elementor-lite
Elementor addon offering 110+ widgets and templates — Elementor Gallery, Slider, Form, Post Grid, Menu, Accordion, WooCommerce & more.
Google for WooCommerce
google-listings-and-ads
Native integration with Google that allows merchants to easily display their products across Google’s network.
WooPayments: Integrated WooCommerce Payments
woocommerce-payments
Securely accept credit and debit cards on your WooCommerce store. Manage payments without leaving your WordPress dashboard. Only with WooPayments.
WooCommerce PayPal Payments
woocommerce-paypal-payments
PayPal's latest payment processing solution. Accept PayPal, Pay Later, credit/debit cards, alternative digital wallets and bank accounts.
Click to Chat – HoliThemes
click-to-chat-for-whatsapp
WhatsApp Chat🔥. Let's make your Web page visitors contact you through 'WhatsApp', 'WhatsApp Business'. Add matching Widget✅
Email Attachment by Order Status & Products Developer Profile
8 plugins · 550 total installs
How We Detect Email Attachment by Order Status & Products
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/email-attachment-by-order-status-products/backend/css/wot-ea-style.css/wp-content/plugins/email-attachment-by-order-status-products/backend/js/wot-ea-scripts.js/wp-content/plugins/email-attachment-by-order-status-products/backend/js/wot-ea-scripts.jsHTML / DOM Fingerprints
data-wot-ea-idwp.media