Email customizer and designer for woocommerce Security & Risk Analysis

wordpress.org/plugins/email-customizer-and-designer-for-woocommerce

If you tired of default email templates of WooCommerce and you are looking for a way to customize WooCommerce emails. Email Customizer for WooCommerce …

100 active installs v1.0.15 PHP 5.6+ WP 4.9+ Updated Feb 24, 2026
drag-and-drop-email-builderemail-customizeremail-designeremail-templatewoocommerce-email-customizer
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Email customizer and designer for woocommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Email customizer and designer for woocommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "email-customizer-and-designer-for-woocommerce" plugin, version 1.0.15, exhibits a generally strong security posture based on the provided static analysis. The absence of unpatched CVEs and a clean vulnerability history are positive indicators. The code demonstrates good practices with a high percentage of properly escaped outputs and a complete reliance on prepared statements for SQL queries. The attack surface, while containing 13 REST API routes, is secured with permission callbacks, and there are no unprotected entry points identified.

However, a few areas warrant attention. The presence of a file operation, even if seemingly benign, introduces a potential risk if not handled with extreme care regarding user-supplied input. More significantly, the complete lack of nonce checks, particularly given the existence of REST API endpoints, is a notable concern. While no direct vulnerabilities were flagged in the taint analysis, the absence of nonce checks could make certain endpoints susceptible to Cross-Site Request Forgery (CSRF) attacks if they perform sensitive actions.

In conclusion, the plugin is well-engineered in many respects, particularly concerning data handling and external interactions. The lack of known vulnerabilities and secure SQL practices are strengths. The primary weakness lies in the absence of nonce checks, which could be exploited in specific attack scenarios. Addressing this would further solidify the plugin's security.

Key Concerns

  • File operations present
  • No nonce checks detected
Vulnerabilities
None known

Email customizer and designer for woocommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Email customizer and designer for woocommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
177 escaped
Nonce Checks
0
Capability Checks
4
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

99% escaped179 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
handle_preview (includes\class-awecm-front-end.php:572)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Email customizer and designer for woocommerce Attack Surface

Entry Points13
Unprotected0

REST API Routes 13

GET/wp-json/awecm/v1/email-map/includes\class-awecm-api.php:45
POST/wp-json/awecm/v1/change-email-map/includes\class-awecm-api.php:51
POST/wp-json/awecm/v1/save-global-style/includes\class-awecm-api.php:57
GET/wp-json/awecm/v1/get-global-styles/includes\class-awecm-api.php:63
POST/wp-json/awecm/v1/templates/includes\class-awecm-api.php:69
POST/wp-json/awecm/v1/delete-template/includes\class-awecm-api.php:75
POST/wp-json/awecm/v1/save-template/includes\class-awecm-api.php:81
POST/wp-json/awecm/v1/template-data/includes\class-awecm-api.php:87
POST/wp-json/awecm/v1/preview/includes\class-awecm-api.php:93
POST/wp-json/awecm/v1/template-map-preview/includes\class-awecm-api.php:99
POST/wp-json/awecm/v1/sent-mail/includes\class-awecm-api.php:105
GET/wp-json/awecm/v1/customizer-data/includes\class-awecm-api.php:111
POST/wp-json/awecm/v1/get-template-list/includes\class-awecm-api.php:117
WordPress Hooks 15
actionplugins_loadedemail-customizer-and-designer-for-woocommerce.php:48
actionbefore_woocommerce_initemail-customizer-and-designer-for-woocommerce.php:98
actionrest_api_initincludes\class-awecm-api.php:44
filterwp_mail_content_typeincludes\class-awecm-api.php:1011
actionadmin_menuincludes\class-awecm-backend.php:97
actionadmin_enqueue_scriptsincludes\class-awecm-backend.php:99
actionadmin_enqueue_scriptsincludes\class-awecm-backend.php:100
actionadmin_footerincludes\class-awecm-backend.php:105
actionadmin_noticesincludes\class-awecm-backend.php:130
actioninitincludes\class-awecm-front-end.php:95
actioninitincludes\class-awecm-front-end.php:97
actioninitincludes\class-awecm-front-end.php:99
filterwoocommerce_email_stylesincludes\class-awecm-front-end.php:101
filterwoocommerce_locate_templateincludes\class-awecm-front-end.php:103
filtersafe_style_cssincludes\class-awecm-front-end.php:105
Maintenance & Trust

Email customizer and designer for woocommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 24, 2026
PHP min version5.6
Downloads7K

Community Trust

Rating100/100
Number of ratings1
Active installs100
Developer Profile

Email customizer and designer for woocommerce Developer Profile

acowebs

13 plugins · 74K total installs

93
trust score
Avg Security Score
98/100
Avg Patch Time
14 days
View full developer profile
Detection Fingerprints

How We Detect Email customizer and designer for woocommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/email-customizer-and-designer-for-woocommerce/assets/css/awecm-admin-style.css/wp-content/plugins/email-customizer-and-designer-for-woocommerce/assets/css/bootstrap.min.css/wp-content/plugins/email-customizer-and-designer-for-woocommerce/assets/css/colorpicker.css/wp-content/plugins/email-customizer-and-designer-for-woocommerce/assets/css/font-awesome.min.css/wp-content/plugins/email-customizer-and-designer-for-woocommerce/assets/css/summernote.css/wp-content/plugins/email-customizer-and-designer-for-woocommerce/assets/js/admin-script.js/wp-content/plugins/email-customizer-and-designer-for-woocommerce/assets/js/bootstrap.min.js/wp-content/plugins/email-customizer-and-designer-for-woocommerce/assets/js/colorpicker.js+2 more
Version Parameters
/wp-content/plugins/email-customizer-and-designer-for-woocommerce/assets/css/awecm-admin-style.css?ver=/wp-content/plugins/email-customizer-and-designer-for-woocommerce/assets/css/bootstrap.min.css?ver=/wp-content/plugins/email-customizer-and-designer-for-woocommerce/assets/css/colorpicker.css?ver=/wp-content/plugins/email-customizer-and-designer-for-woocommerce/assets/css/font-awesome.min.css?ver=/wp-content/plugins/email-customizer-and-designer-for-woocommerce/assets/css/summernote.css?ver=/wp-content/plugins/email-customizer-and-designer-for-woocommerce/assets/js/admin-script.js?ver=/wp-content/plugins/email-customizer-and-designer-for-woocommerce/assets/js/bootstrap.min.js?ver=/wp-content/plugins/email-customizer-and-designer-for-woocommerce/assets/js/colorpicker.js?ver=/wp-content/plugins/email-customizer-and-designer-for-woocommerce/assets/js/customizer.js?ver=/wp-content/plugins/email-customizer-and-designer-for-woocommerce/assets/js/summernote.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
awecm-admin-wrapawecm-tab-contentawecm-content-wrapperawecm-colorpicker-wrapawecm-font-groupawecm-add-new-templateawecm-editor-btnawecm-section-header
HTML Comments
<!-- AWECM Backend settings --><!-- AWECM Frontend settings --><!-- AWECM Deactivation form -->
Data Attributes
data-awecm-iddata-awecm-template-iddata-awecm-field-type
JS Globals
AWECM_paramsawecm_editor_content
FAQ

Frequently Asked Questions about Email customizer and designer for woocommerce