Multiple Email Recipients for WooCommerce Security & Risk Analysis

wordpress.org/plugins/email-recipients-for-woocommerce

Set custom recipients for WooCommerce emails.

60 active installs v2.0.0 PHP + WP 4.4+ Updated May 29, 2025
emailemailsrecipientwoo-commercewoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Multiple Email Recipients for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Multiple Email Recipients for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10mo ago
Risk Assessment

The plugin "email-recipients-for-woocommerce" v2.0.0 demonstrates a generally strong security posture based on the provided static analysis. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, significantly limiting the potential attack surface. Furthermore, the code signals indicate a complete absence of dangerous functions and file operations. All SQL queries are properly handled with prepared statements, and there are no external HTTP requests or bundled libraries to consider. This suggests a careful development approach focused on minimizing common WordPress vulnerabilities.

However, a notable concern arises from the output escaping. With only 50% of the identified outputs being properly escaped, there's a potential for Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is rendered directly into the HTML without sufficient sanitization. While the taint analysis did not reveal any specific unsanitized paths or critical/high severity flows, the absence of these findings could be influenced by the limited scope of the taint analysis itself. The plugin's vulnerability history is remarkably clean, with no recorded CVEs, which is a positive indicator of its security track record.

In conclusion, the plugin exhibits a commendable lack of common vulnerability vectors and a clean history. The primary weakness identified is the incomplete output escaping, which warrants attention. If the taint analysis was comprehensive, the absence of other severe issues is a strong positive. The overall security is good, but the XSS risk should be addressed.

Key Concerns

  • 50% of outputs not properly escaped
Vulnerabilities
None known

Multiple Email Recipients for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Multiple Email Recipients for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

50% escaped2 total outputs
Attack Surface

Multiple Email Recipients for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionplugins_loadedemail-recipients-for-woocommerce.php:54
actioninitincludes\class-alg-wc-email-recipients-core.php:45
filterwoocommerce_email_headersincludes\class-alg-wc-email-recipients-core.php:77
filterwoocommerce_email_headersincludes\class-alg-wc-email-recipients-core.php:85
actioninitincludes\class-alg-wc-email-recipients.php:72
actionbefore_woocommerce_initincludes\class-alg-wc-email-recipients.php:75
filterwoocommerce_get_settings_pagesincludes\class-alg-wc-email-recipients.php:154
actionadmin_initincludes\class-alg-wc-email-recipients.php:158
filterwoocommerce_get_sections_alg_wc_email_recipientsincludes\settings\class-alg-wc-email-recipients-settings-section.php:38
filterwoocommerce_admin_settings_sanitize_optionincludes\settings\class-alg-wc-email-recipients-settings.php:29
actionadmin_noticesincludes\settings\class-alg-wc-email-recipients-settings.php:104
Maintenance & Trust

Multiple Email Recipients for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMay 29, 2025
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs60
Developer Profile

Multiple Email Recipients for WooCommerce Developer Profile

Algoritmika

14 plugins · 510 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Multiple Email Recipients for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/email-recipients-for-woocommerce/assets/css/admin.css/wp-content/plugins/email-recipients-for-woocommerce/assets/js/admin.js
Script Paths
/wp-content/plugins/email-recipients-for-woocommerce/assets/js/admin.js
Version Parameters
email-recipients-for-woocommerce/assets/css/admin.css?ver=email-recipients-for-woocommerce/assets/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
alg-wc-email-recipients-admin-css
JS Globals
alg_wc_email_recipients_params
FAQ

Frequently Asked Questions about Multiple Email Recipients for WooCommerce