
Email Reminders Security & Risk Analysis
wordpress.org/plugins/email-remindersSending friendly email reminders or follow-up emails based on custom rules.
Is Email Reminders Safe to Use in 2026?
Generally Safe
Score 99/100Email Reminders has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "email-reminders" plugin version 2.0.7 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by utilizing prepared statements for 95% of its SQL queries and incorporates a significant number of nonce and capability checks (29 and 3 respectively), suggesting an effort to protect against common WordPress threats. The absence of external HTTP requests also reduces its attack surface in that regard.
However, several concerning signals emerge from the static analysis. The presence of the `unserialize()` function, without explicit mention of input sanitization prior to its use, is a critical risk. This function is notoriously dangerous as it can lead to Remote Code Execution (RCE) if used with untrusted input. Furthermore, the taint analysis reveals 4 flows with unsanitized paths, though thankfully none are categorized as critical or high severity. The output escaping is also a concern, with only 51% of outputs being properly escaped, indicating a significant risk of Cross-Site Scripting (XSS) vulnerabilities.
The vulnerability history shows 2 known medium severity CVEs, both of which are reported as patched. The common vulnerability type being Cross-site Scripting aligns with the findings of insufficient output escaping. While there are no currently unpatched vulnerabilities, the existence of past XSS issues reinforces the need for robust output sanitization. In conclusion, the plugin has some strong security foundations but requires immediate attention regarding the `unserialize()` usage and improvement in output escaping to mitigate significant risks.
Key Concerns
- Unsanitized paths in taint analysis
- Low percentage of properly escaped output
- Presence of 'unserialize' function
- Past medium severity CVEs (XSS)
Email Reminders Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Email Reminders <= 2.0.5 - Authenticated (Administrator+) Stored Cross-Site Scripting
Email Reminders <= 2.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter
Email Reminders Release Timeline
Email Reminders Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Email Reminders Attack Surface
Shortcodes 3
WordPress Hooks 123
Maintenance & Trust
Email Reminders Maintenance & Trust
Maintenance Signals
Community Trust
Email Reminders Alternatives
FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce
wp-marketing-automations
Recover lost revenue with Cart Abandonment Recovery for WooCommerce. Increase retention with Post Purchase Follow-Up Emails.
ShopMagic – email automation
shopmagic-for-woocommerce
Flexible email automation and workflows triggered by customer and site events.
Follow Up Emails
follow-up-emails
Automate personalized follow-up emails for your WooCommerce store based on customer actions and product details.
MailPoet – Newsletters, Email Marketing, and Automation
mailpoet
Send beautiful newsletters from WordPress. Collect subscribers with signup forms, automate your emails for WooCommerce, blog post notifications & more
YayMail – WooCommerce Email Customizer
yaymail
Customize WooCommerce email templates with an advanced drag-and-drop email builder. Works great with 80+ WooCommerce Email Customizer Addons.
Email Reminders Developer Profile
25 plugins · 59K total installs
How We Detect Email Reminders
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/email-reminders/css/main.css/wp-content/plugins/email-reminders/js/main.js/wp-content/plugins/email-reminders/js/datepicker.js/wp-content/plugins/email-reminders/js/admin-scripts.js/wp-content/plugins/email-reminders/css/admin-scripts.cssemail-reminders/css/main.css?ver=email-reminders/js/main.js?ver=email-reminders/js/datepicker.js?ver=email-reminders/js/admin-scripts.js?ver=email-reminders/css/admin-scripts.css?ver=HTML / DOM Fingerprints
email_reminders_settings_pageemail-remindersdata-email-reminders-idoper_settings