
Event Espresso – Custom Email Template Shortcode Security & Risk Analysis
wordpress.org/plugins/email-shortcodeCreate a Custom Shortcode for Default Message Template of Event Espresso.
Is Event Espresso – Custom Email Template Shortcode Safe to Use in 2026?
Use With Caution
Score 64/100Event Espresso – Custom Email Template Shortcode has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "email-shortcode" plugin version 1.0.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and avoiding file operations and external HTTP requests. The presence of nonce checks and a low number of total entry points are also encouraging signs. However, the static analysis reveals that 29% of output operations are not properly escaped, which presents a potential Cross-Site Scripting (XSS) risk. Furthermore, the absence of capability checks on any entry points means that if any were discovered, they could be accessed by any user. The vulnerability history is a significant concern, with one unpatched medium-severity CVE related to XSS. The fact that the last vulnerability was in the near future (2025) and is still unpatched strongly suggests that the plugin is not actively maintained or that the developer is not addressing known security flaws promptly. While the code itself has some strengths, the unpatched vulnerability and the potential for unescaped output create a notable risk that requires immediate attention.
Key Concerns
- Unpatched medium severity CVE
- Unescaped output (29%)
- No capability checks on entry points
Event Espresso – Custom Email Template Shortcode Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Event Espresso – Custom Email Template Shortcode <= 1.0.0 - Reflected Cross-Site Scripting
Event Espresso – Custom Email Template Shortcode Release Timeline
Event Espresso – Custom Email Template Shortcode Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Event Espresso – Custom Email Template Shortcode Attack Surface
WordPress Hooks 9
Maintenance & Trust
Event Espresso – Custom Email Template Shortcode Maintenance & Trust
Maintenance Signals
Community Trust
Event Espresso – Custom Email Template Shortcode Alternatives
Eway Payment Gateway
eway-payment-gateway
Take credit card payments via Eway in some popular WordPress plugins
Hide Unwanted Shortcodes
hide-unwanted-shortcodes
A plugin to prevent unwanted shortcodes from showing on blog.
Files Addon for Event Espresso 4
files-addon-for-event-espresso-4
Files add on plugin allows to create file upload type question which can be used in event registration form.
Custom QR Code Generator
custom-qr-code-generator
Easily generate customizable QR codes for websites, products, and events with this user-friendly WordPress plugin.
Event Espresso Smooth Integration
event-espresso-smooth-integration
Developed for Event Espresso 4. (Not tested with EE3)
Event Espresso – Custom Email Template Shortcode Developer Profile
4 plugins · 50 total installs
How We Detect Event Espresso – Custom Email Template Shortcode
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/email-shortcode/admin/css/ee-email-shortcode-admin.css/wp-content/plugins/email-shortcode/admin/js/ee-email-shortcode-admin.js/wp-content/plugins/email-shortcode/admin/js/ee-email-shortcode-admin.jsee-email-shortcode-admin.css?ver=ee-email-shortcode-admin.js?ver=HTML / DOM Fingerprints
eees_menu-title-tag