Email Templates Customizer for WooCommerce + Drag And Drop Template Builder Security & Risk Analysis

wordpress.org/plugins/email-templates-customizer-for-woocommerce

Allows you to easily customize the email templates sent to your customers in WooCommerce

30 active installs v1.0.2 PHP + WP 2.0+ Updated Nov 28, 2025
email-orderorderwoo-mailwoocommercewoocommerce-email
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Email Templates Customizer for WooCommerce + Drag And Drop Template Builder Safe to Use in 2026?

Generally Safe

Score 100/100

Email Templates Customizer for WooCommerce + Drag And Drop Template Builder has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The email-templates-customizer-for-woocommerce plugin version 1.0.2 exhibits a generally strong security posture based on the static analysis. The absence of known CVEs and the consistent use of prepared statements for SQL queries are significant strengths. The plugin also demonstrates good practices with a high percentage of properly escaped output and the presence of nonce and capability checks on its entry points. The limited attack surface, with only one AJAX handler and no exposed REST API routes or shortcodes, further contributes to its secure design.

However, there are a couple of areas that warrant attention. The taint analysis revealed two flows with unsanitized paths, and while categorized as not critical or high severity, these represent potential avenues for unexpected behavior or information leakage if an attacker can manipulate the input leading to these flows. The presence of file operations and external HTTP requests, while not inherently insecure, are points that should be carefully reviewed to ensure they are handled in a secure and predictable manner. Overall, the plugin appears to be well-developed from a security perspective, but the identified taint flows suggest a need for further scrutiny of input validation.

The vulnerability history is completely clean, with no recorded CVEs. This indicates a responsible development team that likely addresses security issues promptly, or the plugin has not yet attracted significant security research. While this is a positive indicator, it's important to remember that even well-maintained plugins can have undiscovered vulnerabilities. The current lack of historical issues combined with the generally good static analysis results suggests a low risk, but the taint analysis findings should not be ignored.

Key Concerns

  • Taint flows with unsanitized paths identified
  • Presence of file operations
  • Presence of external HTTP requests
Vulnerabilities
None known

Email Templates Customizer for WooCommerce + Drag And Drop Template Builder Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Email Templates Customizer for WooCommerce + Drag And Drop Template Builder Release Timeline

v1.0.2Current
Code Analysis
Analyzed Mar 16, 2026

Email Templates Customizer for WooCommerce + Drag And Drop Template Builder Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
23
282 escaped
Nonce Checks
1
Capability Checks
2
File Operations
1
External Requests
2
Bundled Libraries
0

Output Escaping

92% escaped305 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
yeemail_template (woocommerce\woocommerce.php:377)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Email Templates Customizer for WooCommerce + Drag And Drop Template Builder Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_yeekit_dismiss_notyyeekit\document.php:13
WordPress Hooks 19
filterwc_get_templatewoocommerce\processing.php:5
filterviews_edit-yeemail_template_addonswoocommerce\processing.php:6
filteryeemail_shortcodeswoocommerce\shortcodes.php:7
actionyeemail_builder_tab_block_addonswoocommerce\woocommerce.php:5
filteryeemail_builder_block_htmlwoocommerce\woocommerce.php:6
filteryeemail_id_show_demowoocommerce\woocommerce.php:7
actionyeemail_builder_tab__editor_beforewoocommerce\woocommerce.php:8
actionyeemail_header_builderwoocommerce\woocommerce.php:9
actionsave_post_yeemail_templatewoocommerce\woocommerce.php:10
actionadmin_menuyeekit\document.php:10
actionadmin_enqueue_scriptsyeekit\document.php:11
filterfluentform_global_addonsyeekit\document.php:12
actionadmin_noticesyeekit\document.php:14
actionelementor/element/form/section_form_options/after_section_endyeekit\document.php:15
actionadmin_inityeekit\document.php:17
actionelementor/editor/after_enqueue_stylesyeekit\document.php:19
filterhttp_responseyeekit\document.php:208
actionplugins_loadedyeemail-for-woocommerce.php:19
actionadmin_noticesyeemail-for-woocommerce.php:26
Maintenance & Trust

Email Templates Customizer for WooCommerce + Drag And Drop Template Builder Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedNov 28, 2025
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs30
Developer Profile

Email Templates Customizer for WooCommerce + Drag And Drop Template Builder Developer Profile

add-ons.org

59 plugins · 26K total installs

87
trust score
Avg Security Score
99/100
Avg Patch Time
48 days
View full developer profile
Detection Fingerprints

How We Detect Email Templates Customizer for WooCommerce + Drag And Drop Template Builder

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
yeekit_addons_listyeekit_addons_list li
JS Globals
yeekit_document_addons
FAQ

Frequently Asked Questions about Email Templates Customizer for WooCommerce + Drag And Drop Template Builder