eShop Order Emailer Security & Risk Analysis

wordpress.org/plugins/eshop-order-emailer

Email your successful eShop orders to one or more email addresses for unlimited suppliers.

10 active installs v2.1.1 PHP + WP 3.3+ Updated Feb 8, 2013
csvemaileshopfulfillmentorders
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is eShop Order Emailer Safe to Use in 2026?

Generally Safe

Score 85/100

eShop Order Emailer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 13yr ago
Risk Assessment

The eshop-order-emailer v2.1.1 plugin exhibits a generally positive security posture based on the provided static analysis. The absence of any registered AJAX handlers, REST API routes, shortcodes, or cron events significantly limits its potential attack surface, which is a strong security practice. Furthermore, the use of prepared statements for all SQL queries and the lack of known CVEs in its history are commendable. However, the static analysis reveals a significant concern regarding output escaping, as 100% of detected outputs are not properly escaped. This could lead to cross-site scripting (XSS) vulnerabilities if any user-supplied data is ever reflected in the plugin's output without sanitization. The lack of nonce and capability checks on any potential entry points (though none are explicitly identified in this analysis) also presents a theoretical risk, as it implies that if entry points were to be added in future updates or through unforeseen interactions, they might be exposed.

Key Concerns

  • Unescaped output detected
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

eShop Order Emailer Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

eShop Order Emailer Release Timeline

v2.1.1Current
v2.1.0
v2.0.1
v2
v1.1
Code Analysis
Analyzed Apr 16, 2026

eShop Order Emailer Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
6 prepared
Unescaped Output
2
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
4
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared6 total queries

Output Escaping

0% escaped2 total outputs
Attack Surface

eShop Order Emailer Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actioneshop_order_status_updatedeordem.php:101
actionwp_loadedeordem.php:105
Maintenance & Trust

eShop Order Emailer Maintenance & Trust

Maintenance Signals

WordPress version tested3.5.2
Last updatedFeb 8, 2013
PHP min version
Downloads8K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

eShop Order Emailer Developer Profile

CPK Web Solutions

5 plugins · 250 total installs

69
trust score
Avg Security Score
85/100
Avg Patch Time
4120 days
View full developer profile
Detection Fingerprints

How We Detect eShop Order Emailer

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/eshop-order-emailer/css/eshop-order-emailer.css/wp-content/plugins/eshop-order-emailer/js/eshop-order-emailer.js
Script Paths
/wp-content/plugins/eshop-order-emailer/js/eshop-order-emailer.js
Version Parameters
eshop-order-emailer/css/eshop-order-emailer.css?ver=eshop-order-emailer/js/eshop-order-emailer.js?ver=

HTML / DOM Fingerprints

CSS Classes
pws_eordem
HTML Comments
<!-- Automatically email eShop orders to your suppliers or a fulfillment center. --><!-- LICENSE --><!-- Copyright 2012 Paul's Web Solutions (email : paul@paulswebsolutions.com ) --><!-- This program is free software; you can redistribute it and/or modify -->+16 more
Data Attributes
data-plugin-name="eShop Order Emailer"data-plugin-version="2.1.1"
JS Globals
eordempwsPlugin_1_0
FAQ

Frequently Asked Questions about eShop Order Emailer