Events Manager – MultiSite Email Security & Risk Analysis

wordpress.org/plugins/events-manager-add-on-multisite-mail-settings

This add-on has been integrated into Events Manager Email Users as of 21-03-2019. Please install that plugin instead.

0 active installs v4.1 PHP 7.0+ WP 4.5+ Updated Mar 21, 2019
bookingsemailevents-managermailmultisite
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Events Manager – MultiSite Email Safe to Use in 2026?

Generally Safe

Score 85/100

Events Manager – MultiSite Email has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The static analysis of "events-manager-add-on-multisite-mail-settings" v4.1 reveals a seemingly strong security posture with a zero attack surface from known entry points like AJAX, REST API, and shortcodes. The code also demonstrates good practices by exclusively using prepared statements for SQL queries and avoiding file operations and external HTTP requests. However, a significant concern arises from the extremely low rate of output escaping (17%), indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. The absence of any detected dangerous functions or taint flows is positive, but this could be misleading given the insufficient output escaping.

The vulnerability history shows no known CVEs, which is a positive indicator. This lack of historical vulnerabilities, combined with the absence of complex or potentially risky code patterns, suggests a stable plugin. Nevertheless, the low percentage of properly escaped output is a glaring weakness that could lead to critical vulnerabilities if not addressed. The plugin's strengths lie in its limited attack surface and secure database interaction, but its weakness in output sanitization presents a notable risk.

Key Concerns

  • Low output escaping percentage
Vulnerabilities
None known

Events Manager – MultiSite Email Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Events Manager – MultiSite Email Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

17% escaped6 total outputs
Attack Surface

Events Manager – MultiSite Email Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionplugins_loadedevents-manager-multisite-email.php:53
actionadmin_menuevents-manager-multisite-email.php:92
actionadmin_initevents-manager-multisite-email.php:93
actionplugins_loadedevents-manager-multisite-email.php:95
actionem_mailerevents-manager-multisite-email.php:96
Maintenance & Trust

Events Manager – MultiSite Email Maintenance & Trust

Maintenance Signals

WordPress version tested5.1.22
Last updatedMar 21, 2019
PHP min version7.0
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

Events Manager – MultiSite Email Developer Profile

Stonehenge Creations

9 plugins · 1K total installs

83
trust score
Avg Security Score
84/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Events Manager – MultiSite Email

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/events-manager-add-on-multisite-mail-settings/events-manager-multisite-email.css

HTML / DOM Fingerprints

HTML Comments
<!-- Work Around for Safari -webkit bug --><!-- End of Work Around -->
Data Attributes
class="workaround"
FAQ

Frequently Asked Questions about Events Manager – MultiSite Email