
Events Manager – MultiSite Email Security & Risk Analysis
wordpress.org/plugins/events-manager-add-on-multisite-mail-settingsThis add-on has been integrated into Events Manager Email Users as of 21-03-2019. Please install that plugin instead.
Is Events Manager – MultiSite Email Safe to Use in 2026?
Generally Safe
Score 85/100Events Manager – MultiSite Email has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of "events-manager-add-on-multisite-mail-settings" v4.1 reveals a seemingly strong security posture with a zero attack surface from known entry points like AJAX, REST API, and shortcodes. The code also demonstrates good practices by exclusively using prepared statements for SQL queries and avoiding file operations and external HTTP requests. However, a significant concern arises from the extremely low rate of output escaping (17%), indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. The absence of any detected dangerous functions or taint flows is positive, but this could be misleading given the insufficient output escaping.
The vulnerability history shows no known CVEs, which is a positive indicator. This lack of historical vulnerabilities, combined with the absence of complex or potentially risky code patterns, suggests a stable plugin. Nevertheless, the low percentage of properly escaped output is a glaring weakness that could lead to critical vulnerabilities if not addressed. The plugin's strengths lie in its limited attack surface and secure database interaction, but its weakness in output sanitization presents a notable risk.
Key Concerns
- Low output escaping percentage
Events Manager – MultiSite Email Security Vulnerabilities
Events Manager – MultiSite Email Code Analysis
Output Escaping
Events Manager – MultiSite Email Attack Surface
WordPress Hooks 5
Maintenance & Trust
Events Manager – MultiSite Email Maintenance & Trust
Maintenance Signals
Community Trust
Events Manager – MultiSite Email Alternatives
Unconfirmed
unconfirmed
Allows WordPress admins to manage unactivated users, by activating them manually, deleting their pending registrations, or resending the activation em …
Events Manager – Email Users
events-manager-email-users
Free add-on for Events Manager. Send fully customizable HTML emails to all bookings of a specific event per booking status.
Global SMTP
global-smtp
Setup SMTP via wp-config.php.
Events Manager – Event Cancellation
stonehenge-em-cancellation
Adds the "Event Cancelled" status to your EM event and auto-emails a notification to your customers.
Surbma | SMTP
surbma-smtp
External SMTP mail configuration via global variables in wp-config.php.
Events Manager – MultiSite Email Developer Profile
9 plugins · 1K total installs
How We Detect Events Manager – MultiSite Email
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/events-manager-add-on-multisite-mail-settings/events-manager-multisite-email.cssHTML / DOM Fingerprints
<!-- Work Around for Safari -webkit bug --><!-- End of Work Around -->class="workaround"