
Events Manager – Email Users Security & Risk Analysis
wordpress.org/plugins/events-manager-email-usersFree add-on for Events Manager. Send fully customizable HTML emails to all bookings of a specific event per booking status.
Is Events Manager – Email Users Safe to Use in 2026?
Generally Safe
Score 85/100Events Manager – Email Users has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "events-manager-email-users" plugin version 4.8.2 exhibits a mixed security posture. While it demonstrates good practices by not utilizing dangerous functions, all SQL queries are properly prepared, and there are no recorded vulnerabilities, there are significant concerns regarding its attack surface. A total of 4 AJAX handlers are present, and alarmingly, all of them lack authentication checks. This is a major security weakness, as it exposes these handlers to potential abuse by unauthenticated users, which could lead to various exploits depending on the handler's functionality. The plugin also performs file operations and external HTTP requests, which, without proper input validation and authorization, could be leveraged in attacks. Although taint analysis shows no critical or high severity unsanitized paths, the lack of authentication on AJAX handlers is a substantial risk that overshadows the otherwise positive indicators like proper SQL usage and absence of historical CVEs. The plugin's history of no vulnerabilities is a positive sign, but it cannot negate the present risks stemming from the unprotected AJAX endpoints. Further investigation into the specific functions of these AJAX handlers is crucial to fully understand the potential impact of these vulnerabilities.
Key Concerns
- Unprotected AJAX handlers
- Low output escaping percentage
- File operations without apparent checks
- External HTTP requests without apparent checks
Events Manager – Email Users Security Vulnerabilities
Events Manager – Email Users Code Analysis
Output Escaping
Data Flow Analysis
Events Manager – Email Users Attack Surface
AJAX Handlers 4
WordPress Hooks 51
Maintenance & Trust
Events Manager – Email Users Maintenance & Trust
Maintenance Signals
Community Trust
Events Manager – Email Users Alternatives
Events Manager – Event Cancellation
stonehenge-em-cancellation
Adds the "Event Cancelled" status to your EM event and auto-emails a notification to your customers.
Events Manager – MultiSite Email
events-manager-add-on-multisite-mail-settings
This add-on has been integrated into Events Manager Email Users as of 21-03-2019. Please install that plugin instead.
WP Mail SMTP by WPForms – The Most Popular SMTP and Email Log Plugin
wp-mail-smtp
Make email delivery easy for WordPress. Connect with SMTP, Gmail, Outlook, SendGrid, Mailgun, SES, Zoho, + more. Rated #1 WordPress SMTP Email plugin.
Easy WP SMTP – WordPress SMTP and Email Logs: Gmail, Office 365, Outlook, Custom SMTP, and more
easy-wp-smtp
Make SMTP email sending and delivery easy. Configure Gmail, Outlook, Brevo, SendGrid, Mailgun, SendLayer or connect to any SMTP server.
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App
post-smtp
Improve WordPress email deliverability. Connect Gmail SMTP, Microsoft 365, Brevo, SendGrid, Mailgun, Zoho, Amazon SES, etc. #1 WordPress SMTP Plugin.
Events Manager – Email Users Developer Profile
9 plugins · 1K total installs
How We Detect Events Manager – Email Users
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/events-manager-email-users/assets/em-email-users.min.js/wp-content/plugins/events-manager-email-users/assets/em-email-users.min.jsevents-manager-email-users/assets/em-email-users.min.js?ver=HTML / DOM Fingerprints
dashicons-email-altEMU