MailerSend – Transactional emails for WooCommerce Security & Risk Analysis

wordpress.org/plugins/mailersend-transactional-emails-for-woocommerce

Send custom invoices, password reset links, order status updates, and much more, with MailerSend.

200 active installs v1.2.9 PHP + WP 5.7+ Updated Jan 22, 2026
ecommerceemailmailersendwoowoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is MailerSend – Transactional emails for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

MailerSend – Transactional emails for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The mailersend-transactional-emails-for-woocommerce plugin, version 1.2.9, demonstrates some good security practices, particularly in its handling of SQL queries and output escaping. The vast majority of its output is properly escaped, and all SQL queries utilize prepared statements, which significantly reduces the risk of common database-related vulnerabilities. The absence of known CVEs and a clean vulnerability history further contribute to a generally positive security posture.

However, the plugin has a notable security concern regarding its attack surface. It exposes two AJAX handlers that lack authentication checks. This means that any unauthenticated user could potentially interact with these handlers, leading to unintended consequences or information disclosure. While the taint analysis did not reveal critical or high-severity issues with unsanitized paths, the presence of two such flows warrants attention. The plugin also relies on external HTTP requests, which, while not inherently insecure, could be a vector if the external service is compromised or mishandled.

Overall, the plugin is in a decent state of security due to its diligent use of prepared statements and output escaping, along with no recorded vulnerabilities. The primary weakness lies in the unprotected AJAX endpoints. Addressing these would significantly enhance the plugin's security. The plugin's vulnerability history is a strength, suggesting consistent security awareness from the developers. However, the identified unprotected AJAX handlers are the main area of concern that needs immediate attention.

Key Concerns

  • AJAX handlers without authentication checks
  • Flows with unsanitized paths
Vulnerabilities
None known

MailerSend – Transactional emails for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

MailerSend – Transactional emails for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
111 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

97% escaped115 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

5 flows2 with unsanitized paths
mailersend_test_mail (includes\class-mailersend-woocommerce.php:159)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

MailerSend – Transactional emails for WooCommerce Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_check_api_keyincludes\class-mailersend-woocommerce.php:78
authwp_ajax_mailersend_test_mailincludes\class-mailersend-woocommerce.php:79
WordPress Hooks 10
filterplugin_row_metaadmin\class-mailersend-woocommerce-admin.php:38
filterwoocommerce_email_recipient_customer_invoiceincludes\class-mailersend-woocommerce.php:72
filterwoocommerce_email_classesincludes\class-mailersend-woocommerce.php:75
actionplugins_loadedincludes\class-mailersend-woocommerce.php:319
actionadmin_enqueue_scriptsincludes\class-mailersend-woocommerce.php:331
actionadmin_enqueue_scriptsincludes\class-mailersend-woocommerce.php:332
actionadmin_menuincludes\class-mailersend-woocommerce.php:334
actionadmin_noticesmailersend-woocommerce.php:56
actionadmin_initmailersend-woocommerce.php:66
actionbefore_woocommerce_initmailersend-woocommerce.php:85
Maintenance & Trust

MailerSend – Transactional emails for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedJan 22, 2026
PHP min version
Downloads6K

Community Trust

Rating60/100
Number of ratings5
Active installs200
Developer Profile

MailerSend – Transactional emails for WooCommerce Developer Profile

MailerSend

2 plugins · 2K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect MailerSend – Transactional emails for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mailersend-transactional-emails-for-woocommerce/admin/css/mailersend-woocommerce-admin.css/wp-content/plugins/mailersend-transactional-emails-for-woocommerce/admin/css/admin.css/wp-content/plugins/mailersend-transactional-emails-for-woocommerce/admin/js/mailersend-woocommerce-admin.js
Script Paths
wp-content/plugins/mailersend-transactional-emails-for-woocommerce/admin/js/mailersend-woocommerce-admin.js
Version Parameters
mailersend-transactional-emails-for-woocommerce/admin/css/mailersend-woocommerce-admin.css?ver=mailersend-transactional-emails-for-woocommerce/admin/css/admin.css?ver=mailersend-transactional-emails-for-woocommerce/admin/js/mailersend-woocommerce-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
mailersend-woocommerce-admin-wrap
Data Attributes
data-mailersend-noncedata-mailersend-admin-url
JS Globals
mailersend_woocommerce_admin_params
FAQ

Frequently Asked Questions about MailerSend – Transactional emails for WooCommerce