
Network Mass Email Security & Risk Analysis
wordpress.org/plugins/network-mass-emailAllows network admins to send a manually created notification email to all registered users based on user role.
Is Network Mass Email Safe to Use in 2026?
Generally Safe
Score 85/100Network Mass Email has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'network-mass-email' v1.5 presents a concerning security posture despite having no recorded vulnerabilities in its history. The static analysis reveals a significant weakness in output escaping, with 0% of the 26 identified outputs being properly escaped. This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected into the user interface via the plugin's outputs. Furthermore, the taint analysis identified 5 high-severity flows with unsanitized paths, suggesting potential for data manipulation or unauthorized access if these paths are triggered through user input. While the plugin has no known CVEs and a relatively low number of SQL queries, the complete absence of nonce checks and capability checks, combined with the output escaping issues and taint analysis findings, creates a substantial attack surface that could be exploited. The lack of these fundamental security checks on entry points (though stated as 0, this might be an artifact of analysis or very limited functionality) is a critical oversight. In conclusion, while the plugin boasts a clean vulnerability history, the static analysis points to critical underlying security flaws that require immediate attention to mitigate XSS and other potential data-related vulnerabilities.
Key Concerns
- High severity taint flows with unsanitized paths
- 0% properly escaped output
- Missing nonce checks
- Missing capability checks
- Raw SQL queries (29% prepared)
Network Mass Email Security Vulnerabilities
Network Mass Email Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Network Mass Email Attack Surface
WordPress Hooks 2
Maintenance & Trust
Network Mass Email Maintenance & Trust
Maintenance Signals
Community Trust
Network Mass Email Alternatives
Unconfirmed
unconfirmed
Allows WordPress admins to manage unactivated users, by activating them manually, deleting their pending registrations, or resending the activation em …
Metro Share Widget
metro-share-widget
Add Metro style social share widget to your sidebar. 5 most popular social networks supported
Network Username Restrictions Override
network-username-restrictions-override
Override restrictions on WordPress network usernames.
Plugin Activation Status
plugin-activation-status
Scans a multisite or multi-network installation to identify all plugins that are active or not.
WP Over Network
wp-over-network
Add ability to get posts from over your network sites. Supports widget, shortcode, and customizable original function.
Network Mass Email Developer Profile
1 plugin · 10 total installs
How We Detect Network Mass Email
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/network-mass-email/icon.pngHTML / DOM Fingerprints
nmeerrorCopyright 2012 Kenny Zaron (email: kzaron@gmail.com)Mail Icon(s) courtesy of: http://www.iconhot.com/icon/android-style-icons-r1/mail-64.htmlname="massemailform"id="nmeerror"name="emailssent"id="emailssent"name="allincsubs"id="allincsubs"+1 more