
Resend Welcome Email Security & Risk Analysis
wordpress.org/plugins/resend-welcome-emailQuickly send a new welcome email and password reset link for a user through the user's profile edit area.
Is Resend Welcome Email Safe to Use in 2026?
Generally Safe
Score 85/100Resend Welcome Email has a strong security track record. Known vulnerabilities have been patched promptly.
The "resend-welcome-email" plugin v1.1.9 exhibits a generally good security posture based on the provided static analysis. The absence of identified AJAX handlers, REST API routes, shortcodes, and cron events with unprotected entry points is a significant strength. Furthermore, the plugin demonstrates adherence to secure coding practices by not utilizing dangerous functions, performing all SQL queries using prepared statements, and having no file operations or external HTTP requests. The presence of capability checks also indicates an attempt to restrict functionality to authorized users.
However, there are areas for concern. The taint analysis revealing no flows is positive, but the static analysis shows that only 50% of the output is properly escaped, with two outputs in total. This suggests a potential for Cross-Site Scripting (XSS) vulnerabilities if the unescaped outputs handle user-supplied data without adequate sanitization. While no current vulnerabilities are unpatched, the plugin has a history of one known CVE, specifically an XSS vulnerability from 2015. This historical pattern, coupled with the current output escaping issue, warrants caution.
In conclusion, the plugin's architecture is relatively secure with a minimal attack surface and good data handling for SQL. The primary weakness lies in the incomplete output escaping, which, combined with its past XSS vulnerability, presents a moderate risk. While the plugin has no unpatched CVEs and a clean taint analysis, the potential for XSS remains a concern that should be addressed by ensuring all output is properly escaped.
Key Concerns
- 50% of outputs not properly escaped
- Historical XSS vulnerability (2015)
Resend Welcome Email Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Resend Welcome Email <= 1.0.1 - Reflected Cross-Site Scripting
Resend Welcome Email Code Analysis
Output Escaping
Resend Welcome Email Attack Surface
WordPress Hooks 6
Maintenance & Trust
Resend Welcome Email Maintenance & Trust
Maintenance Signals
Community Trust
Resend Welcome Email Alternatives
New User Approve
new-user-approve
WordPress user approval plugin to moderate registrations. Approve or deny real users and prevent fake signups to control who registers on site.
Support Me
support-me
Allows you to generate expireable user accounts for support purposes.
Bulk Delete Users by Keyword
bulk-delete-users-by-keyword
Efficiently manage your WordPress users with keyword-based bulk deletion capabilities.
Last Users Order Column for WooCommerce
last-users-order-column-for-woocommerce
Plugin that allows you to easily see last order for a user in WordPress user list, trivial setup - upload and enable.
Users Bulk Delete With Preview
users-bulk-delete-with-preview
Easily delete multiple WordPress users with the Users Bulk Delete With Preview plugin. Preview details before removal for accuracy and better control.
Resend Welcome Email Developer Profile
4 plugins · 1K total installs
How We Detect Resend Welcome Email
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/resend-welcome-email/resend-welcome-email.php