
Split Email Providers Security & Risk Analysis
wordpress.org/plugins/split-email-providersSplit Email Providers is a WooCommerce addon that automatically sends emails to suppliers for each order, simplifying communication.
Is Split Email Providers Safe to Use in 2026?
Generally Safe
Score 100/100Split Email Providers has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'split-email-providers' plugin version 1.1.4 exhibits a concerning security posture primarily due to a significant attack surface with no authentication checks. All 8 identified AJAX handlers are unprotected, presenting a direct pathway for unauthenticated attackers to interact with the plugin's functionality. While the code demonstrates good practices in other areas, such as 100% output escaping and extensive use of prepared statements for SQL queries, the lack of authentication on these entry points is a critical weakness.
The static analysis found no dangerous functions or critical taint flows, and the vulnerability history is clean, indicating a potentially well-maintained codebase in terms of known exploits and secure coding practices for SQL and output handling. However, the absence of capability checks on the majority of AJAX handlers, coupled with the 7 nonces that are likely not covering all 8 AJAX handlers effectively, leaves a substantial portion of the plugin's functionality exposed. This could lead to potential abuse, unauthorized actions, or denial-of-service attacks if the AJAX handlers perform sensitive operations.
In conclusion, while the plugin avoids common pitfalls like raw SQL or unescaped output, the critical flaw of unprotected AJAX endpoints overshadows these strengths. The clean vulnerability history is a positive sign, but the immediate risk posed by the exposed attack surface requires attention. Further investigation into what actions these unprotected AJAX handlers perform is crucial to fully assess the potential impact.
Key Concerns
- 8 unprotected AJAX handlers
- 7 nonce checks, likely insufficient for 8 AJAX handlers
- 2 capability checks, insufficient for 8 AJAX handlers
Split Email Providers Security Vulnerabilities
Split Email Providers Release Timeline
Split Email Providers Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Split Email Providers Attack Surface
AJAX Handlers 8
WordPress Hooks 12
Maintenance & Trust
Split Email Providers Maintenance & Trust
Maintenance Signals
Community Trust
Split Email Providers Alternatives
HoneyBadger.IT
honeybadger-it
WC Order Management System including custom order statuses, emails, attachments, split orders, combine orders, variant image gallery, PDF Invoices, ma …
MailPoet – Newsletters, Email Marketing, and Automation
mailpoet
Send beautiful newsletters from WordPress. Collect subscribers with signup forms, automate your emails for WooCommerce, blog post notifications & more
Kadence WooCommerce Email Designer
kadence-woocommerce-email-designer
Customize the default WooCommerce email templates design and text through the native WordPress customizer. Preview emails and send test emails.
Klaviyo
klaviyo
Klaviyo for WooCommerce
EmailKit – Email Customizer for WooCommerce & WP
emailkit
EmailKit is a powerful WordPress and WooCommerce email customizer tool, free for everyone! It allows users to customize and design templates that show …
Split Email Providers Developer Profile
3 plugins · 30 total installs
How We Detect Split Email Providers
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/split-email-providers/dist/assets/css/style.css/wp-content/plugins/split-email-providers/dist/assets/js/app.js/wp-content/plugins/split-email-providers/dist/assets/css/settings-page.css/wp-content/plugins/split-email-providers/dist/assets/js/app.jssplit-email-providers/dist/assets/css/style.css?ver=split-email-providers/dist/assets/js/app.js?ver=split-email-providers/dist/assets/css/settings-page.css?ver=HTML / DOM Fingerprints
fand-settings-pagedata-fand-fournisseur-iddata-fand-fournisseur-namewindow.fand_app_settingswindow.fand_countries_listwindow.fand_app_settings_pro/wp-json/fand/v1/fournisseurs/wp-json/fand/v1/fournisseurs/(?P<id>[\d]+)