WP Email Delivery Security & Risk Analysis

wordpress.org/plugins/wp-email-delivery

Simple, Easy to setup API based email delivery for WordPress. No SMTP needed!

100 active installs v1.20.11.23 PHP + WP 3.7+ Updated Nov 23, 2020
manager-newsletternewsletternewsletter-signupnewsletter-widgetnewsletters
64
C · Use Caution
CVEs total1
Unpatched1
Last CVEMar 17, 2025
Safety Verdict

Is WP Email Delivery Safe to Use in 2026?

Use With Caution

Score 64/100

WP Email Delivery has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Mar 17, 2025Updated 5yr ago
Risk Assessment

The wp-email-delivery plugin, version 1.20.11.23, exhibits a generally positive security posture based on static analysis, with no identified attack surface from common entry points like AJAX handlers, REST API routes, or shortcodes. The code also demonstrates good practices by utilizing prepared statements for all SQL queries and performing nonce checks. However, the presence of unsanitized paths in the taint analysis is a notable concern, indicating a potential for vulnerabilities if these paths are user-controlled. The single file operation also warrants attention, especially when combined with the unsanitized path, as it could lead to path traversal or other file manipulation issues.

Key Concerns

  • Unsanitized path in taint analysis
  • Unpatched medium severity CVE found
  • File operation present without clear context
  • External HTTP request present without clear context
  • Capability checks missing on code
Vulnerabilities
1

WP Email Delivery Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

WF-4b0aa44f-abe3-44c0-a43a-aacdaaa378cd-wp-email-deliverymedium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

WP Email Delivery <= 1.20.11.23 - Reflected Cross-Site Scripting

Mar 17, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

WP Email Delivery Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
12 escaped
Nonce Checks
1
Capability Checks
0
File Operations
1
External Requests
1
Bundled Libraries
0

Output Escaping

86% escaped14 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
settings_page (includes\class-wp-email-delivery-settings.php:457)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

WP Email Delivery Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actioninitincludes\class-wp-email-delivery-settings.php:45
actionadmin_initincludes\class-wp-email-delivery-settings.php:48
actionadmin_menuincludes\class-wp-email-delivery-settings.php:52
filternetwork_admin_menuincludes\class-wp-email-delivery-settings.php:54
actionadmin_enqueue_scriptsincludes\class-wp-email-delivery.php:118
actionadmin_enqueue_scriptsincludes\class-wp-email-delivery.php:119
actioninitincludes\class-wp-email-delivery.php:129
Maintenance & Trust

WP Email Delivery Maintenance & Trust

Maintenance Signals

WordPress version tested5.6.17
Last updatedNov 23, 2020
PHP min version
Downloads5K

Community Trust

Rating100/100
Number of ratings2
Active installs100
Developer Profile

WP Email Delivery Developer Profile

brewlabs

4 plugins · 2K total installs

58
trust score
Avg Security Score
70/100
Avg Patch Time
1682 days
View full developer profile
Detection Fingerprints

How We Detect WP Email Delivery

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-email-delivery/assets/css/settings.css/wp-content/plugins/wp-email-delivery/assets/js/settings.js
Script Paths
/wp-content/plugins/wp-email-delivery/assets/js/settings.js
Version Parameters
wp-email-delivery/assets/css/settings.css?ver=wp-email-delivery/assets/js/settings.js?ver=

HTML / DOM Fingerprints

CSS Classes
wped_settings_page
Data Attributes
data-token="wped_"id="wped_license_key"
JS Globals
WPEDwped_is_network_activated
FAQ

Frequently Asked Questions about WP Email Delivery