
Email Template Designer – WP HTML Mail Security & Risk Analysis
wordpress.org/plugins/wp-html-mailAll in one email template designer for WooCommerce, Ninja Forms, Elementor Forms, Gravity Forms, CF7, Support Plus, EDD, ...
Is Email Template Designer – WP HTML Mail Safe to Use in 2026?
Generally Safe
Score 89/100Email Template Designer – WP HTML Mail has a strong security track record. Known vulnerabilities have been patched promptly.
The wp-html-mail plugin, version 3.4.9, presents a mixed security posture. On one hand, the static analysis reveals a commendable absence of direct attack vectors through AJAX, REST API, shortcodes, or cron events that lack authentication. The plugin also demonstrates good practices by utilizing prepared statements for all SQL queries and implementing a significant percentage of output escaping. Nonce and capability checks are also present, suggesting a degree of security awareness in its development.
However, several concerns warrant attention. The presence of 3 unsanitized paths in the taint analysis indicates potential vulnerabilities where user-supplied data could be manipulated to impact file operations or other sensitive actions. While no critical or high severity taint flows were identified, this is still a significant area of risk. The plugin's history of 4 known CVEs, including high and medium severity issues like Missing Authorization, CSRF, and XSS, is a strong indicator of past security weaknesses. The fact that the last vulnerability was as recent as August 2023, and that there are currently no unpatched CVEs, suggests the developers are addressing issues, but the historical pattern is concerning.
In conclusion, while the plugin has improved its handling of direct entry points and database interactions, the potential for vulnerabilities stemming from unsanitized paths and its past exploit history require ongoing vigilance. The plugin demonstrates strengths in its core WordPress integration security but needs to ensure all data processing, particularly related to file operations, is robustly sanitized to prevent exploitation.
Key Concerns
- Taint flows with unsanitized paths (3)
- Historical high severity vulnerabilities (2)
- Historical medium severity vulnerabilities (2)
- Bundled library (TinyMCE)
- Only 93% of output properly escaped
Email Template Designer – WP HTML Mail Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
WP HTML Mail <= 3.4.0 - Cross-Site Request Forgery via 'send_test'
WP HTML Mail <= 3.0.9 - Missing Authorization on Rest Route
WordPress Email Template Designer < 3.0.8 - Cross-Site Request Forgery
WP HTML Mail < 2.9.1 - HTML Injection
Email Template Designer – WP HTML Mail Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Email Template Designer – WP HTML Mail Attack Surface
WordPress Hooks 36
Maintenance & Trust
Email Template Designer – WP HTML Mail Maintenance & Trust
Maintenance Signals
Community Trust
Email Template Designer – WP HTML Mail Alternatives
Email Templates Customizer and Designer for WordPress and WooCommerce
email-templates
Design and send custom emails with Email Templates plugin for WordPress and WooCommerce
Email Customizer for WooCommerce | Drag and Drop Email Templates Builder
email-customizer-for-woocommerce
WooCommerce Email Customizer plugin lets you customize transactional emails using a template builder, adding text, images & more to match your brand
Email customizer and designer for woocommerce
email-customizer-and-designer-for-woocommerce
If you tired of default email templates of WooCommerce and you are looking for a way to customize WooCommerce emails. Email Customizer for WooCommerce …
Advanced Emailing for WooCommerce
advanced-emailing-for-woocommerce
Customize your WooCommerce emails or create new one that are sent when a condition is met.
EmailKit – Email Customizer for WooCommerce & WP
emailkit
EmailKit is a powerful WordPress and WooCommerce email customizer tool, free for everyone! It allows users to customize and design templates that show …
Email Template Designer – WP HTML Mail Developer Profile
5 plugins · 20K total installs
How We Detect Email Template Designer – WP HTML Mail
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-html-mail/css/wp-html-mail.css/wp-content/plugins/wp-html-mail/css/backend.css/wp-content/plugins/wp-html-mail/css/wp-html-mail-gutenberg.css/wp-content/plugins/wp-html-mail/js/wp-html-mail-backend.js/wp-content/plugins/wp-html-mail/js/wp-html-mail-gutenberg.js/wp-content/plugins/wp-html-mail/js/wp-html-mail-frontend.js/wp-content/plugins/wp-html-mail/js/wp-html-mail-backend.js/wp-content/plugins/wp-html-mail/js/wp-html-mail-gutenberg.js/wp-content/plugins/wp-html-mail/js/wp-html-mail-frontend.jswp-html-mail/css/wp-html-mail.css?ver=wp-html-mail/css/backend.css?ver=wp-html-mail/css/wp-html-mail-gutenberg.css?ver=wp-html-mail/js/wp-html-mail-backend.js?ver=wp-html-mail/js/wp-html-mail-gutenberg.js?ver=wp-html-mail/js/wp-html-mail-frontend.js?ver=HTML / DOM Fingerprints
wp-html-mail-backenddata-wp-html-mail-editorhaetMailBackendhaetMailGutenberg