BuddyPress Email Template Designer – WP HTML Mail Security & Risk Analysis

wordpress.org/plugins/wp-html-mail-buddypress

Simply customize email templates for BuddyPress

200 active installs v1.0.1 PHP + WP 5.0+ Updated Oct 23, 2020
emailhtml-mailmailmessagetemplate
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is BuddyPress Email Template Designer – WP HTML Mail Safe to Use in 2026?

Generally Safe

Score 85/100

BuddyPress Email Template Designer – WP HTML Mail has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The static analysis of wp-html-mail-buddypress v1.0.1 reveals an exceptionally small attack surface, with no identified AJAX handlers, REST API routes, shortcodes, or cron events. The absence of direct entry points into the plugin significantly limits the ways an attacker could interact with it. Furthermore, the code signals indicate a positive security practice regarding database interactions, as all SQL queries utilize prepared statements, which is a strong defense against SQL injection. The plugin also shows no file operations or external HTTP requests, further reducing its potential exposure.

However, a significant concern arises from the output escaping results, where 100% of identified outputs are not properly escaped. This suggests a high likelihood of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data or plugin-generated data that is not escaped can be rendered directly in the browser, allowing for malicious script execution. The lack of nonce and capability checks, while potentially mitigated by the limited attack surface, represents a weakness if any future entry points are introduced or if existing ones are overlooked. The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive indicator. This, combined with the secure SQL practices, paints a picture of a plugin that has good internal database handling but a critical flaw in output sanitization.

Key Concerns

  • Unescaped output found
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

BuddyPress Email Template Designer – WP HTML Mail Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

BuddyPress Email Template Designer – WP HTML Mail Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Attack Surface

BuddyPress Email Template Designer – WP HTML Mail Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
filterbp_email_use_wp_mailincludes\class-haet-sender-plugin-buddypress.php:54
filterbp_email_get_content_plaintextincludes\class-haet-sender-plugin-buddypress.php:58
actionadmin_menuincludes\class-haet-sender-plugin-buddypress.php:68
filterbp_core_render_email_templateincludes\class-haet-sender-plugin-buddypress.php:74
actionadmin_noticeswp-html-mail-buddypress.php:31
actionplugins_loadedwp-html-mail-buddypress.php:41
filterhaet_mail_available_pluginswp-html-mail-buddypress.php:62
actionplugins_loadedwp-html-mail-buddypress.php:64
Maintenance & Trust

BuddyPress Email Template Designer – WP HTML Mail Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedOct 23, 2020
PHP min version
Downloads7K

Community Trust

Rating100/100
Number of ratings1
Active installs200
Developer Profile

BuddyPress Email Template Designer – WP HTML Mail Developer Profile

Hannes Etzelstorfer

5 plugins · 20K total installs

69
trust score
Avg Security Score
86/100
Avg Patch Time
845 days
View full developer profile
Detection Fingerprints

How We Detect BuddyPress Email Template Designer – WP HTML Mail

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-html-mail-buddypress/assets/css/admin.css/wp-content/plugins/wp-html-mail-buddypress/assets/js/admin.js/wp-content/plugins/wp-html-mail-buddypress/assets/css/editor.css/wp-content/plugins/wp-html-mail-buddypress/assets/js/editor.js
Script Paths
/wp-content/plugins/wp-html-mail-buddypress/assets/js/admin.js/wp-content/plugins/wp-html-mail-buddypress/assets/js/editor.js
Version Parameters
wp-html-mail-buddypress/assets/css/admin.css?ver=wp-html-mail-buddypress/assets/js/admin.js?ver=wp-html-mail-buddypress/assets/css/editor.css?ver=wp-html-mail-buddypress/assets/js/editor.js?ver=

HTML / DOM Fingerprints

CSS Classes
wp-html-mail-buddypress
FAQ

Frequently Asked Questions about BuddyPress Email Template Designer – WP HTML Mail