
WP JV Custom Email Settings Security & Risk Analysis
wordpress.org/plugins/wp-jv-custom-email-settingsNotify users about new posts published and customize your e-mail notification settings
Is WP JV Custom Email Settings Safe to Use in 2026?
Generally Safe
Score 85/100WP JV Custom Email Settings has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-jv-custom-email-settings plugin v2.6 presents a mixed security posture. On the positive side, there are no known CVEs associated with the plugin, and it has a limited attack surface with only one AJAX handler, which appears to be protected by authentication checks. Furthermore, the plugin demonstrates good practices by implementing nonce and capability checks, and it does not perform file operations or external HTTP requests, reducing potential attack vectors. However, significant concerns arise from the code analysis. The output escaping is alarmingly low at only 15%, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. The taint analysis reveals a high severity flow with unsanitized paths, suggesting a potential for path traversal or similar issues, even though it's not classified as critical. Additionally, while 56% of SQL queries use prepared statements, 44% do not, which could lead to SQL injection vulnerabilities if those queries handle user-supplied input without proper sanitization. The lack of vulnerability history is a positive indicator, but it doesn't negate the immediate risks identified in the static analysis. The plugin's strengths lie in its limited attack surface and its efforts to implement security checks, but the severe deficiency in output escaping and the high-severity taint flow are critical areas that require immediate attention.
Key Concerns
- Low percentage of properly escaped output
- High severity taint flow with unsanitized paths
- Significant portion of SQL queries not prepared
WP JV Custom Email Settings Security Vulnerabilities
WP JV Custom Email Settings Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WP JV Custom Email Settings Attack Surface
AJAX Handlers 1
WordPress Hooks 22
Maintenance & Trust
WP JV Custom Email Settings Maintenance & Trust
Maintenance Signals
Community Trust
WP JV Custom Email Settings Alternatives
MailUp for WordPress – Email and Newsletter Subscription Form
mailup-email-and-newsletter-subscription-form
Il plugin permette di inserire sul proprio sito WordPress un form per l’iscrizione degli utenti a newsletter, campagne email e SMS.
e-mailing service
e-mailing-service
Full plugin management and sending newsletter.The plugin also sending links your new articles and new pages to your subscribers.
Easy Email
easy-email
The easy way to fix WordPress emails not sending or going to spam. Setup on only takes a few minutes.
Change Administration Email
change-administration-email
Change the Site's Administration Email Address on the General Settings page without the confirmation email.
Hostinger Reach – AI-Powered Email Marketing for WordPress
hostinger-reach
Launch and grow your email marketing effortlessly with Hostinger Reach. Collect contacts, sync subscribers, and send emails – all in one, AI powered.
WP JV Custom Email Settings Developer Profile
2 plugins · 280 total installs
How We Detect WP JV Custom Email Settings
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-jv-custom-email-settings/wp-jv-custom-email-settings.min.jswp-jv-custom-email-settings.min.js?ver=HTML / DOM Fingerprints
id="wp_jv_ces_set_email_from"name="wp_jv_ces_set_email_from"id="wp_jv_ces_set_email_from_address"name="wp_jv_ces_set_email_from_address"id="wp_jv_ces_set_notification_mode"name="wp_jv_ces_set_notification_mode"+6 morewp_jv_ces_obj