
WPFrom Email Security & Risk Analysis
wordpress.org/plugins/wpfrom-emailReplaces default WordPress sender FROM Name and Email Address. NEW admin email options.
Is WPFrom Email Safe to Use in 2026?
Generally Safe
Score 100/100WPFrom Email has a strong security track record. Known vulnerabilities have been patched promptly.
The "wpfrom-email" plugin version 1.9.7 exhibits a mixed security posture. On the positive side, the static analysis reveals no dangerous functions, no raw SQL queries, and no file operations or external HTTP requests, indicating a generally cautious approach to common vulnerability vectors. The absence of shortcodes, cron events, and a zero attack surface are also strengths, reducing potential entry points for attackers. However, the low percentage of properly escaped output (29%) is a significant concern, suggesting a high risk of Cross-Site Scripting (XSS) vulnerabilities. The lack of any capability checks or nonce checks on any entry points further exacerbates this risk, as even if the attack surface were to expand, there would be no built-in authorization mechanisms to protect it. The vulnerability history shows one previously disclosed medium-severity CVE related to XSS, which aligns with the observed output escaping issues. While this CVE is currently patched, the pattern of XSS vulnerabilities suggests a recurring problem with input sanitization and output encoding within the plugin's codebase. In conclusion, while the plugin has strong points in avoiding certain dangerous practices, the significant under-escaping of output presents a substantial risk that needs immediate attention.
Key Concerns
- Low output escaping percentage
- No capability checks
- No nonce checks
- Previous medium severity CVE (XSS)
WPFrom Email Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WPFrom Email <= 1.8.8 - Authenticated (Administrator+) Stored Cross-Site Scripting
WPFrom Email Code Analysis
Output Escaping
WPFrom Email Attack Surface
WordPress Hooks 15
Maintenance & Trust
WPFrom Email Maintenance & Trust
Maintenance Signals
Community Trust
WPFrom Email Alternatives
EmailKit – Email Customizer for WooCommerce & WP
emailkit
EmailKit is a powerful WordPress and WooCommerce email customizer tool, free for everyone! It allows users to customize and design templates that show …
Disable Email Notifications in WordPress 4.x for new user registration
disable-email-notifications-for-new-user-registration
This plugin disables the admin notifications that are sent to admin when a new user registers on the site.
YayMail – WooCommerce Email Customizer
yaymail
Customize WooCommerce email templates with an advanced drag-and-drop email builder. Works great with 80+ WooCommerce Email Customizer Addons.
Disable Emails
disable-emails
Stop WordPress from sending any emails. ANY!
Email Template Customizer for WooCommerce
email-template-customizer-for-woo
Make your WooCommerce emails become professional.
WPFrom Email Developer Profile
4 plugins · 5K total installs
How We Detect WPFrom Email
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
wpfrom_mail_sender_sectionname="wpfrom_custom_sender_id"id="wpfrom_custom_sender_id"name="wpfrom_mail_sender_email_id"id="wpfrom_mail_sender_email_id"name="wpfrom_mail_sender_name_id"id="wpfrom_mail_sender_name_id"+14 more