
YeeMail — Email Template Builder & Customizer Security & Risk Analysis
wordpress.org/plugins/yeemailMake an impression with your customers and represent your brand well by customizing the design and content of your email
Is YeeMail — Email Template Builder & Customizer Safe to Use in 2026?
Generally Safe
Score 99/100YeeMail — Email Template Builder & Customizer has a strong security track record. Known vulnerabilities have been patched promptly.
The "yeemail" plugin version 2.1.5 presents a mixed security posture. On the positive side, it demonstrates good practices with a high percentage of properly escaped outputs and a solid number of capability checks. The absence of unpatched CVEs and the presence of nonce checks on all identified AJAX handlers are also favorable indicators. However, several concerns warrant attention. The static analysis reveals a notable attack surface with six AJAX handlers, one of which lacks proper authentication checks, representing a direct entry point for potential attacks. The use of the `unserialize` function is a significant risk, as it can lead to arbitrary object injection vulnerabilities if not handled with extreme caution and validation. While the taint analysis did not reveal critical or high-severity issues in this version, the presence of a flow with unsanitized paths is concerning. The vulnerability history indicates a past medium-severity Cross-Site Scripting (XSS) vulnerability, suggesting a potential recurring pattern of input sanitization weaknesses. This, combined with the identified unprotected AJAX handler and the dangerous `unserialize` function, elevates the overall risk profile.
Key Concerns
- Unprotected AJAX handler
- Use of dangerous function (unserialize)
- Flow with unsanitized paths
- Past medium vulnerability (XSS)
YeeMail — Email Template Builder & Customizer Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Email Templates Customizer for WordPress – Drag And Drop Email Templates Builder – YeeMail <= 2.1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
YeeMail — Email Template Builder & Customizer Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
YeeMail — Email Template Builder & Customizer Attack Surface
AJAX Handlers 6
WordPress Hooks 93
Maintenance & Trust
YeeMail — Email Template Builder & Customizer Maintenance & Trust
Maintenance Signals
Community Trust
YeeMail — Email Template Builder & Customizer Alternatives
Email customizer and designer for woocommerce
email-customizer-and-designer-for-woocommerce
If you tired of default email templates of WooCommerce and you are looking for a way to customize WooCommerce emails. Email Customizer for WooCommerce …
EmailKit – Email Customizer for WooCommerce & WP
emailkit
EmailKit is a powerful WordPress and WooCommerce email customizer tool, free for everyone! It allows users to customize and design templates that show …
YayMail – WooCommerce Email Customizer
yaymail
Customize WooCommerce email templates with an advanced drag-and-drop email builder. Works great with 80+ WooCommerce Email Customizer Addons.
Email Templates Customizer and Designer for WordPress and WooCommerce
email-templates
Design and send custom emails with Email Templates plugin for WordPress and WooCommerce
Email Template Designer – WP HTML Mail
wp-html-mail
All in one email template designer for WooCommerce, Ninja Forms, Elementor Forms, Gravity Forms, CF7, Support Plus, EDD, ...
YeeMail — Email Template Builder & Customizer Developer Profile
55 plugins · 26K total installs
How We Detect YeeMail — Email Template Builder & Customizer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/yeemail/frontend/css/yeemail-admin.css/wp-content/plugins/yeemail/frontend/css/yeemail-frontend.css/wp-content/plugins/yeemail/frontend/css/yeemail-main.css/wp-content/plugins/yeemail/frontend/js/yeemail-main.js/wp-content/plugins/yeemail/frontend/js/yeemail-script.js/wp-content/plugins/yeemail/backend/css/css/font-awesome.css/wp-content/plugins/yeemail/backend/css/yeemail-customizer.css/wp-content/plugins/yeemail/backend/js/yeemail-customizer.js+2 more/wp-content/plugins/yeemail/frontend/js/yeemail-main.js/wp-content/plugins/yeemail/frontend/js/yeemail-script.js/wp-content/plugins/yeemail/libs/js/jquery.min.js/wp-content/plugins/yeemail/backend/js/yeemail-customizer.js/wp-content/plugins/yeemail/backend/js/yeemail-editor.jsyeemail/style.css?ver=yeemail/script.js?ver=HTML / DOM Fingerprints
yeemail-message-notice-contentyeemail-message-notice-content-inneryeemail-editor-containeryeemail-main-wrapperyeemail-customizer-controlsyeemail-preview-area<!-- Start YeeMail template --><!-- End YeeMail template --><!-- YeeMail Pro Notification -->data-yeemail-editordata-yeemail-idyeemail_dataYeeMailyeemail_editor_datayeemail_customizer_data