Zesty Emails Custom Template Designer for WooCommerce Security & Risk Analysis

wordpress.org/plugins/zesty-emails-custom-template-designer-for-woocommerce

Design your own 100% custom email templates for WooCommerce with easy drag-and-drop tools.

0 active installs v1.0.01 PHP + WP 4.6+ Updated Jun 20, 2022
customizedesignemailtemplateswoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Zesty Emails Custom Template Designer for WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

Zesty Emails Custom Template Designer for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The plugin "zesty-emails-custom-template-designer-for-woocommerce" v1.0.01 exhibits a mixed security posture. While it demonstrates strong adherence to secure coding practices in areas like SQL query preparation (100% prepared statements) and output escaping (99% properly escaped), there are significant security concerns regarding its attack surface. A total of six AJAX handlers are exposed, and alarmingly, none of them have authentication checks, making them directly accessible to unauthenticated users. The taint analysis further highlights this weakness, revealing two high-severity flows with unsanitized paths, which could potentially lead to code injection or other severe vulnerabilities if exploited. The complete lack of vulnerability history is a positive indicator of past security diligence, but it does not mitigate the risks identified in the current static analysis. The reliance on direct access for all AJAX endpoints is a critical oversight that requires immediate attention to prevent potential exploits.

Key Concerns

  • Unprotected AJAX handlers
  • High severity taint flows with unsanitized paths
  • Missing nonce checks on AJAX
  • Missing capability checks on AJAX
Vulnerabilities
None known

Zesty Emails Custom Template Designer for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Zesty Emails Custom Template Designer for WooCommerce Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

Zesty Emails Custom Template Designer for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
10 prepared
Unescaped Output
2
162 escaped
Nonce Checks
0
Capability Checks
0
File Operations
14
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared10 total queries

Output Escaping

99% escaped164 total outputs
Data Flows · Security
5 unsanitized

Data Flow Analysis

5 flows5 with unsanitized paths
zbldr_export_json (ajax/ZBLDR_Ajax.php:49)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
6 unprotected

Zesty Emails Custom Template Designer for WooCommerce Attack Surface

Entry Points6
Unprotected6

AJAX Handlers 6

authwp_ajax_zbldr_export_jsonajax/ZBLDR_Ajax.php:47
authwp_ajax_zefw_save_optionajax/options-ajax.php:3
authwp_ajax_zefw_save_templateajax/options-ajax.php:113
authwp_ajax_zefw_load_templateajax/options-ajax.php:125
authwp_ajax_zefw_email_status_toggleajax/options-ajax.php:150
authwp_ajax_zefw_email_previewajax/options-ajax.php:179
WordPress Hooks 14
actionadmin_menuadmin/admin-side-menu.php:3
actionadmin_menuadmin/admin-side-menu.php:14
actionzefw_after_admin_menuadmin/test-emails.php:4
actionadmin_footeradmin/test-emails.php:49
actionzbldr_after_modal_bodyadmin/test-emails.php:93
actionadmin_footerajax/ZBLDR_Ajax.php:5
actionadmin_footerajax/options-ajax.php:19
actionadmin_footerfunctions/ZBLDR_Functions.php:3
actionadmin_enqueue_scriptsinit/enqueue.php:38
actionplugins_loadedinit/tables.php:62
actionadmin_headplugin.php:42
actionadmin_footerplugin.php:48
filterwc_get_templateplugin.php:61
filtersafecss_filter_attr_allow_cssplugin.php:142
Maintenance & Trust

Zesty Emails Custom Template Designer for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedJun 20, 2022
PHP min version
Downloads760

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

Zesty Emails Custom Template Designer for WooCommerce Developer Profile

Bijingus

2 plugins · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Zesty Emails Custom Template Designer for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/zesty-emails-custom-template-designer-for-woocommerce/css/spectrum.min.css/wp-content/plugins/zesty-emails-custom-template-designer-for-woocommerce/js/spectrum/spectrum.min.js/wp-content/plugins/zesty-emails-custom-template-designer-for-woocommerce/css/bootstrap.min.css/wp-content/plugins/zesty-emails-custom-template-designer-for-woocommerce/js/bootstrap.bundle.min.js/wp-content/plugins/zesty-emails-custom-template-designer-for-woocommerce/js/builder.js/wp-content/plugins/zesty-emails-custom-template-designer-for-woocommerce/js/iblize.min.js/wp-content/plugins/zesty-emails-custom-template-designer-for-woocommerce/js/admin.js/wp-content/plugins/zesty-emails-custom-template-designer-for-woocommerce/css/builder.css+3 more
Script Paths
https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.1.0/css/all.min.css../js/spectrum/spectrum.min.js../js/bootstrap.bundle.min.js../js/builder.js../js/iblize.min.js../js/admin.js+1 more
Version Parameters
zesty-emails-custom-template-designer-for-woocommerce/js/builder.js?ver=1.0

HTML / DOM Fingerprints

CSS Classes
zefw-ajax-save-option-iconzefw-ajax-save-option-icon-innerzefw-saving-text
Data Attributes
zbldr-custom-css
JS Globals
zefw_get_template_status_by_typeZBLDR_RESPONSIVE
FAQ

Frequently Asked Questions about Zesty Emails Custom Template Designer for WooCommerce