
Comfort Email SMTP, Logger & Email Api Security & Risk Analysis
wordpress.org/plugins/cbxwpemailloggerThis plugin helps to send email using SMTP and Email Api. It helps to log email and displays in admin panel and more.
Is Comfort Email SMTP, Logger & Email Api Safe to Use in 2026?
Generally Safe
Score 100/100Comfort Email SMTP, Logger & Email Api has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
This plugin, cbxwpemaillogger v2.0.12, exhibits a mixed security posture. On the positive side, it has no recorded vulnerabilities (CVEs) and demonstrates good practices in SQL query preparation (86%) and output escaping (83%). It also correctly implements nonce and capability checks in a significant portion of its code.
However, a significant concern is the presence of 3 unprotected AJAX handlers, representing the entire attack surface exposed via AJAX. This lack of authentication on critical entry points is a major security risk, as it could allow unauthenticated users to trigger potentially sensitive actions. The use of `unserialize` is also a potential risk, although the taint analysis shows no unsanitized paths related to it in this instance.
Given the absence of known CVEs, the plugin's security history is clean, which is a positive indicator. However, the static analysis reveals inherent design flaws in how its AJAX endpoints are secured. The plugin's strengths lie in its data handling practices like prepared statements and output escaping, but these are undermined by the unprotected entry points.
Key Concerns
- Unprotected AJAX handlers (3)
- Dangerous function: unserialize
Comfort Email SMTP, Logger & Email Api Security Vulnerabilities
Comfort Email SMTP, Logger & Email Api Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Comfort Email SMTP, Logger & Email Api Attack Surface
AJAX Handlers 3
WordPress Hooks 29
Scheduled Events 1
Maintenance & Trust
Comfort Email SMTP, Logger & Email Api Maintenance & Trust
Maintenance Signals
Community Trust
Comfort Email SMTP, Logger & Email Api Alternatives
GoSMTP – SMTP for WordPress
gosmtp
Send emails from your WordPress site using your preferred SMTP provider like Gmail, Outlook, AWS, Zoho, SMTP.com, Brevo (formerly Sendinblue), Mailgun …
Solid Mail – SMTP email and logging made by SolidWP
wp-smtp
Email deliverability made SOLID. Connect to your chosen email provider with an intuitive set-it-and-forget-it SMTP plugin.
WP SMTP Mailer – SMTP7
wp-mail-smtp-mailer
WP SMTP Mailer Plugin - SMTP7. Make email delivery easy from WordPress. It is easy to configure.
SMTP for Amazon SES – YaySMTP
smtp-amazon-ses
Send WordPress emails through Amazon SES server using YaySMTP
SMTP for SendGrid – YaySMTP
smtp-sendgrid
Send emails from WordPress through SendGrid using SMTP by YayCommerce
Comfort Email SMTP, Logger & Email Api Developer Profile
9 plugins · 3K total installs
How We Detect Comfort Email SMTP, Logger & Email Api
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cbxwpemaillogger/assets/css/comfortsmtp-admin.css/wp-content/plugins/cbxwpemaillogger/assets/js/comfortsmtp-admin.js/wp-content/plugins/cbxwpemaillogger/assets/js/comfortsmtp-admin.jscbxwpemaillogger/assets/css/comfortsmtp-admin.css?ver=cbxwpemaillogger/assets/js/comfortsmtp-admin.js?ver=HTML / DOM Fingerprints
comfortsmtp-admin-wrapcomfortsmtp-wrap<!-- END MAIN CONTENT --><!-- MAIN CONTENT -->data-cbx-noncedata-cbx-ajax-urldata-cbx-settings-pagecomfortsmtp_admin_params/wp-json/comfortsmtp/v1/email/test