
Deliverability – pass DKIM, SPF, DMARC & more Security & Risk Analysis
wordpress.org/plugins/deliverabilityCheck and improve your Email Deliverability. Pass DMARC by DKIM-signing your emails without an external SMTP. Comply with Google & Yahoo requirements!
Is Deliverability – pass DKIM, SPF, DMARC & more Safe to Use in 2026?
Generally Safe
Score 100/100Deliverability – pass DKIM, SPF, DMARC & more has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "deliverability" plugin v1.8.0 exhibits a generally good security posture with zero known CVEs and no recorded vulnerabilities. The static analysis shows a remarkably small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events, which is a significant strength. Furthermore, all SQL queries utilize prepared statements, a crucial security measure. However, the presence of dangerous functions like `proc_open` and `unserialize` raises concerns, as these can be leveraged in vulnerabilities if not handled with extreme care and proper sanitization. The limited output escaping (30%) is another area that warrants attention, as unescaped output can lead to Cross-Site Scripting (XSS) vulnerabilities.
The plugin's vulnerability history is clean, suggesting a diligent development team or perhaps limited exposure. However, the absence of vulnerabilities does not negate the risks identified in the code analysis. The use of `unserialize` is particularly concerning as it can lead to Remote Code Execution (RCE) if untrusted data is deserialized. While the taint analysis shows no current flows with unsanitized paths, the potential for exploitation exists given the presence of these dangerous functions. In conclusion, the plugin benefits from a minimal attack surface and secure database practices, but the use of dangerous functions and insufficient output escaping represent key areas for improvement to further enhance its security.
Key Concerns
- Presence of 'unserialize' function
- Presence of 'proc_open' function
- Low percentage of properly escaped output
Deliverability – pass DKIM, SPF, DMARC & more Security Vulnerabilities
Deliverability – pass DKIM, SPF, DMARC & more Code Analysis
Dangerous Functions Found
Bundled Libraries
Output Escaping
Deliverability – pass DKIM, SPF, DMARC & more Attack Surface
WordPress Hooks 9
Maintenance & Trust
Deliverability – pass DKIM, SPF, DMARC & more Maintenance & Trust
Maintenance Signals
Community Trust
Deliverability – pass DKIM, SPF, DMARC & more Alternatives
Mailsure
mailsure
Test email sending, SPF, DKIM & DMARC
Email Essentials
email-essentials
A plugin to make WordPress outgoing emails better and less likely to be marked as spam.
DMARCREPORT Domain Auth Checker
dmarcreport-domain-auth-checker
Check SPF, DMARC, BIMI, MTA-STS and TLS-RPT records for any domain. Embed email authentication checkers with a shortcode.
WP Mail Logging
wp-mail-logging
Log, view, and resend all emails sent from your WordPress site. Great for resolving email sending issues or keeping a copy for auditing.
Mail Control – Email Customizer, SMTP Deliverability, logging, open and click Tracking
mail-control
Design and customize email templates, control your SMTP email deliverability, track your emails clicks and openings, and send them as background task.
Deliverability – pass DKIM, SPF, DMARC & more Developer Profile
1 plugin · 800 total installs
How We Detect Deliverability – pass DKIM, SPF, DMARC & more
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/deliverability/assets/css/admin.css/wp-content/plugins/deliverability/assets/js/admin.js/wp-content/plugins/deliverability/assets/js/admin.jsdeliverability/assets/css/admin.css?ver=deliverability/assets/js/admin.js?ver=HTML / DOM Fingerprints
top-deliverability-admin-pagedata-td-plugin-version="1.8.0"window.topDeliverabilityAdmin