
FS Email Tools Security & Risk Analysis
wordpress.org/plugins/email-toolsCollection of tools to interact with emails in WordPress including email rerouting, outgoing email logging to the database, and automatic BCC to speci …
Is FS Email Tools Safe to Use in 2026?
Generally Safe
Score 85/100FS Email Tools has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "email-tools" v1.2.4 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices in output escaping and SQL query preparedness, with 98% of outputs properly escaped and 82% of SQL queries using prepared statements. The absence of known CVEs and a clean vulnerability history are also strong indicators of a well-maintained and secure plugin. However, significant concerns arise from the static analysis. The presence of an unprotected AJAX handler presents a direct attack vector. Furthermore, two high-severity taint flows with unsanitized paths indicate potential risks of data injection or manipulation, especially when combined with the use of the `unserialize` function, which is known for its potential security pitfalls if used with untrusted data. The limited capability checks also suggest that access control might be insufficient for certain functionalities.
Key Concerns
- Unprotected AJAX handler
- High severity taint flows with unsanitized paths
- Dangerous function unserialize used
- Limited capability checks found
FS Email Tools Security Vulnerabilities
FS Email Tools Release Timeline
FS Email Tools Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
FS Email Tools Attack Surface
AJAX Handlers 1
WordPress Hooks 10
Maintenance & Trust
FS Email Tools Maintenance & Trust
Maintenance Signals
Community Trust
FS Email Tools Alternatives
WP Reroute Email
wp-reroute-email
This plugin reroutes all outgoing emails from a WordPress site (sent using the wp_mail() function) to a predefined configurable email address.
Change Administration Email
change-administration-email
Change the Site's Administration Email Address on the General Settings page without the confirmation email.
WP Mail SMTP by WPForms – The Most Popular SMTP and Email Log Plugin
wp-mail-smtp
Make email delivery easy for WordPress. Connect with SMTP, Gmail, Outlook, SendGrid, Mailgun, SES, Zoho, + more. Rated #1 WordPress SMTP Email plugin.
Hostinger Reach – AI-Powered Email Marketing for WordPress
hostinger-reach
Launch and grow your email marketing effortlessly with Hostinger Reach. Collect contacts, sync subscribers, and send emails – all in one, AI powered.
MC4WP: Mailchimp for WordPress
mailchimp-for-wp
The #1 Mailchimp plugin for WordPress. Allows you to add a multitude of newsletter sign-up methods to your site.
FS Email Tools Developer Profile
4 plugins · 110 total installs
How We Detect FS Email Tools
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/email-tools/assets/dist/js/admin.js/wp-content/plugins/email-tools/assets/dist/css/admin.css/wp-content/plugins/email-tools/assets/dist/js/admin.jsemail-tools/assets/dist/js/admin.js?ver=email-tools/assets/dist/css/admin.css?ver=HTML / DOM Fingerprints
js-view-email-logjs-delete-email-logdata-id