
Emails Catch All Security & Risk Analysis
wordpress.org/plugins/emails-catch-allLog all emails send through your WordPress website, edit SMTP settings, change/add recipients, or disable outgoing emails.
Is Emails Catch All Safe to Use in 2026?
Generally Safe
Score 97/100Emails Catch All has a strong security track record. Known vulnerabilities have been patched promptly.
The "emails-catch-all" plugin v3.5.4 exhibits a mixed security posture. On the positive side, it demonstrates good practices regarding database interactions, exclusively using prepared statements for its SQL queries and showing a high percentage of properly escaped output, which mitigates common injection and cross-site scripting risks. The absence of file operations, external HTTP requests, and bundled libraries is also a strength. However, a significant concern arises from its attack surface, with two AJAX handlers identified as completely unprotected by authentication or capability checks. While the taint analysis shows no critical or high-severity flows, the lack of input validation on these AJAX endpoints is a potential gateway for unauthorized actions.
The plugin's vulnerability history, including a past high-severity "Exposure of Sensitive Information to an Unauthorized Actor" vulnerability, is a worrying pattern. While this specific vulnerability is listed as unpatched, its recency suggests that attackers may still be able to exploit it if the plugin is not updated. The absence of any recent CVEs is a positive sign, but the historical exposure of sensitive information cannot be ignored. The plugin has a single, high-severity vulnerability that was previously unpatched. This suggests a history of potential security oversights, even if current analysis shows no immediate exploitable flaws. The combination of unprotected entry points and past data exposure incidents warrants caution.
Key Concerns
- Unprotected AJAX handlers
- Past high severity vulnerability
- Lack of capability checks
Emails Catch All Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Emails Catch <= 3.5.3 - Authenticated (Subscriber+) Information Exposure to Password Reset and Privilege Escalation
Emails Catch All Code Analysis
SQL Query Safety
Output Escaping
Emails Catch All Attack Surface
AJAX Handlers 2
WordPress Hooks 23
Maintenance & Trust
Emails Catch All Maintenance & Trust
Maintenance Signals
Community Trust
Emails Catch All Alternatives
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App
post-smtp
Improve WordPress email deliverability. Connect Gmail SMTP, Microsoft 365, Brevo, SendGrid, Mailgun, Zoho, Amazon SES, etc. #1 WordPress SMTP Plugin.
SureMail – SMTP and Email Logs Plugin with Amazon SES, Postmark, and Other Providers
suremails
SureMail – SMTP and Email Logs Plugin with Amazon SES, Postmark, and Other Providers
YaySMTP and Email Logs: Amazon SES, SendGrid, Outlook, Mailgun, Brevo, Google and Any SMTP Service
yaysmtp
Send WordPress emails successfully with WP Mail SMTP via your favorite mailer
Bit SMTP – Easy SMTP Solution with Email Logs
bit-smtp
Short Description
WP Mail SMTP by WPForms – The Most Popular SMTP and Email Log Plugin
wp-mail-smtp
Make email delivery easy for WordPress. Connect with SMTP, Gmail, Outlook, SendGrid, Mailgun, SES, Zoho, + more. Rated #1 WordPress SMTP Email plugin.
Emails Catch All Developer Profile
8 plugins · 21K total installs
How We Detect Emails Catch All
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/emails-catch-all/css/admin.css/wp-content/plugins/emails-catch-all/js/admin.js/wp-content/plugins/emails-catch-all/js/frontend.jsemails-catch-all/css/admin.css?ver=emails-catch-all/js/admin.js?ver=emails-catch-all/js/frontend.js?ver=HTML / DOM Fingerprints
secas-email-logsecas-log-item<!-- Emails Catch All Settings --><!-- Emails Catch All Log -->data-secas-email-log-iddata-secas-email-log-linkdata-secas-log-idwindow.secas_admin_object