
f(x) Email Log Security & Risk Analysis
wordpress.org/plugins/fx-email-logSimple plugin to log all email sent via WordPress.
Is f(x) Email Log Safe to Use in 2026?
Generally Safe
Score 85/100f(x) Email Log has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The fx-email-log v1.0.3 plugin exhibits a generally good security posture with a limited attack surface, consisting of a single AJAX handler. Notably, the analysis indicates zero unprotected entry points, suggesting a solid understanding of authentication and authorization best practices regarding its primary interaction points. The plugin also demonstrates a reasonable approach to output escaping and uses nonces and capability checks, which are crucial for preventing common web vulnerabilities. However, the static analysis revealed two flows with unsanitized paths during taint analysis, with one classified as high severity. This is a significant concern as it indicates a potential pathway for malicious data to be processed without proper validation, which could lead to unexpected behavior or security exploits. Additionally, while the plugin has no recorded vulnerability history, this absence of past issues should be viewed with caution. It might reflect a lack of discovery or audit rather than inherent invulnerability. Therefore, while the plugin adheres to many security fundamentals, the presence of high-severity taint flows warrants careful attention and remediation.
Key Concerns
- High severity taint flow found
- Flows with unsanitized paths found
- SQL queries not fully prepared
- Output escaping not fully implemented
f(x) Email Log Security Vulnerabilities
f(x) Email Log Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
f(x) Email Log Attack Surface
AJAX Handlers 1
WordPress Hooks 10
Maintenance & Trust
f(x) Email Log Maintenance & Trust
Maintenance Signals
Community Trust
f(x) Email Log Alternatives
Ajax Contact Form
fws-ajax-contact-form
An easy to use contact form plugin with multiple inbuilt features to prevent contact form spam.
MultiMailer
scand-multi-mailer
Send data from one contact form to multiple email addresses or save data into log file.
WP Mail SMTP by WPForms – The Most Popular SMTP and Email Log Plugin
wp-mail-smtp
Make email delivery easy for WordPress. Connect with SMTP, Gmail, Outlook, SendGrid, Mailgun, SES, Zoho, + more. Rated #1 WordPress SMTP Email plugin.
Easy WP SMTP – WordPress SMTP and Email Logs: Gmail, Office 365, Outlook, Custom SMTP, and more
easy-wp-smtp
Make SMTP email sending and delivery easy. Configure Gmail, Outlook, Brevo, SendGrid, Mailgun, SendLayer or connect to any SMTP server.
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App
post-smtp
Improve WordPress email deliverability. Connect Gmail SMTP, Microsoft 365, Brevo, SendGrid, Mailgun, Zoho, Amazon SES, etc. #1 WordPress SMTP Plugin.
f(x) Email Log Developer Profile
12 plugins · 2K total installs
How We Detect f(x) Email Log
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/fx-email-log/assets/settings.css/wp-content/plugins/fx-email-log/assets/settings.js/wp-content/plugins/fx-email-log/assets/reset.css/wp-content/plugins/fx-email-log/assets/settings.jsfx-email-log/assets/settings.css?ver=fx-email-log/assets/settings.js?ver=HTML / DOM Fingerprints
fx-email-log-settings-wrapfx-email-log-modal-overlayfx-email-log-modalfx-email-log-modal-containerfx-email-log-modal-titlefx-email-log-modal-closedata-noncefx_email_log_settings_paramsFX_EMAIL_LOG_URI