
GD Mail Queue Security & Risk Analysis
wordpress.org/plugins/gd-mail-queueIntercept emails sent with wp_mail() into flexible mail queue for sending emails, convert plain text emails to HTML, email log, and more.
Is GD Mail Queue Safe to Use in 2026?
Generally Safe
Score 90/100GD Mail Queue has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The gd-mail-queue plugin v4.4 presents a mixed security posture. While it demonstrates good practices like a high percentage of prepared SQL statements and a significant number of nonce and capability checks, several areas raise concerns. The presence of two AJAX handlers without authentication checks, coupled with five unsanitized paths identified in taint analysis, including three critical severity flows, indicates potential for unauthorized actions and data manipulation. The plugin's vulnerability history, though currently showing no unpatched issues, has previously included high and medium severity vulnerabilities, primarily Cross-site Scripting. This pattern suggests that the plugin, while actively maintained, may have had past coding weaknesses that could re-emerge if not rigorously addressed. Overall, the plugin exhibits some strong security foundations but requires vigilance due to its exposed entry points and past susceptibility to input validation flaws.
Key Concerns
- Unprotected AJAX handlers
- Taint flows with unsanitized paths (Critical)
- Taint flows with unsanitized paths (High)
- Known past high severity vulnerability
- Known past medium severity vulnerability
- Bundled library (PHPMailer)
- Output escaping not fully implemented
GD Mail Queue Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
GD Mail Queue <= 4.3 - Reflected Cross-Site Scripting
GD Mail Queue <= 3.9.3 - Unauthenticated Stored Cross-Site Scripting via Email
GD Mail Queue Release Timeline
GD Mail Queue Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
GD Mail Queue Attack Surface
AJAX Handlers 4
WordPress Hooks 103
Scheduled Events 2
Maintenance & Trust
GD Mail Queue Maintenance & Trust
Maintenance Signals
Community Trust
GD Mail Queue Alternatives
Unified – Email Log, Email Queue, Page cache and more
unified
Unified is a plugin that combines functionalities that most sites use, all in one plugin, with a sharp focus on high performance and low memory usage.
WP Mail SMTP by WPForms – The Most Popular SMTP and Email Log Plugin
wp-mail-smtp
Make email delivery easy for WordPress. Connect with SMTP, Gmail, Outlook, SendGrid, Mailgun, SES, Zoho, + more. Rated #1 WordPress SMTP Email plugin.
Easy WP SMTP – WordPress SMTP and Email Logs: Gmail, Office 365, Outlook, Custom SMTP, and more
easy-wp-smtp
Make SMTP email sending and delivery easy. Configure Gmail, Outlook, Brevo, SendGrid, Mailgun, SendLayer or connect to any SMTP server.
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App
post-smtp
Improve WordPress email deliverability. Connect Gmail SMTP, Microsoft 365, Brevo, SendGrid, Mailgun, Zoho, Amazon SES, etc. #1 WordPress SMTP Plugin.
WP Mail Logging
wp-mail-logging
Log, view, and resend all emails sent from your WordPress site. Great for resolving email sending issues or keeping a copy for auditing.
GD Mail Queue Developer Profile
17 plugins · 12K total installs
How We Detect GD Mail Queue
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gd-mail-queue/d4plib/core/admin/css/style.css/wp-content/plugins/gd-mail-queue/d4plib/core/admin/js/script.js/wp-content/plugins/gd-mail-queue/core/admin/css/style.css/wp-content/plugins/gd-mail-queue/core/admin/js/script.js/wp-content/plugins/gd-mail-queue/core/grids/css/log.css/wp-content/plugins/gd-mail-queue/core/grids/js/log.js/wp-content/plugins/gd-mail-queue/d4plib/core/admin/js/script.js/wp-content/plugins/gd-mail-queue/core/admin/js/script.js/wp-content/plugins/gd-mail-queue/core/grids/js/log.jsgd-mail-queue/d4plib/core/admin/css/style.css?ver=gd-mail-queue/d4plib/core/admin/js/script.js?ver=gd-mail-queue/core/admin/css/style.css?ver=gd-mail-queue/core/admin/js/script.js?ver=gd-mail-queue/core/grids/css/log.css?ver=gd-mail-queue/core/grids/js/log.js?ver=HTML / DOM Fingerprints
gdmaq_admingdmaq-notice-info<!-- D4PLIB --><!-- Copyright -->data-gdmaq-core$_gdmaq_core$_gdmaq_settingsgdmaqgdmaq_settings