
Lana Email Logger Security & Risk Analysis
wordpress.org/plugins/lana-email-loggerLogs all emails sent by WordPress
Is Lana Email Logger Safe to Use in 2026?
Mostly Safe
Score 84/100Lana Email Logger is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved.
The lana-email-logger plugin, at version 1.1.0, presents a generally positive security posture with several good practices evident in the static analysis. The absence of any identified taint flows and a very high percentage of properly escaped output are particularly strong indicators of secure coding. Furthermore, the plugin demonstrates a commitment to security by implementing nonce and capability checks on a good portion of its identified entry points, and importantly, has no currently unpatched vulnerabilities despite a past high-severity CVE.
However, there are a few areas that warrant caution. The presence of raw SQL queries, even if a majority use prepared statements, always carries a potential risk. The single file operation, while not explicitly flagged as dangerous, could be a vector if not handled with extreme care regarding user-supplied input. The plugin's history of a high-severity cross-site scripting vulnerability, even though patched, suggests that input validation and output encoding should be meticulously reviewed and maintained at all times. While the current version appears secure in these regards, past vulnerabilities are a reminder of potential pitfalls.
In conclusion, lana-email-logger v1.1.0 exhibits strong security fundamentals. The development team has addressed past issues and implemented robust output escaping and input validation practices. The primary remaining concerns revolve around the potential risks associated with any raw SQL queries and the single file operation, alongside the historical context of a past XSS vulnerability. Overall, the plugin is in a good state, but continuous vigilance regarding its limited identified risk areas is recommended.
Key Concerns
- Raw SQL queries detected
- Past high severity vulnerability
Lana Email Logger Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Lana Email Logger <= 1.0.2 - Unauthenticated Stored Cross-Site Scripting via Email Subject
Lana Email Logger Release Timeline
Lana Email Logger Code Analysis
SQL Query Safety
Output Escaping
Lana Email Logger Attack Surface
WordPress Hooks 21
Scheduled Events 2
Maintenance & Trust
Lana Email Logger Maintenance & Trust
Maintenance Signals
Community Trust
Lana Email Logger Alternatives
Email Log
email-log
Log and view all outgoing emails from WordPress. Very useful if you have to debug email related problems or have to store sent emails for auditing.
Lana Email Tester
lana-email-tester
Send test email
Virtual Mailbox
virtual-mailbox
Virtual Mailbox - log all outgoing emails, and allow to browse them.
Mail logging – WP Mail Catcher
wp-mail-catcher
Stop from ever losing your emails again! This fast, lightweight plugin (under 140kb in size!) is also useful for debugging or backing up your messages
WP Mail Log
wp-mail-log
WP Mail Log helps you to Log and view all emails from WordPress. It is useful if you have to debug email related problems or have to store sent emails …
Lana Email Logger Developer Profile
15 plugins · 4K total installs
How We Detect Lana Email Logger
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/lana-email-logger/assets/js/lana-email-logger-settings-admin.js/wp-content/plugins/lana-email-logger/assets/css/lana-email-logger-admin.csslana-email-logger-settings-admin.jslana-email-logger/assets/js/lana-email-logger-settings-admin.js?ver=lana-email-logger/assets/css/lana-email-logger-admin.css?ver=