Lana Email Logger Security & Risk Analysis

wordpress.org/plugins/lana-email-logger

Logs all emails sent by WordPress

0 active installs v1.1.0 PHP 5.3+ WP 4.0+ Updated Jun 8, 2023
emaillog-emailloggersend-emailwp-mail
84
B · Generally Safe
CVEs total1
Unpatched0
Last CVEJun 8, 2023
Safety Verdict

Is Lana Email Logger Safe to Use in 2026?

Mostly Safe

Score 84/100

Lana Email Logger is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved.

1 known CVELast CVE: Jun 8, 2023Updated 2yr ago
Risk Assessment

The lana-email-logger plugin, at version 1.1.0, presents a generally positive security posture with several good practices evident in the static analysis. The absence of any identified taint flows and a very high percentage of properly escaped output are particularly strong indicators of secure coding. Furthermore, the plugin demonstrates a commitment to security by implementing nonce and capability checks on a good portion of its identified entry points, and importantly, has no currently unpatched vulnerabilities despite a past high-severity CVE.

However, there are a few areas that warrant caution. The presence of raw SQL queries, even if a majority use prepared statements, always carries a potential risk. The single file operation, while not explicitly flagged as dangerous, could be a vector if not handled with extreme care regarding user-supplied input. The plugin's history of a high-severity cross-site scripting vulnerability, even though patched, suggests that input validation and output encoding should be meticulously reviewed and maintained at all times. While the current version appears secure in these regards, past vulnerabilities are a reminder of potential pitfalls.

In conclusion, lana-email-logger v1.1.0 exhibits strong security fundamentals. The development team has addressed past issues and implemented robust output escaping and input validation practices. The primary remaining concerns revolve around the potential risks associated with any raw SQL queries and the single file operation, alongside the historical context of a past XSS vulnerability. Overall, the plugin is in a good state, but continuous vigilance regarding its limited identified risk areas is recommended.

Key Concerns

  • Raw SQL queries detected
  • Past high severity vulnerability
Vulnerabilities
1 published

Lana Email Logger Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

High
1

1 total CVE

CVE-2023-3166high · 7.2Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Lana Email Logger <= 1.0.2 - Unauthenticated Stored Cross-Site Scripting via Email Subject

Jun 8, 2023 Patched in 1.1.0 (229d)
Version History

Lana Email Logger Release Timeline

v1.1.0Current
v1.0.21 CVE
v1.0.11 CVE
Code Analysis
Analyzed Apr 16, 2026

Lana Email Logger Code Analysis

Dangerous Functions
0
Raw SQL Queries
5
4 prepared
Unescaped Output
1
60 escaped
Nonce Checks
2
Capability Checks
3
File Operations
1
External Requests
0
Bundled Libraries
0

SQL Query Safety

44% prepared9 total queries

Output Escaping

98% escaped61 total outputs
Attack Surface

Lana Email Logger Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 21
actionadmin_enqueue_scriptslana-email-logger.php:67
actionadmin_enqueue_scriptslana-email-logger.php:80
actionadmin_initlana-email-logger.php:134
actionadmin_initlana-email-logger.php:153
actionadmin_menulana-email-logger.php:156
actionadmin_menulana-email-logger.php:186
actionadmin_menulana-email-logger.php:216
filterparent_filelana-email-logger.php:244
filtersubmenu_filelana-email-logger.php:275
filteradmin_titlelana-email-logger.php:310
filterset-screen-optionlana-email-logger.php:381
actionlana_email_logger_email_view_postbox_1lana-email-logger.php:573
actionlana_email_logger_email_view_postbox_1lana-email-logger.php:584
actionlana_email_logger_email_view_postbox_1lana-email-logger.php:595
filterwp_maillana-email-logger.php:658
actionadded_optionlana-email-logger.php:725
actionupdated_optionlana-email-logger.php:726
actionplugins_loadedlana-email-logger.php:744
actionplugins_loadedlana-email-logger.php:762
actionlana_email_logger_cleanup_by_amountlana-email-logger.php:792
actionlana_email_logger_cleanup_by_timelana-email-logger.php:819

Scheduled Events 2

lana_email_logger_cleanup_by_amount
lana_email_logger_cleanup_by_time
Maintenance & Trust

Lana Email Logger Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedJun 8, 2023
PHP min version5.3
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Lana Email Logger Developer Profile

Lana Codes

15 plugins · 4K total installs

71
trust score
Avg Security Score
89/100
Avg Patch Time
349 days
View full developer profile
Detection Fingerprints

How We Detect Lana Email Logger

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/lana-email-logger/assets/js/lana-email-logger-settings-admin.js/wp-content/plugins/lana-email-logger/assets/css/lana-email-logger-admin.css
Script Paths
lana-email-logger-settings-admin.js
Version Parameters
lana-email-logger/assets/js/lana-email-logger-settings-admin.js?ver=lana-email-logger/assets/css/lana-email-logger-admin.css?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Lana Email Logger