Lana Email Tester Security & Risk Analysis

wordpress.org/plugins/lana-email-tester

Send test email

0 active installs v1.1.0 PHP 5.3+ WP 4.0+ Updated Unknown
emailsend-emailtest-emailtesterwp-mail
100
A · Safe
CVEs total1
Unpatched0
Last CVEJun 15, 2022
Safety Verdict

Is Lana Email Tester Safe to Use in 2026?

Generally Safe

Score 100/100

Lana Email Tester has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jun 15, 2022
Risk Assessment

The 'lana-email-tester' plugin, version 1.1.0, exhibits a generally positive security posture based on the static analysis. The absence of any identified attack surface points, dangerous functions, or taint flows is a strong indicator of careful coding practices. The use of prepared statements for all SQL queries and the presence of nonce and capability checks further bolster its security. However, the static analysis does reveal a concerning 50% rate of unescaped output, meaning half of the plugin's outputs are not properly sanitized, which could expose users to Cross-Site Scripting (XSS) vulnerabilities. The vulnerability history, while currently showing no unpatched CVEs, indicates a past medium-severity issue, specifically Cross-Site Request Forgery (CSRF), which suggests that while the plugin has addressed past issues, historical weaknesses should still be considered. The plugin's strengths lie in its limited attack surface and secure data handling for SQL, but the unescaped output remains a notable concern that requires immediate attention.

Key Concerns

  • 50% of output is not properly escaped
  • Past medium severity vulnerability (CSRF)
Vulnerabilities
1

Lana Email Tester Security Vulnerabilities

CVEs by Year

1 CVE in 2022
2022
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

WF-fe4171b9-b17e-4e6e-9ab4-4b1b125e8950-lana-email-testermedium · 5.3Cross-Site Request Forgery (CSRF)

Lana Email Tester <= 1.0.0 - Missing Authorization to Mail Relay & Cross-Site Request Forgery

Jun 15, 2022 Patched in 1.1.0 (587d)
Code Analysis
Analyzed Mar 17, 2026

Lana Email Tester Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
5 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

50% escaped10 total outputs
Attack Surface

Lana Email Tester Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionadmin_menulana-email-tester.php:55
actionwp_mail_failedlana-email-tester.php:147
filterwp_mail_fromlana-email-tester.php:151
filterwp_mail_from_namelana-email-tester.php:152
actionadmin_post_lana_email_tester_send_test_wp_maillana-email-tester.php:164
actionadmin_noticeslana-email-tester.php:225
Maintenance & Trust

Lana Email Tester Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedUnknown
PHP min version5.3
Downloads899

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Lana Email Tester Developer Profile

Lana Codes

13 plugins · 4K total installs

73
trust score
Avg Security Score
92/100
Avg Patch Time
400 days
View full developer profile
Detection Fingerprints

How We Detect Lana Email Tester

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
wrapform-tableregular-textbutton-primarynoticenotice-successis-dismissiblenotice-error
Data Attributes
name="email_to"id="email-to"name="send_email"id="send-test-email"
Shortcode Output
<h2>Lana Email Tester</h2><h2 class="title">Email Server Settings</h2><h2 class='title'>Email Header Settings</h2><h2 class="title">Email Tester Settings</h2>
FAQ

Frequently Asked Questions about Lana Email Tester