Lana Email Tester Security & Risk Analysis

wordpress.org/plugins/lana-email-tester

Send test email

0 active installs v1.1.0 PHP 5.3+ WP 4.0+ Updated Jun 15, 2022
emailsend-emailtest-emailtesterwp-mail
85
A · Safe
CVEs total1
Unpatched0
Last CVEJun 15, 2022
Safety Verdict

Is Lana Email Tester Safe to Use in 2026?

Generally Safe

Score 85/100

Lana Email Tester has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Jun 15, 2022Updated 3yr ago
Risk Assessment

The 'lana-email-tester' plugin, version 1.1.0, exhibits a generally positive security posture based on the static analysis. The absence of any identified attack surface points, dangerous functions, or taint flows is a strong indicator of careful coding practices. The use of prepared statements for all SQL queries and the presence of nonce and capability checks further bolster its security. However, the static analysis does reveal a concerning 50% rate of unescaped output, meaning half of the plugin's outputs are not properly sanitized, which could expose users to Cross-Site Scripting (XSS) vulnerabilities. The vulnerability history, while currently showing no unpatched CVEs, indicates a past medium-severity issue, specifically Cross-Site Request Forgery (CSRF), which suggests that while the plugin has addressed past issues, historical weaknesses should still be considered. The plugin's strengths lie in its limited attack surface and secure data handling for SQL, but the unescaped output remains a notable concern that requires immediate attention.

Key Concerns

  • 50% of output is not properly escaped
  • Past medium severity vulnerability (CSRF)
Vulnerabilities
1 published

Lana Email Tester Security Vulnerabilities

CVEs by Year

1 CVE in 2022
2022
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

WF-fe4171b9-b17e-4e6e-9ab4-4b1b125e8950-lana-email-testermedium · 5.3Cross-Site Request Forgery (CSRF)

Lana Email Tester <= 1.0.0 - Missing Authorization to Mail Relay & Cross-Site Request Forgery

Jun 15, 2022 Patched in 1.1.0 (587d)
Version History

Lana Email Tester Release Timeline

v1.1.0Current
Code Analysis
Analyzed Mar 17, 2026

Lana Email Tester Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
5 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

50% escaped10 total outputs
Attack Surface

Lana Email Tester Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionadmin_menulana-email-tester.php:55
actionwp_mail_failedlana-email-tester.php:147
filterwp_mail_fromlana-email-tester.php:151
filterwp_mail_from_namelana-email-tester.php:152
actionadmin_post_lana_email_tester_send_test_wp_maillana-email-tester.php:164
actionadmin_noticeslana-email-tester.php:225
Maintenance & Trust

Lana Email Tester Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedJun 15, 2022
PHP min version5.3
Downloads932

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Lana Email Tester Developer Profile

Lana Codes

15 plugins · 4K total installs

71
trust score
Avg Security Score
89/100
Avg Patch Time
349 days
View full developer profile
Detection Fingerprints

How We Detect Lana Email Tester

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
wrapform-tableregular-textbutton-primarynoticenotice-successis-dismissiblenotice-error
Data Attributes
name="email_to"id="email-to"name="send_email"id="send-test-email"
Shortcode Output
<h2>Lana Email Tester</h2><h2 class="title">Email Server Settings</h2><h2 class='title'>Email Header Settings</h2><h2 class="title">Email Tester Settings</h2>
FAQ

Frequently Asked Questions about Lana Email Tester