
Mail Control – Email Customizer, SMTP Deliverability, logging, open and click Tracking Security & Risk Analysis
wordpress.org/plugins/mail-controlDesign and customize email templates, control your SMTP email deliverability, track your emails clicks and openings, and send them as background task.
Is Mail Control – Email Customizer, SMTP Deliverability, logging, open and click Tracking Safe to Use in 2026?
Generally Safe
Score 91/100Mail Control – Email Customizer, SMTP Deliverability, logging, open and click Tracking has a strong security track record. Known vulnerabilities have been patched promptly.
The "mail-control" plugin v0.3.9 exhibits a concerning security posture primarily due to its unprotected AJAX handlers. The static analysis reveals a significant attack surface with 6 AJAX handlers, all of which lack authentication checks. This presents a high risk of unauthorized actions being performed by unauthenticated users. While the plugin demonstrates good practices in its use of prepared statements for SQL queries (85%) and proper output escaping (87%), and no critical or high severity taint flows were detected, the unprotected entry points are a major weakness. The vulnerability history indicates one past high-severity CVE related to Cross-site Scripting, which, combined with the current lack of authentication on AJAX handlers, suggests a potential for similar vulnerabilities to be exploited if not addressed. The plugin has strengths in its SQL and output handling but critically fails to secure its primary interaction points.
Key Concerns
- 6 AJAX handlers without auth checks
- 1 past high severity CVE
Mail Control – Email Customizer, SMTP Deliverability, logging, open and click Tracking Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Mail Control <= 0.2.8 - Unauthenticated Stored Cross-Site Scripting via Email Subject
Mail Control – Email Customizer, SMTP Deliverability, logging, open and click Tracking Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Mail Control – Email Customizer, SMTP Deliverability, logging, open and click Tracking Attack Surface
AJAX Handlers 6
WordPress Hooks 64
Scheduled Events 2
Maintenance & Trust
Mail Control – Email Customizer, SMTP Deliverability, logging, open and click Tracking Maintenance & Trust
Maintenance Signals
Community Trust
Mail Control – Email Customizer, SMTP Deliverability, logging, open and click Tracking Alternatives
WP Mail SMTP by WPForms – The Most Popular SMTP and Email Log Plugin
wp-mail-smtp
Make email delivery easy for WordPress. Connect with SMTP, Gmail, Outlook, SendGrid, Mailgun, SES, Zoho, + more. Rated #1 WordPress SMTP Email plugin.
Easy WP SMTP – WordPress SMTP and Email Logs: Gmail, Office 365, Outlook, Custom SMTP, and more
easy-wp-smtp
Make SMTP email sending and delivery easy. Configure Gmail, Outlook, Brevo, SendGrid, Mailgun, SendLayer or connect to any SMTP server.
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App
post-smtp
Improve WordPress email deliverability. Connect Gmail SMTP, Microsoft 365, Brevo, SendGrid, Mailgun, Zoho, Amazon SES, etc. #1 WordPress SMTP Plugin.
WP Mail Logging
wp-mail-logging
Log, view, and resend all emails sent from your WordPress site. Great for resolving email sending issues or keeping a copy for auditing.
Site Mailer – SMTP Replacement, Email API Deliverability & Email Log
site-mailer
Effortlessly manage transactional emails with Site Mailer. High deliverability, logs and statistics, and no SMTP plugins needed.
Mail Control – Email Customizer, SMTP Deliverability, logging, open and click Tracking Developer Profile
1 plugin · 60 total installs
How We Detect Mail Control – Email Customizer, SMTP Deliverability, logging, open and click Tracking
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mail-control/assets/css/backend.css/wp-content/plugins/mail-control/assets/js/backend.js/wp-content/plugins/mail-control/assets/css/frontend.css/wp-content/plugins/mail-control/assets/js/frontend.js/wp-content/plugins/mail-control/assets/css/track.css/wp-content/plugins/mail-control/assets/js/backend.js/wp-content/plugins/mail-control/assets/js/frontend.jsmail-control/assets/css/backend.css?ver=mail-control/assets/js/backend.js?ver=mail-control/assets/css/frontend.css?ver=mail-control/assets/js/frontend.js?ver=mail-control/assets/css/track.css?ver=HTML / DOM Fingerprints
mc-settings-pagemc-customizer-headermc-customizer-labelmc-customizer-fieldmc-customizer-descriptionmc-btn-savemc-toggle-switch<!-- Mail Control Admin Settings --><!-- Mail Control Customizer Content -->data-mc-fielddata-mc-typedata-mc-valuemc_backend_paramsmc_frontend_paramsMailControlBackend/wp-json/mail-control/v1/settings/wp-json/mail-control/v1/customizer/save<div class="mail-control-shortcode-example"><p>This is an example of Mail Control shortcode output.</p></div>