
Mail Komplet Security & Risk Analysis
wordpress.org/plugins/mail-kompletThis plugin will connect your WooCommerce shop to your account on Mail Komplet.
Is Mail Komplet Safe to Use in 2026?
Generally Safe
Score 85/100Mail Komplet has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'mail-komplet' v1.1.2 exhibits a mixed security posture. On one hand, it demonstrates good practices by avoiding dangerous functions, utilizing prepared statements for all SQL queries, and having no recorded vulnerability history. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits its potential attack surface. However, there are notable concerns. The low percentage of properly escaped output (11%) suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data might be rendered directly in the browser without sufficient sanitization. Furthermore, the taint analysis revealed one flow with unsanitized paths, indicating a potential for path traversal or file inclusion vulnerabilities, despite the static analysis reporting no file operations. The single external HTTP request, while not inherently risky, should be monitored for potential vulnerabilities in the remote endpoint.
While the plugin has no known CVEs and no history of vulnerabilities, this does not guarantee its current safety. The identified issues in output escaping and taint analysis are critical and could lead to severe security breaches if exploited. The lack of capability checks and nonce checks, especially in conjunction with potential unescaped outputs and unsanitized paths, further exacerbates these risks. The plugin's strengths lie in its minimal attack surface and secure database interactions, but these are overshadowed by the significant risks of unescaped output and the potential for path manipulation.
Key Concerns
- Low percentage of properly escaped output
- Flows with unsanitized paths
- No nonce checks
- No capability checks
Mail Komplet Security Vulnerabilities
Mail Komplet Code Analysis
Output Escaping
Data Flow Analysis
Mail Komplet Attack Surface
WordPress Hooks 10
Maintenance & Trust
Mail Komplet Maintenance & Trust
Maintenance Signals
Community Trust
Mail Komplet Alternatives
Klarna for WooCommerce
klarna-payments-for-woocommerce
Grow your business for increased sales and enhanced shopping experiences at no extra costs.
Conversion Tracking for WooCommerce
woocommerce-conversion-tracking
Adds various conversion tracking codes to cart, checkout, registration success and product page on WooCommerce
Kustom Checkout for WooCommerce
klarna-checkout-for-woocommerce
The leading checkout in the Nordics, built for higher conversion and returning shoppers. Easy to integrate, supports Klarna and all popular payment me …
Japanized for WooCommerce
woocommerce-for-japan
Essential Japanese localization toolkit for WooCommerce - adds address formats, payment methods, delivery scheduling, and legal compliance.
Breadcrumbs for WooCommerce
woocommerce-breadcrumbs
A simple plugin to style the WooCommerce Breadcrumbs or disable them altogether
Mail Komplet Developer Profile
1 plugin · 10 total installs
How We Detect Mail Komplet
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mail-komplet/css/mail-komplet-admin.css/wp-content/plugins/mail-komplet/js/mail-komplet-admin.js/wp-content/plugins/mail-komplet/js/mail-komplet-admin.jsmail-komplet-admin.css?ver=mail-komplet-admin.js?ver=HTML / DOM Fingerprints
<!-- Begin Mail Komplet Settings --><!-- End Mail Komplet Settings -->data-mk-typedata-mk-iddata-mk-titledata-mk-url<div class="mk-widget-container" data-mk-type="form" data-mk-id="" data-mk-title="" data-mk-url=""></div>