
Mail Queue Security & Risk Analysis
wordpress.org/plugins/mail-queueTake control of emails sent by WordPress. Queue outgoing emails and get notified instantly if your website is trying to send too many emails at once!
Is Mail Queue Safe to Use in 2026?
Generally Safe
Score 99/100Mail Queue has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "mail-queue" plugin version 1.4.6 demonstrates a generally good security posture with a very small attack surface and a high percentage of properly escaped outputs. The plugin also includes a decent number of capability checks and a nonce check, indicating an effort to implement basic security measures. Notably, there are no identified dangerous functions, external HTTP requests, or unsanitized taint flows from the static analysis, which are positive indicators. However, a significant concern is the presence of SQL queries where only 18% utilize prepared statements, leaving a substantial portion vulnerable to SQL injection if not handled meticulously elsewhere. The plugin's vulnerability history reveals one past high-severity vulnerability related to Cross-site Scripting, which was patched. While this suggests the developers address security issues, the existence of a past high-severity XSS highlights a potential weakness that, if not thoroughly remediated, could reappear. The plugin's strengths lie in its limited attack surface and good output escaping, but the reliance on non-prepared SQL statements and the historical XSS vulnerability are areas that warrant attention.
Key Concerns
- SQL queries not using prepared statements
- Past high severity vulnerability (XSS)
Mail Queue Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Mail Queue <= 1.1 - Unauthenticated Stored Cross-Site Scripting via Email Subject
Mail Queue Release Timeline
Mail Queue Code Analysis
SQL Query Safety
Output Escaping
Mail Queue Attack Surface
REST API Routes 1
WordPress Hooks 12
Scheduled Events 1
Maintenance & Trust
Mail Queue Maintenance & Trust
Maintenance Signals
Community Trust
Mail Queue Alternatives
YaySMTP and Email Logs: Amazon SES, SendGrid, Outlook, Mailgun, Brevo, Google and Any SMTP Service
yaysmtp
Send WordPress emails successfully with WP Mail SMTP via your favorite mailer
Bit SMTP – Easy SMTP Solution with Email Logs
bit-smtp
Short Description
GD Mail Queue
gd-mail-queue
Intercept emails sent with wp_mail() into flexible mail queue for sending emails, convert plain text emails to HTML, email log, and more.
WP Mail Debugger
wp-mail-debugger
WP Mail Debugger captures and displays all emails sent through wp_mail() for debugging and troubleshooting.
Email Sender Control
email-sender-control
Set custom WP sender name/email, send test emails, and search, sort, or view detailed logs to track, debug, and ensure reliable email delivery.
Mail Queue Developer Profile
2 plugins · 1K total installs
How We Detect Mail Queue
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mail-queue/mail-queue.css/wp-content/plugins/mail-queue/mail-queue.jsmail-queue/mail-queue.css?ver=mail-queue/mail-queue.js?ver=HTML / DOM Fingerprints
<!-- Mail Queue v1.4.6 --><!-- Mail Queue by WDM -->wdm_wpma_optionswdm_wpma_mailid