
Mail Queues by PBCI Security & Risk Analysis
wordpress.org/plugins/mail-queuesQueue, Throttle, Send SMTP email through multiple providers. Automatic re-send when non-delivery received.
Is Mail Queues by PBCI Safe to Use in 2026?
Generally Safe
Score 85/100Mail Queues by PBCI has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "mail-queues" v1.6 plugin exhibits a generally good security posture with no known CVEs or critical taint flows. The absence of external HTTP requests and the use of prepared statements for all SQL queries are significant strengths. The plugin also demonstrates an effort towards security by including nonce checks and some output escaping.
However, several concerns warrant attention. The presence of two instances of the `unserialize` function, without clear sanitization controls identified in the static analysis, presents a significant risk. If the data being unserialized originates from an untrusted source, this could lead to remote code execution vulnerabilities. Additionally, the low percentage of properly escaped output (56%) indicates a potential for cross-site scripting (XSS) vulnerabilities, especially given that the plugin has several file operations which could interact with user-supplied data.
The plugin's vulnerability history being clean is a positive indicator, suggesting a history of secure development. However, this does not negate the risks identified in the current code. The overall assessment is that while the plugin has strong foundations, the identified risks associated with `unserialize` and insufficient output escaping require immediate remediation.
Key Concerns
- Dangerous function: unserialize used
- Low percentage of properly escaped output
Mail Queues by PBCI Security Vulnerabilities
Mail Queues by PBCI Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Mail Queues by PBCI Attack Surface
WordPress Hooks 3
Maintenance & Trust
Mail Queues by PBCI Maintenance & Trust
Maintenance Signals
Community Trust
Mail Queues by PBCI Alternatives
Akismet Anti-spam: Spam Protection
akismet
The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam solution for WordPress and WooCommerce.
WP Mail SMTP by WPForms – The Most Popular SMTP and Email Log Plugin
wp-mail-smtp
Make email delivery easy for WordPress. Connect with SMTP, Gmail, Outlook, SendGrid, Mailgun, SES, Zoho, + more. Rated #1 WordPress SMTP Email plugin.
Disable Comments – Remove Comments & Stop Spam [Multi-Site Support]
disable-comments
Allows administrators to globally disable comments on their site. Comments can be disabled according to post type. Multisite friendly.
Antispam Bee
antispam-bee
Sophisticated antispam plugin for effective daily comment and trackback spam-fighting. Built with data protection and privacy in mind.
Sucuri Security – Auditing, Malware Scanner and Security Hardening
sucuri-scanner
The Sucuri WordPress Security plugin is a security toolset for security integrity monitoring, malware detection and security hardening.
Mail Queues by PBCI Developer Profile
4 plugins · 1K total installs
How We Detect Mail Queues by PBCI
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mail-queues/js/mail-queues-admin.js/wp-content/plugins/mail-queues/css/mail-queues-admin.css/wp-content/plugins/mail-queues/js/mail-queues-admin.jsmail-queues/css/mail-queues-admin.css?ver=mail-queues/js/mail-queues-admin.js?ver=HTML / DOM Fingerprints
mail-queues-admin-wrappermail-queues-message-status-pendingmail-queues-message-status-sentmail-queues-message-status-errormail-queues-message-status-failed<!-- begin mail-queues settings --><!-- end mail-queues settings --><!-- mail-queues: Shortcode content goes here -->data-mail-queue-iddata-mail-message-idmailQueuesAdmin[mail_queues_list][mail_queues_stats]