MailMoo for Mailgun Security & Risk Analysis

wordpress.org/plugins/mailmoo-for-mailgun

A simple, no bloat, no paid features email sending plugin using Mailgun API for reliable email delivery.

0 active installs v1.0.1 PHP 7.4+ WP 6.5+ Updated Feb 13, 2026
emailmailgunmailmoo
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is MailMoo for Mailgun Safe to Use in 2026?

Generally Safe

Score 100/100

MailMoo for Mailgun has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The mailmoo-for-mailgun v1.0.1 plugin demonstrates a generally strong security posture based on the provided static analysis and vulnerability history. It utilizes a good number of nonce and capability checks, and a high percentage of its SQL queries are properly prepared. The absence of direct file operations and external HTTP requests, along with no identified critical or high severity taint flows, are significant strengths. The plugin also has no recorded vulnerability history, which is a positive indicator of its past security diligence.

However, a minor concern arises from the presence of one AJAX handler. While the analysis states it has auth checks, the absolute number of AJAX handlers, even if secured, still represents an entry point that requires careful review to ensure the authentication and authorization mechanisms are robust and consistently applied.

Overall, the plugin appears to be developed with security in mind, employing many best practices. The lack of historical vulnerabilities and the positive code signals outweigh the single, seemingly secured, AJAX entry point. The use of a bundled library, Guzzle v1.1, should be monitored for potential vulnerabilities in future versions, although no immediate risk is indicated.

Key Concerns

  • One AJAX handler present
  • Bundled library Guzzle v1.1
Vulnerabilities
None known

MailMoo for Mailgun Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

MailMoo for Mailgun Code Analysis

Dangerous Functions
0
Raw SQL Queries
3
4 prepared
Unescaped Output
8
57 escaped
Nonce Checks
5
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Guzzle1.1

SQL Query Safety

57% prepared7 total queries

Output Escaping

88% escaped65 total outputs
Data Flows
All sanitized

Data Flow Analysis

4 flows
<admin-page> (includes\admin-page.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

MailMoo for Mailgun Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_mailmoo_for_mailgun_get_log_detailsmailmoo-for-mailgun.php:46
WordPress Hooks 7
actioninitmailmoo-for-mailgun.php:40
actionadmin_menumailmoo-for-mailgun.php:41
actionadmin_initmailmoo-for-mailgun.php:42
actionadmin_enqueue_scriptsmailmoo-for-mailgun.php:43
actionwp_mail_failedmailmoo-for-mailgun.php:44
filterpre_wp_mailmailmoo-for-mailgun.php:45
actionadmin_noticesmailmoo-for-mailgun.php:47
Maintenance & Trust

MailMoo for Mailgun Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 13, 2026
PHP min version7.4
Downloads260

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

MailMoo for Mailgun Developer Profile

creatorcow

3 plugins · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect MailMoo for Mailgun

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mailmoo-for-mailgun/assets/css/mailmoo-mailgun-admin.css/wp-content/plugins/mailmoo-for-mailgun/assets/js/mailmoo-mailgun-admin.js
Script Paths
/wp-content/plugins/mailmoo-for-mailgun/assets/js/mailmoo-mailgun-admin.js
Version Parameters
mailmoo-for-mailgun/assets/css/mailmoo-mailgun-admin.css?ver=mailmoo-for-mailgun/assets/js/mailmoo-mailgun-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
mailmoo-for-mailgun-log-details
Data Attributes
data-log-id
JS Globals
mailmoo_for_mailgun_ajax_object
REST Endpoints
/wp-json/mailmoo-for-mailgun/v1/get_log_details
FAQ

Frequently Asked Questions about MailMoo for Mailgun