
Mailtree Log Mail Security & Risk Analysis
wordpress.org/plugins/mailtree-log-mailA solid mail logger with additional REST API support to backup your messages to an external WordPress automatically.
Is Mailtree Log Mail Safe to Use in 2026?
Generally Safe
Score 91/100Mailtree Log Mail has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The 'mailtree-log-mail' v1.0.1 plugin presents a mixed security posture. On the positive side, it demonstrates good practices in handling SQL queries and output escaping, with a high percentage of prepared statements and properly escaped outputs. The presence of nonce and capability checks in several areas is also a positive indicator. However, there are significant concerns, particularly regarding its attack surface and past vulnerability history.
The static analysis reveals a notable risk with one of the two REST API routes lacking permission callbacks, creating an unprotected entry point. The use of the 'unserialize' function, while not directly flagged by taint analysis in this specific version, is a historically dangerous function that can lead to remote code execution if not handled with extreme care, especially when processing user-controlled input. The plugin also makes external HTTP requests, which, without proper validation and sanitization of the target URL or response, could be exploited.
The plugin's vulnerability history, specifically a past high-severity 'Cross-site Scripting' vulnerability, is a significant red flag. While currently unpatched CVEs are zero, the recurring nature of such vulnerabilities suggests potential recurring weaknesses in input sanitization or output encoding. The historical context implies a need for ongoing vigilance and robust security testing. Overall, while the plugin exhibits some good coding practices, the unprotected REST API endpoint and past vulnerabilities necessitate caution.
Key Concerns
- REST API route without permission callback
- Use of dangerous function (unserialize)
- Past high severity vulnerability (XSS)
- External HTTP requests
Mailtree Log Mail Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Mailtree Log Mail <= 1.0.0 - Unauthenticated Stored Cross-Site Scripting via Email Subject
Mailtree Log Mail Release Timeline
Mailtree Log Mail Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Mailtree Log Mail Attack Surface
REST API Routes 2
WordPress Hooks 10
Maintenance & Trust
Mailtree Log Mail Maintenance & Trust
Maintenance Signals
Community Trust
Mailtree Log Mail Alternatives
WP Mail SMTP by WPForms – The Most Popular SMTP and Email Log Plugin
wp-mail-smtp
Make email delivery easy for WordPress. Connect with SMTP, Gmail, Outlook, SendGrid, Mailgun, SES, Zoho, + more. Rated #1 WordPress SMTP Email plugin.
Easy WP SMTP – WordPress SMTP and Email Logs: Gmail, Office 365, Outlook, Custom SMTP, and more
easy-wp-smtp
Make SMTP email sending and delivery easy. Configure Gmail, Outlook, Brevo, SendGrid, Mailgun, SendLayer or connect to any SMTP server.
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App
post-smtp
Improve WordPress email deliverability. Connect Gmail SMTP, Microsoft 365, Brevo, SendGrid, Mailgun, Zoho, Amazon SES, etc. #1 WordPress SMTP Plugin.
WP Mail Logging
wp-mail-logging
Log, view, and resend all emails sent from your WordPress site. Great for resolving email sending issues or keeping a copy for auditing.
Activity Log – Monitor & Record User Changes
aryo-activity-log
This top rated Activity Log plugin helps you monitor & log all changes and actions on your WordPress site, so you can remain secure and organized.
Mailtree Log Mail Developer Profile
3 plugins · 510 total installs
How We Detect Mailtree Log Mail
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mailtree-log-mail/assets/css/styles.min.css/wp-content/plugins/mailtree-log-mail/assets/js/index.min.js/wp-content/plugins/mailtree-log-mail/assets/js/index.min.jsmailtree-log-mail/assets/css/styles.min.css?v=mailtree-log-mail/assets/js/index.min.js?v=HTML / DOM Fingerprints
NOTE load all default variables for settings. NOTE later when there might be more logging types this will be important. NOTE Disable auto delete. NOTE Instantiate custom screen options.+11 moredata-bulk-action="export"data-bulk-action="resend"data-bulk-action="delete"mailtree/wp-json/mailtree/v1/logs