NG-Mail2Telegram Security & Risk Analysis

wordpress.org/plugins/ng-mail2telegram

Create your own notification bot which will send emails to your dashboard users via telegram.

10 active installs v1.4 PHP 5.6+ WP 3.6+ Updated Feb 27, 2020
mailnotificationstelegramwp-mailwpmail
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is NG-Mail2Telegram Safe to Use in 2026?

Generally Safe

Score 85/100

NG-Mail2Telegram has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The static analysis of "ng-mail2telegram" v1.4 reveals a plugin with a seemingly small attack surface, as indicated by zero AJAX handlers, REST API routes, shortcodes, and cron events. However, this apparent simplicity masks several significant security concerns. A critical finding is that 100% of its outputs are not properly escaped, meaning any data processed by the plugin could be vulnerable to Cross-Site Scripting (XSS) attacks. Furthermore, the complete lack of nonce checks and capability checks is alarming, as it suggests that even if an attack surface existed, there would be no built-in mechanisms to verify user authorization or prevent CSRF attacks. The presence of file operations and external HTTP requests, while not inherently insecure, are points of interest given the absence of robust input validation and output sanitization. The plugin's vulnerability history is clean, with zero recorded CVEs. While this is a positive indicator, it doesn't negate the risks identified in the static analysis, which represent potential vulnerabilities that have perhaps not yet been discovered or exploited. The lack of reported vulnerabilities might be due to the plugin's limited reach or simply a lack of thorough auditing. In conclusion, while the plugin boasts no known historical vulnerabilities, the static analysis highlights substantial weaknesses in output escaping and authorization checks, creating a notable risk profile that requires immediate attention.

Key Concerns

  • Outputs not properly escaped
  • Missing nonce checks
  • Missing capability checks
  • File operations without clear sanitization context
  • External HTTP requests without clear sanitization context
Vulnerabilities
None known

NG-Mail2Telegram Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

NG-Mail2Telegram Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

NG-Mail2Telegram Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
14
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
2
Bundled Libraries
0

Output Escaping

0% escaped14 total outputs
Attack Surface

NG-Mail2Telegram Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actioninitng-mail2telegram.php:90
actionadmin_initng-mail2telegram.php:91
actionadmin_initng-mail2telegram.php:92
actioninitng-mail2telegram.php:93
actionrest_api_initng-mail2telegram.php:94
filterwp_mailng-mail2telegram.php:95
actioninitng-mail2telegram.php:96
actionadmin_menung-mail2telegram.php:97
filterplugin_action_linksng-mail2telegram.php:128
Maintenance & Trust

NG-Mail2Telegram Maintenance & Trust

Maintenance Signals

WordPress version tested5.3.21
Last updatedFeb 27, 2020
PHP min version5.6
Downloads1K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

NG-Mail2Telegram Developer Profile

nikita.global

4 plugins · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect NG-Mail2Telegram

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ng-mail2telegram/css/style.css/wp-content/plugins/ng-mail2telegram/js/script.js
Script Paths
/wp-content/plugins/ng-mail2telegram/js/script.js
Version Parameters
ng-mail2telegram/css/style.css?ver=ng-mail2telegram/js/script.js?ver=

HTML / DOM Fingerprints

REST Endpoints
/wp-json/NG-Mail2Telegram/v1/hook/
FAQ

Frequently Asked Questions about NG-Mail2Telegram