
PocketGecko Email Security & Risk Analysis
wordpress.org/plugins/pocketgecko-emailMakes it easy to configure and send emails using POST/AJAX.
Is PocketGecko Email Safe to Use in 2026?
Generally Safe
Score 85/100PocketGecko Email has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The pocketgecko-email plugin v1.0.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices regarding SQL queries, utilizing prepared statements exclusively, and has no known vulnerabilities or a history of them, suggesting a potentially stable and secure codebase. File operations and external HTTP requests are also absent, reducing common attack vectors. However, significant concerns arise from the static analysis. The plugin exposes two AJAX handlers without any authentication checks, creating a substantial attack surface that could be exploited by unauthenticated users. While the presence of nonce and capability checks is noted, their absence on critical AJAX entry points is a serious oversight.
The taint analysis revealed one flow with unsanitized paths, which, although not flagged as critical or high severity, still warrants attention as it could lead to unintended behavior or potential vulnerabilities if exploited. The limited output escaping (32% properly escaped) is also a weakness, increasing the risk of cross-site scripting (XSS) vulnerabilities in the plugin's output. In conclusion, while the lack of known vulnerabilities is a good sign, the unprotected AJAX endpoints and the unsanitized path flow are critical security flaws that significantly lower the plugin's overall security standing.
Key Concerns
- AJAX handlers without auth checks
- Unsanitized paths in taint flow
- Low percentage of properly escaped output
PocketGecko Email Security Vulnerabilities
PocketGecko Email Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
PocketGecko Email Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 13
Maintenance & Trust
PocketGecko Email Maintenance & Trust
Maintenance Signals
Community Trust
PocketGecko Email Alternatives
ActiveCampaign Postmark for WordPress
postmark-approved-wordpress-plugin
The officially-supported ActiveCampaign Postmark plugin for Wordpress.
G7 SMTP Mail
g7-smtp-mail
Allows clients to configure SMTP settings for outgoing emails, including a test email functionality with debug logs.
Oderland SMTP & Postal Mailer
oderland-smtp-postal-mailer
Send transactional emails from WordPress using SMTP or Postal with logging and delivery tracking.
WP Mail SMTP by WPForms – The Most Popular SMTP and Email Log Plugin
wp-mail-smtp
Make email delivery easy for WordPress. Connect with SMTP, Gmail, Outlook, SendGrid, Mailgun, SES, Zoho, + more. Rated #1 WordPress SMTP Email plugin.
Easy WP SMTP – WordPress SMTP and Email Logs: Gmail, Office 365, Outlook, Custom SMTP, and more
easy-wp-smtp
Make SMTP email sending and delivery easy. Configure Gmail, Outlook, Brevo, SendGrid, Mailgun, SendLayer or connect to any SMTP server.
PocketGecko Email Developer Profile
1 plugin · 0 total installs
How We Detect PocketGecko Email
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pocketgecko-email/public/js/pocketgecko-email-min.js/wp-content/plugins/pocketgecko-email/public/js/pocketgecko-email-min.jsHTML / DOM Fingerprints
pgem<form id="pocketgecko-email-form"