
Test Email Redirector Security & Risk Analysis
wordpress.org/plugins/test-email-redirectorRedirects all outgoing WordPress emails to a specified test address for development and testing purposes.
Is Test Email Redirector Safe to Use in 2026?
Generally Safe
Score 100/100Test Email Redirector has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'test-email-redirector' v1.3.3 presents a seemingly strong security posture based on the provided static analysis and vulnerability history. The absence of any entry points like AJAX handlers, REST API routes, shortcodes, or cron events significantly limits its attack surface. Furthermore, the code signals indicate no dangerous functions, all SQL queries use prepared statements, and there are no file operations or external HTTP requests. The vulnerability history is also clean, with no recorded CVEs, suggesting a mature and stable codebase.
However, a key concern arises from the output escaping. With 22 total outputs, only 45% are properly escaped. This means a significant portion of the plugin's output is susceptible to Cross-Site Scripting (XSS) vulnerabilities if any user-supplied data is incorporated into these unescaped outputs. While taint analysis shows no identified unsanitized paths, the lack of proper output escaping is a concrete risk that could be exploited if an indirect path for malicious input exists or is discovered.
In conclusion, the plugin excels in limiting its attack surface and avoiding common risky practices like raw SQL or dangerous functions. The clean vulnerability history is a positive indicator. The primary weakness lies in the insufficient output escaping, which warrants attention and mitigation to prevent potential XSS attacks. This specific concern is the main area for potential risk in an otherwise well-secured plugin.
Key Concerns
- Insufficient output escaping
Test Email Redirector Security Vulnerabilities
Test Email Redirector Code Analysis
Output Escaping
Test Email Redirector Attack Surface
WordPress Hooks 5
Maintenance & Trust
Test Email Redirector Maintenance & Trust
Maintenance Signals
Community Trust
Test Email Redirector Alternatives
MailcatcherClient
mailcatcher-client
Integrate your WordPress development environment with Mailcatcher to effortlessly capture and view outgoing emails during testing.
Stop Emails
stop-emails
Stop all outgoing emails sent from WordPress.
WP Reroute Email
wp-reroute-email
This plugin reroutes all outgoing emails from a WordPress site (sent using the wp_mail() function) to a predefined configurable email address.
Admin Bar Tools
sf-adminbar-tools
Adds some small development tools to the admin bar.
Woo Email Control
woo-email-control
Get better control of your Woocommerce emails. Add product images & embed them in emails. Test emails in your browser and via email.
Test Email Redirector Developer Profile
1 plugin · 60 total installs
How We Detect Test Email Redirector
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
zbet-email-forwarder-statusname="zbet_email_forwarder_enabled"name="zbet_email_forwarder_email"name="zbet_email_forwarder_cc"name="zbet_email_forwarder_bcc"name="zbet_email_forwarder_send_original_info"