
Mail Logger for WordPress Security & Risk Analysis
wordpress.org/plugins/wb-mail-loggerSave all WordPress emails.
Is Mail Logger for WordPress Safe to Use in 2026?
Generally Safe
Score 100/100Mail Logger for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wb-mail-logger" plugin v1.1.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices in several areas, including a high percentage of properly escaped outputs (91%) and SQL queries using prepared statements (77%). The absence of file operations, external HTTP requests, and bundled libraries further reduces potential attack vectors. However, a significant concern lies in its attack surface, with two AJAX handlers present and both lacking authentication checks, creating direct entry points for attackers. While taint analysis did not reveal critical or high severity issues, the presence of one flow with an unsanitized path warrants attention, as this could potentially lead to vulnerabilities if exploited in conjunction with other factors.
The plugin has no recorded vulnerability history (CVEs), which is a positive indicator of its current stability. This lack of past issues might suggest a diligent development process or simply a lack of discovery. Despite this, the presence of unprotected AJAX handlers remains a notable weakness. The plugin's strengths lie in its careful handling of database queries and output, but the critical lack of authorization on its entry points necessitates caution. Overall, the plugin is reasonably secure in its data handling but has a critical flaw in its access control for its AJAX endpoints.
Key Concerns
- Unprotected AJAX handlers
- Flow with unsanitized path
Mail Logger for WordPress Security Vulnerabilities
Mail Logger for WordPress Release Timeline
Mail Logger for WordPress Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Mail Logger for WordPress Attack Surface
AJAX Handlers 2
WordPress Hooks 8
Maintenance & Trust
Mail Logger for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
Mail Logger for WordPress Alternatives
WP SMTP Mailer
wp-smtp-mailer
WP SMTP Mailer is a simple and flexible plugin to configure SMTP settings in WordPress. It allows you to set up SMTP credentials, test email sending, …
MultiMailer
scand-multi-mailer
Send data from one contact form to multiple email addresses or save data into log file.
Frumbik SMTP
frumbik-smtp
Send WordPress emails via SMTP or API providers (SendGrid, SES, Gmail, M365) with smart routing, failover, email logging, and queue.
Meow Mailer
meow-mailer
Reliable WordPress email through the provider of your choice, with a beautiful log, offline mode, and one click resend. Simple by design.
WP Mail SMTP by WPForms – The Most Popular SMTP and Email Log Plugin
wp-mail-smtp
Make email delivery easy for WordPress. Connect with SMTP, Gmail, Outlook, SendGrid, Mailgun, SES, Zoho, + more. Rated #1 WordPress SMTP Email plugin.
Mail Logger for WordPress Developer Profile
3 plugins · 11K total installs
How We Detect Mail Logger for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wb-mail-logger/admin/css/wb-mail-logger-admin.css/wp-content/plugins/wb-mail-logger/admin/js/wb-mail-logger-admin.js/wp-content/plugins/wb-mail-logger/admin/js/wb-mail-logger-admin.jswb-mail-logger-adminwb-mail-loggerHTML / DOM Fingerprints
wb_mlr_data_idwb_mlr_bulk_deletewb_mlr_deletewb_mlr_searchwb_mlr_bulk_actionwb_mlr_reset_buttonwb_mlr_bulk_action_submitdata-wb_mlr_delete_idwb_mlr_params