
Wb Mail Logger Security & Risk Analysis
wordpress.org/plugins/wb-mail-loggerSave all WordPress emails.
Is Wb Mail Logger Safe to Use in 2026?
Generally Safe
Score 100/100Wb Mail Logger has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wb-mail-logger" plugin v1.1.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices in several areas, including a high percentage of properly escaped outputs (91%) and SQL queries using prepared statements (77%). The absence of file operations, external HTTP requests, and bundled libraries further reduces potential attack vectors. However, a significant concern lies in its attack surface, with two AJAX handlers present and both lacking authentication checks, creating direct entry points for attackers. While taint analysis did not reveal critical or high severity issues, the presence of one flow with an unsanitized path warrants attention, as this could potentially lead to vulnerabilities if exploited in conjunction with other factors.
The plugin has no recorded vulnerability history (CVEs), which is a positive indicator of its current stability. This lack of past issues might suggest a diligent development process or simply a lack of discovery. Despite this, the presence of unprotected AJAX handlers remains a notable weakness. The plugin's strengths lie in its careful handling of database queries and output, but the critical lack of authorization on its entry points necessitates caution. Overall, the plugin is reasonably secure in its data handling but has a critical flaw in its access control for its AJAX endpoints.
Key Concerns
- Unprotected AJAX handlers
- Flow with unsanitized path
Wb Mail Logger Security Vulnerabilities
Wb Mail Logger Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Wb Mail Logger Attack Surface
AJAX Handlers 2
WordPress Hooks 8
Maintenance & Trust
Wb Mail Logger Maintenance & Trust
Maintenance Signals
Community Trust
Wb Mail Logger Alternatives
WP SMTP Mailer
wp-smtp-mailer
WP SMTP Mailer is a simple and flexible plugin to configure SMTP settings in WordPress. It allows you to set up SMTP credentials, test email sending, …
MultiMailer
scand-multi-mailer
Send data from one contact form to multiple email addresses or save data into log file.
WP Mail SMTP by WPForms – The Most Popular SMTP and Email Log Plugin
wp-mail-smtp
Make email delivery easy for WordPress. Connect with SMTP, Gmail, Outlook, SendGrid, Mailgun, SES, Zoho, + more. Rated #1 WordPress SMTP Email plugin.
Easy WP SMTP – WordPress SMTP and Email Logs: Gmail, Office 365, Outlook, Custom SMTP, and more
easy-wp-smtp
Make SMTP email sending and delivery easy. Configure Gmail, Outlook, Brevo, SendGrid, Mailgun, SendLayer or connect to any SMTP server.
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App
post-smtp
Improve WordPress email deliverability. Connect Gmail SMTP, Microsoft 365, Brevo, SendGrid, Mailgun, Zoho, Amazon SES, etc. #1 WordPress SMTP Plugin.
Wb Mail Logger Developer Profile
3 plugins · 11K total installs
How We Detect Wb Mail Logger
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wb-mail-logger/admin/css/wb-mail-logger-admin.css/wp-content/plugins/wb-mail-logger/admin/js/wb-mail-logger-admin.js/wp-content/plugins/wb-mail-logger/admin/js/wb-mail-logger-admin.jswb-mail-logger-adminwb-mail-loggerHTML / DOM Fingerprints
wb_mlr_data_idwb_mlr_bulk_deletewb_mlr_deletewb_mlr_searchwb_mlr_bulk_actionwb_mlr_reset_buttonwb_mlr_bulk_action_submitdata-wb_mlr_delete_idwb_mlr_params