
WP Test Email Security & Risk Analysis
wordpress.org/plugins/wp-test-emailWP Test Email is allows you to test if your WordPress installation is sending mail or not.
Is WP Test Email Safe to Use in 2026?
Use With Caution
Score 63/100WP Test Email has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The wp-test-email plugin, version 1.1.7, exhibits a mixed security posture. On the positive side, the static analysis reveals a commendable lack of dangerous functions, SQL injection vulnerabilities due to the exclusive use of prepared statements, and no file operations or external HTTP requests. The presence of nonce checks and a low number of total entry points (all reported as protected) are also good indicators. However, the plugin's vulnerability history is a significant concern, with three known CVEs, one of which remains unpatched and is of high severity. The common vulnerability type being Cross-site Scripting (XSS) suggests a recurring pattern of input sanitization issues in previous versions. The last recorded vulnerability being in 2026 is an anomaly and should be treated as a potential data error, but the existence of multiple past vulnerabilities, including an unpatched one, points to a need for ongoing security diligence.
Key Concerns
- Unpatched high severity CVE
- Two previously patched medium severity CVEs
- Moderate output escaping (78% proper)
- 0 capability checks on entry points
WP Test Email Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Test Email <= 1.1.7 - Reflected Cross-Site Scripting
WP Test Email <= 1.1.8 - Unauthenticated Stored Cross-Site Scripting
WP Test Email <= 1.1.7 - Reflected Cross-Site Scripting
WP Test Email Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Test Email Attack Surface
WordPress Hooks 4
Scheduled Events 1
Maintenance & Trust
WP Test Email Maintenance & Trust
Maintenance Signals
Community Trust
WP Test Email Alternatives
Automatic Email Testing for WP
automatic-email-testing-for-wp
[UPDATED!] Automatic Email Testing for WP plugin allows you to set up a system inside wordpress to test your email server every day.
ZeroBounce Email Verification & Validation
zerobounce
ZeroBounce validates emails on your WordPress site in real-time, blocking invalid and risky emails to improve deliverability and reduce bounce rates.
Mailsure
mailsure
Test email sending, SPF, DKIM & DMARC
WP SMTP Mailer
wp-smtp-mailer
WP SMTP Mailer is a simple and flexible plugin to configure SMTP settings in WordPress. It allows you to set up SMTP credentials, test email sending, …
Email Checker
real-time-email-checker
Prevent spam signups by bots and lost customers in comment, registration, and contact forms using Email Checker's Email Verification Plugin.
WP Test Email Developer Profile
13 plugins · 44K total installs
How We Detect WP Test Email
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
wrapform-tablenoticenotice-successis-dismissiblenotice-errordescriptionwidefat+2 morenoncename="mail_to"value="Test Mail"name="mail_subject"id="wp_test_email_nonce_field"