Email logging plugins retain message bodies, recipient details, headers, attachments, and delivery errors that may contain sensitive operational data. WP Mail Logging version 1.16.0 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65696. The review focused on log access, stored message rendering, attachment references, search and bulk actions, resend requests, and protection of plugin settings.
| Name of | WP Mail Logging |
| Version | 1.16.0 |
| Active installations | 300,000+ |
| Description | Records emails generated by WordPress, including message content, headers, recipients, attachments, timestamps, and sending errors, with tools for inspection and resending. |
| Security | Successfully tested for: SQL Injection (SQLi) Cross-Site Scripting (XSS) – Stored and Reflected Cross-Site Request Forgery (CSRF) Authentication Vulnerabilities Authentication Bypass Exploits Privilege Escalation Buffer Overflow Denial-of-Service (DoS) vectors Data Leakage Vulnerabilities Insecure Dependency Usage Remote Code Execution (RCE) Risks Unauthorized File Access Insufficient Injection Protection Information Disclosure via Misconfigured Endpoints |
| CleanTalk Certification | Proudly earned the “Plugin Security Certification” (PSC) from CleanTalk, indicating adherence to stringent security standards. |
| Additional Information | Use WP Mail Logging with confidence backed by the “Plugin Security Certification” (PSC). Restrict access to email logs, choose a retention period appropriate for the site, and avoid keeping sensitive message content longer than necessary. |
| Plugin Security Certification by CleanTalk | ![]() |
| Logo of the plugin |
PSC by CleantalkJoin the community of developers who prioritize security. Highlight your plugin in the WordPress catalog.
Key Features
WP Mail Logging records emails produced through the WordPress mail flow without requiring initial configuration. Administrators can search individual records, inspect HTML or text content, review headers and attachments, see sending errors, and resend selected messages. Its logs help distinguish WordPress generation problems from later delivery failures outside the site.
Security Assurance
The CleanTalk Plugin Security Certification evaluation focused on capability checks for viewing, deleting, and resending logged messages, along with nonce validation for state-changing actions. The review also covered safe display of stored subjects and message bodies, attachment handling, query inputs, bulk operations, configuration access, and limiting exposure of recipient and server information.
The plugin has been successfully tested for:
✅ Information Leakage Vulnerabilities
✅ SQL Injection Vulnerabilities
✅ Cross-Site Scripting (XSS) Attacks
✅ Cross-Site Request Forgery (CSRF) Attacks
✅ Authentication and Authentication Bypass Vulnerabilities
✅ Privilege Escalation Vulnerabilities
✅ Buffer Overflow Vulnerabilities
✅ Denial-of-Service (DoS) Vulnerabilities
✅ Data Leakage Vulnerabilities
✅ Insecure Dependencies
✅ Code Execution Vulnerabilities
✅ File Unauthorized Access Vulnerabilities
✅ Insufficient Injection Protection
Conclusion
With PSC-2026-65696, WP Mail Logging version 1.16.0 demonstrates a strong security baseline for recording and reviewing outgoing WordPress email. The certification addresses log permissions, message rendering, attachment references, administrative actions, and resend controls. Site owners should grant log access sparingly, define a practical retention policy, and remember that a successful log entry does not confirm delivery to the recipient inbox.
Note: The date and certification information may change over time. It is advisable to verify the latest details on the plugin developer’s website.
