RoundCube

roundcube.net
RoundCube

Browser-based multilingual IMAP client with an application-like user interface. It provides full functionality you expect from an email client, including MIME support, address book, folder manipulation, message searching and spell checking.

Open Source

RoundCube Source Code

Author

roundcube

Description

The Roundcube Webmail suite

Homepage

https://roundcube.net

Repository

  • LicenseGPL-3.0
  • Created04 May 12
  • Primary languagePHP
  • Size68,316 KB
  • Stars7,152
  • Forks1,779
  • Watchers7,152

Language Usage

Language Usage

Project Health

  • Last commit5 days ago
  • Open issues492
  • Latest releasev1.0-rc

Recent Commits

  • Aleksander Machniak(02 Sept 26)

    Small code de-duplication

  • Aleksei Shpakovskii(02 Sept 26)

    Wrap html2text-converted text in plain message-part, not html (#10316) When user has "prefer_html" option, we display output of html2text (can be noticed by presense of [1], [2] links), which should be rendered as plain text (monospaced font and with dark background if dark mode is enabled) Co-authored-by: Alexey Shpakovsky <[email protected]>

  • Dmitry(02 Sept 26)

    Drop two php-cs-fixer rules that a later duplicate key already overrides (#10318) * Drop two php-cs-fixer rules that a later duplicate key already overrides * Point phpstan at the php-cs-fixer configs, dot files are skipped when scanning * Scan the custom fixer instead of analysing it --------- Co-authored-by: Dmitry Rantovov <[email protected]>

  • Aleksander Machniak(25 Aug 26)

    Tests: MessageMock

  • Sai Asish Y(23 Aug 26)

    Password: Fix undefined array key warning when _curpasswd is not posted (#10309) Signed-off-by: Sai Asish Y <[email protected]>

  • Philip Weir(23 Aug 26)

    Add CVE ids (#10311) [skip ci]

  • Aleksander Machniak(16 Aug 26)

    Use `X-Content-Type-Options:nosniff` for attachment previews and downloads (#10308)

  • Konrad Pettersson(16 Aug 26)

    Code improvements (#10306) * Simplified boolean ternary expressions * Removed variables that are never used * Simplified conditional assignments using logical or assignments * Replaced trailing comma, always-falsy condition, unused initial value and unnecessary redeclaration

  • Konrad Pettersson(15 Aug 26)

    Remove unused variable n (#10302)

  • Philip Weir(13 Aug 26)

    move LICENSE.md back to root so GitHub recognises it (#10299) [skip ci]

  • Aleksander Machniak(12 Aug 26)

    IMAP: Improve handling of command continuation responses Unify and prevent from throwing a warning when server response does not contain an expected "+" token. This can happen if the connection gets dropped.

  • Aleksander Machniak(10 Aug 26)

    Update changelog [skip ci]

  • Aleksander Machniak(09 Aug 26)

    More phpunit.xml improvements

  • Aleksander Machniak(09 Aug 26)

    Fix phpunit.xml

  • Aleksander Machniak(09 Aug 26)

    Update phpunit config for the browser tests

  • Aleksander Machniak(09 Aug 26)

    Phpunit: Enable displaying details on deprecations

  • Aleksander Machniak(09 Aug 26)

    Simplify

  • Aleksander Machniak(09 Aug 26)

    Fix HTML/CSS sanitization bypass via SVG animate `by` attribute

  • Aleksander Machniak(09 Aug 26)

    Fix stored XSS in "Add to address book" action

  • Aleksander Machniak(09 Aug 26)

    Fix password's modoboa driver leak of an authentication token to a user-controlled host

  • Aleksander Machniak(09 Aug 26)

    Fix IMAP command injection via mail search and LITERAL+ byte-count desynchronization

  • Aleksander Machniak(09 Aug 26)

    Fix RCE via cmd_learn driver of markasjunk plugin

  • Aleksander Machniak(09 Aug 26)

    Fix arbitrary Sieve script injection via a filter rule name bypassing managesieve_disabled_actions

  • Aleksander Machniak(09 Aug 26)

    Fix LDAP filter injection via unescaped %u/%fu/%d substitution into the `search_filter`

  • Aleksander Machniak(09 Aug 26)

    Fix remote content blocking bypass via unclosed url() in a FuncIRI attribute

  • Aleksander Machniak(09 Aug 26)

    Fix SSRF filter bypass via various forms of nip.io/sslip.io hostnames evading is_local_url() check

  • Aleksander Machniak(09 Aug 26)

    Fix SSRF bypass via specific local address URLs using 100.64.0.0/10 and fe80::/10 nets

  • Aleksander Machniak(09 Aug 26)

    Add basic validation for content proxied by the css proxy

  • Aleksander Machniak(09 Aug 26)

    Fix so `REQUEST_URI` is used as a fallback if `PATH_INFO` is empty in static.php (#10181)

  • Aleksander Machniak(08 Aug 26)

    Fix CS

RoundCube Security

6.7/10

Repo Security Summary

Updated 17 Aug 26

  • Maintained10/10
  • Code-Review1/10
  • Security-Policy10/10
  • Dangerous-Workflow10/10
  • CII-Best-Practices0/10
  • Token-Permissions9/10
  • Binary-Artifacts10/10
  • License10/10
  • Fuzzing0/10
  • Pinned-Dependencies7/10
  • Branch-Protection3/10
  • Signed-Releases8/10
  • SAST0/10
  • Packaging10/10

RoundCube Website

Website

Roundcube - Free and Open Source Webmail Software

Free and open source webmail software for the masses, written in PHP

Redirects

Does not redirect

Security Checks

All 65 security checks passed

Server Details

  • IP Address172.67.153.189
  • LocationSan Francisco,California,United States of America,NA
  • ISPCloudFlare Inc.
  • ASNAS13335

Associated Countries

  • USUS
  • DEDE
  • FRFR

Safety Score

Website marked as safe

100%

Blacklist Check

roundcube.net was found on 0 blacklists

  • AntiSocial Blacklist
  • Artists Against 419
  • Badbitcoin
  • Bambenek Consulting
  • CERT Polska
  • CoinBlockerLists
  • CRDF
  • CryptoScamDB
  • EtherAddressLookup
  • EtherScamDB
  • Fake Website Buster
  • MetaMask EthPhishing
  • NABP Not Recommended Sites
  • OpenPhish
  • PetScams
  • PhishFeed
  • PhishFort
  • Phishing.Database
  • PhishStats
  • PhishTank
  • Phishunt
  • RPiList Not Serious
  • Scam.Directory
  • SecureReload Phishing List
  • Spam404
  • StopGunScams
  • Suspicious Hosting IP
  • ThreatFox
  • ThreatLog
  • TweetFeed
  • URLhaus
  • ViriBack C2 Tracker

Website Preview

Website preview

RoundCube Reviews

More Email Clients

About the Data: RoundCube

Edit RoundCube Data

You can edit RoundCube's entry in this section of awesome-privacy.yml by submitting a PR to our GitHub repo.
Note that some of the information shown above has been aggregated from external sources, a list of these can be found data documentation.

Origin Data

Modify Data

API

You can access RoundCube's data programmatically via our API. Simply make a GET request to:

https://api.awesome-privacy.xyz/v1/services/roundcube

The REST API is free, no-auth and CORS-enabled. To learn more, view the API Docs or read the API Usage Guide.

Share RoundCube

Help your friends compare Email Clients, and pick privacy-respecting software and services.
Share RoundCube and Awesome Privacy with your network!