
atec SMTP Mail Security & Risk Analysis
wordpress.org/plugins/atec-smtp-mailUse SMTP mail instead of standard WP mail. The only plugin supporting DKIM signature.
Is atec SMTP Mail Safe to Use in 2026?
Generally Safe
Score 100/100atec SMTP Mail has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'atec-smtp-mail' plugin version 1.1.25 exhibits a generally good security posture with several positive indicators. The vast majority of output is properly escaped, and the plugin doesn't appear to bundle outdated libraries or make excessive external HTTP requests. The absence of known CVEs and past vulnerabilities is also a strong positive sign, suggesting a history of secure development. However, a significant concern arises from the static analysis, which reveals one AJAX handler that lacks authentication checks. This represents a direct entry point into the plugin's functionality that could be exploited by unauthenticated users, potentially leading to unintended actions or information disclosure if the handler's functionality is sensitive. The relatively small number of total entry points makes this single unprotected handler a proportionally larger risk.
While the taint analysis shows no critical or high-severity flows, the presence of an unprotected AJAX handler warrants careful attention. The code signals indicate a moderate use of prepared statements for SQL queries, but the existence of raw SQL without proper preparation could still pose a risk, especially if the unprotected AJAX handler interacts with the database in any way. The plugin also uses nonce and capability checks for some of its operations, which is good practice, but their absence on the identified AJAX handler is a clear weakness. In conclusion, the plugin has strengths in its output escaping and lack of vulnerability history, but the unprotected AJAX handler presents a notable risk that needs to be addressed to improve the overall security.
Key Concerns
- Unprotected AJAX handler
- SQL queries: 50% not using prepared statements
atec SMTP Mail Security Vulnerabilities
atec SMTP Mail Code Analysis
SQL Query Safety
Output Escaping
atec SMTP Mail Attack Surface
AJAX Handlers 1
WordPress Hooks 13
Maintenance & Trust
atec SMTP Mail Maintenance & Trust
Maintenance Signals
Community Trust
atec SMTP Mail Alternatives
No alternatives data available yet.
atec SMTP Mail Developer Profile
16 plugins · 3K total installs
How We Detect atec SMTP Mail
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/atec-smtp-mail/includes/ATEC/load.js/wp-content/plugins/atec-smtp-mail/includes/ATEC/admin.js/wp-content/plugins/atec-smtp-mail/includes/ATEC/svg.js/wp-content/plugins/atec-smtp-mail/includes/ATEC/load.js/wp-content/plugins/atec-smtp-mail/includes/ATEC/admin.js/wp-content/plugins/atec-smtp-mail/includes/ATEC/svg.jsatec-smtp-mail/includes/ATEC/load.js?ver=atec-smtp-mail/includes/ATEC/admin.js?ver=atec-smtp-mail/includes/ATEC/svg.js?ver=HTML / DOM Fingerprints
data-wp-hooksATEC_INITATEC_LOADER