Authority Mailer SMTP – WordPress SMTP Plugin with Email Logs Security & Risk Analysis

wordpress.org/plugins/authority-mailer-smtp

Fix WordPress emails not sending. SMTP plugin with Email Logs for Gmail, Outlook, SendGrid, Mailgun. Easy Setup, reliable delivery.

0 active installs v1.0.3 PHP 7.4+ WP 5.0+ Updated Feb 19, 2026
gmail-smtpmailsmtpwordpress-smtpwp-mail
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Authority Mailer SMTP – WordPress SMTP Plugin with Email Logs Safe to Use in 2026?

Generally Safe

Score 100/100

Authority Mailer SMTP – WordPress SMTP Plugin with Email Logs has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The authority-mailer-smtp plugin, version 1.0.3, demonstrates a generally strong security posture with several positive indicators. Notably, 100% of its output appears to be properly escaped, and a very high percentage (94%) of its SQL queries utilize prepared statements, significantly reducing the risk of SQL injection vulnerabilities. The plugin also implements a decent number of nonce and capability checks, further enhancing its security. However, there are a few areas of concern that warrant attention. The presence of one REST API route without permission callbacks is a significant security gap, as it could potentially be exploited by unauthenticated users. While the taint analysis found no critical or high severity flows, the two flows with unsanitized paths, even if not immediately exploitable due to other checks, suggest potential areas for future development to be more robust. The lack of any recorded vulnerabilities in its history is a positive sign, suggesting a history of secure development practices.

Key Concerns

  • REST API route without permission callback
  • Flows with unsanitized paths
Vulnerabilities
None known

Authority Mailer SMTP – WordPress SMTP Plugin with Email Logs Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Authority Mailer SMTP – WordPress SMTP Plugin with Email Logs Code Analysis

Dangerous Functions
0
Raw SQL Queries
4
61 prepared
Unescaped Output
6
1812 escaped
Nonce Checks
14
Capability Checks
21
File Operations
3
External Requests
25
Bundled Libraries
0

SQL Query Safety

94% prepared65 total queries

Output Escaping

100% escaped1818 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

6 flows2 with unsanitized paths
authority_mailer_smtp_render_email_log_page (includes\admin\email-log.php:615)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Authority Mailer SMTP – WordPress SMTP Plugin with Email Logs Attack Surface

Entry Points11
Unprotected1

AJAX Handlers 9

authwp_ajax_authority_mailer_smtp_delete_email_logincludes\admin\email-log.php:177
authwp_ajax_authority_mailer_smtp_bulk_delete_email_logsincludes\admin\email-log.php:236
authwp_ajax_authority_mailer_smtp_resend_email_from_logincludes\admin\email-log.php:389
authwp_ajax_authority_mailer_check_deliverabilityincludes\ajax\tools-handler.php:54
authwp_ajax_authority_mailer_dismiss_noticeincludes\class-conflict-detector.php:143
authwp_ajax_authority_mailer_smtp_set_selected_mailerincludes\class-onboarding-wizard.php:186
authwp_ajax_authority_mailer_smtp_run_saved_testincludes\class-onboarding-wizard.php:189
authwp_ajax_authority_mailer_smtp_resend_emailincludes\class-onboarding-wizard.php:192
authwp_ajax_authority_mailer_review_actionincludes\class-review-request.php:75

REST API Routes 1

GET/wp-json/authority-mailer-smtp/google/callbackauthority-mailer-smtp.php:66

Shortcodes 1

[authority_mailer_smtp_email_logs] includes\email-logger.php:759
WordPress Hooks 32
actionrest_api_initauthority-mailer-smtp.php:43
actioninitauthority-mailer-smtp.php:281
actionadmin_enqueue_scriptsauthority-mailer-smtp.php:304
actionadmin_enqueue_scriptsauthority-mailer-smtp.php:364
actionadmin_initauthority-mailer-smtp.php:447
actionadmin_menuauthority-mailer-smtp.php:553
actionauthority_mailer_smtp_debugauthority-mailer-smtp.php:605
filteradmin_body_classincludes\admin\dashboard.php:15
actionadmin_enqueue_scriptsincludes\admin\email-log.php:129
actionadmin_enqueue_scriptsincludes\admin\free-vs-pro.php:40
actionadmin_enqueue_scriptsincludes\admin\tools.php:40
actionadmin_noticesincludes\class-conflict-detector.php:140
filterauthority_mailer_smtp_enabledincludes\class-conflict-detector.php:146
actionadmin_enqueue_scriptsincludes\class-conflict-detector.php:149
filterauthority_mailer_system_statusincludes\class-conflict-detector.php:152
actionplugins_loadedincludes\class-conflict-detector.php:887
actionauthority_mailer_smtp_email_loggedincludes\class-review-request.php:66
actionadmin_noticesincludes\class-review-request.php:69
actionadmin_footerincludes\class-review-request.php:72
actionadmin_enqueue_scriptsincludes\class-review-request.php:78
filterpre_wp_mailincludes\class-sender.php:127
actionphpmailer_initincludes\class-sender.php:128
actionphpmailer_initincludes\class-sender.php:129
actionphpmailer_initincludes\class-sender.php:130
actionphpmailer_initincludes\class-sender.php:131
filterwp_mail_fromincludes\class-sender.php:132
filterwp_mail_from_nameincludes\class-sender.php:133
actionwp_mail_succeededincludes\class-sender.php:136
actionwp_mail_failedincludes\class-sender.php:137
filteroption_authority_mailer_smtp_optionsincludes\class-sender.php:411
actioninitincludes\class-sender.php:1406
filterwp_mailincludes\providers\common.php:1244
Maintenance & Trust

Authority Mailer SMTP – WordPress SMTP Plugin with Email Logs Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 19, 2026
PHP min version7.4
Downloads258

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

Authority Mailer SMTP – WordPress SMTP Plugin with Email Logs Developer Profile

Authority Plugins

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Authority Mailer SMTP – WordPress SMTP Plugin with Email Logs

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/authority-mailer-smtp/assets/css/admin-notice.css/wp-content/plugins/authority-mailer-smtp/assets/css/admin.css/wp-content/plugins/authority-mailer-smtp/assets/js/admin.js
Script Paths
/wp-content/plugins/authority-mailer-smtp/assets/js/admin.js
Version Parameters
authority-mailer-smtp/assets/css/admin-notice.css?ver=authority-mailer-smtp/assets/css/admin.css?ver=authority-mailer-smtp/assets/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
authority-mailer-smtp-onboarding-wrap
HTML Comments
Authority Mailer SMTP CRITICAL FIX: Load Google OAuth callback handler immediately (top-level) Security Note: permission_callback uses __return_true intentionally. OAuth 2.0 specification (RFC 6749) requires callback URLs to be publicly accessible.+4 more
JS Globals
authority_mailer_smtp_vars
REST Endpoints
/wp-json/authority-mailer-smtp/google/callback
FAQ

Frequently Asked Questions about Authority Mailer SMTP – WordPress SMTP Plugin with Email Logs