
SMTP by BestWebSoft Security & Risk Analysis
wordpress.org/plugins/bws-smtpConfigure SMTP server to receive email messages from WordPress to Gmail, Yahoo, Hotmail, and other services.
Is SMTP by BestWebSoft Safe to Use in 2026?
Generally Safe
Score 98/100SMTP by BestWebSoft has a strong security track record. Known vulnerabilities have been patched promptly.
The BWS SMTP plugin v1.2.0 exhibits a mixed security posture. On the positive side, the static analysis reveals a relatively small attack surface with no exposed REST API routes or shortcodes, and importantly, no unprotected AJAX handlers. The code also demonstrates good practices in output escaping, with 97% of outputs properly escaped, and a strong emphasis on nonce and capability checks. However, there are areas for concern. The plugin utilizes raw SQL queries in half of its instances, which presents a risk if not handled with extreme care. Additionally, the history of known vulnerabilities, including a high-severity Cross-Site Scripting (XSS) and an Unrestricted File Upload vulnerability, is a significant red flag, even though none are currently unpatched. The recurrence of these types of vulnerabilities suggests potential underlying coding weaknesses that could resurface.
Key Concerns
- 50% of SQL queries are not prepared
- Two known vulnerabilities, one high severity
SMTP by BestWebSoft Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
SMTP by BestWebSoft <= 1.1.9 - Authenticated (Administrator+) Arbitrary File Upload
SMTP by BestWebSoft <= 1.0.9 - Multiple Cross-Site Scripting
SMTP by BestWebSoft Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
SMTP by BestWebSoft Attack Surface
AJAX Handlers 2
WordPress Hooks 18
Maintenance & Trust
SMTP by BestWebSoft Maintenance & Trust
Maintenance Signals
Community Trust
SMTP by BestWebSoft Alternatives
SmartSMTP
smart-smtp
Reliable Email Delivery with SmartSMTP
MailHawk — Simple SMTP, Email Delivery, and Email Logging
mailhawk
An easier SMTP service for WordPress. Improve your WordPress email deliverability!
WP SMTP Mailer
wp-smtp-mailer
WP SMTP Mailer is a simple and flexible plugin to configure SMTP settings in WordPress. It allows you to set up SMTP credentials, test email sending, …
G7 SMTP Mail
g7-smtp-mail
Allows clients to configure SMTP settings for outgoing emails, including a test email functionality with debug logs.
Stars SMTP Mailer
stars-smtp-mailer
Every email your WordPress website sends is important — whether it’s a contact form message, password reset, order update, or newsletter.
SMTP by BestWebSoft Developer Profile
32 plugins · 17K total installs
How We Detect SMTP by BestWebSoft
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bws-smtp/css/icon.css/wp-content/plugins/bws-smtp/css/style.css/wp-content/plugins/bws-smtp/js/script.js/wp-content/plugins/bws-smtp/js/script.jsbws-smtp/css/icon.css?ver=bws-smtp/css/style.css?ver=bws-smtp/js/script.js?ver=HTML / DOM Fingerprints
bwssmtp-form-groupbwssmtp-form-controlbwssmtp-btnbwssmtp-table© Copyright 2021 BestWebSoft ( https://support.bestwebsoft.com )This program is free software; you can redistribute it and/or modifyit under the terms of the GNU General Public License, version 2, aspublished by the Free Software Foundation.+7 moredata-bwssmtp-hostdata-bwssmtp-portdata-bwssmtp-securedata-bwssmtp-authenticationdata-bwssmtp-usernamebwssmtp_optionsbwssmtp_plugin_info