
Check-Mail-SMTP Security & Risk Analysis
wordpress.org/plugins/check-server-mail-smtpConfigure a SMTP server to send email from your WordPress site. Configure the wp_mail() function to use SMTP instead of the PHP mail() function.
Is Check-Mail-SMTP Safe to Use in 2026?
Generally Safe
Score 85/100Check-Mail-SMTP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "check-server-mail-smtp" plugin v1.1 exhibits a generally good security posture, with no publicly known vulnerabilities recorded and a promising absence of critical code signals in static analysis. The plugin demonstrates an awareness of security best practices by implementing nonce checks and capability checks. However, the static analysis reveals a significant concern regarding output escaping, with less than half of the outputs being properly sanitized. This, coupled with a taint flow identified with unsanitized paths, suggests a potential for cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled with extreme care throughout the plugin's execution. While the plugin's attack surface is currently zero, this could change with future updates. The lack of historical vulnerabilities is a positive sign, but the identified code signals warrant attention to prevent future issues.
Key Concerns
- Low proper output escaping percentage
- Taint flow with unsanitized paths
Check-Mail-SMTP Security Vulnerabilities
Check-Mail-SMTP Release Timeline
Check-Mail-SMTP Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Check-Mail-SMTP Attack Surface
WordPress Hooks 5
Maintenance & Trust
Check-Mail-SMTP Maintenance & Trust
Maintenance Signals
Community Trust
Check-Mail-SMTP Alternatives
SMTP Mailer
smtp-mailer
Configure a SMTP server to send email from your WordPress site. Configure the wp_mail() function to use SMTP instead of the PHP mail() function.
WPO365 | MICROSOFT 365 GRAPH MAILER
wpo365-msgraphmailer
Send WordPress emails from a M365 / Exchange Online Mailbox using Microsoft Graph, leveraging OAuth for authentication which is more secure than SMTP
WP SMTP Mailer – SMTP7
wp-mail-smtp-mailer
WP SMTP Mailer Plugin - SMTP7. Make email delivery easy from WordPress. It is easy to configure.
Configure SMTP
configure-smtp
Configure SMTP mailing in WordPress, including support for sending email via SSL/TLS (such as Gmail).
MailerSend – Official SMTP Integration
mailersend-official-smtp-integration
Improve your deliverability and avoid the spam box with MailerSend’s SMTP server. Check your analytics to improve your emails for better conversion!
Check-Mail-SMTP Developer Profile
1 plugin · 10 total installs
How We Detect Check-Mail-SMTP
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/check-server-mail-smtp/js/admin_script.js/wp-content/plugins/check-server-mail-smtp/css/admin_style.css/wp-content/plugins/check-server-mail-smtp/js/admin_script.jscheck-server-mail-smtp/css/admin_style.css?ver=check-server-mail-smtp/js/admin_script.js?ver=HTML / DOM Fingerprints
nav-tab-wrappernav-tabnav-tab-activename="CSMS_send_test_email"id="CSMS_send_test_email"name="CSMS_to_email"id="CSMS_to_email"name="CSMS_email_subject"id="CSMS_email_subject"+3 more