
Easy WP SMTP – WordPress SMTP and Email Logs: Gmail, Office 365, Outlook, Custom SMTP, and more Security & Risk Analysis
wordpress.org/plugins/easy-wp-smtpMake SMTP email sending and delivery easy. Configure Gmail, Outlook, Brevo, SendGrid, Mailgun, SendLayer or connect to any SMTP server.
Is Easy WP SMTP – WordPress SMTP and Email Logs: Gmail, Office 365, Outlook, Custom SMTP, and more Safe to Use in 2026?
Generally Safe
Score 91/100Easy WP SMTP – WordPress SMTP and Email Logs: Gmail, Office 365, Outlook, Custom SMTP, and more has a strong security track record. Known vulnerabilities have been patched promptly.
The easy-wp-smtp plugin version 2.13.1 presents a mixed security posture. While it demonstrates good practices in areas like output escaping (98% properly escaped) and a high percentage of SQL queries using prepared statements (62%), there are significant concerns. The presence of 3 AJAX handlers without any authentication checks exposes a direct attack surface that could be exploited by unauthenticated users. Furthermore, the plugin has a history of 8 known CVEs, including one critical and three high-severity vulnerabilities, even though none are currently unpatched. This past indicates recurring security weaknesses in areas such as password storage, path traversal, code injection, deserialization, information disclosure, missing authorization, and cross-site scripting. The single unsanitized path flow in the taint analysis, though not critical or high severity, adds to the existing concerns regarding input sanitization.
Despite the lack of currently unpatched critical or high vulnerabilities and the generally good output escaping, the unprotected AJAX endpoints and the historical pattern of severe vulnerabilities warrant caution. The plugin's attack surface, while not excessively large, has a notable unprotected component. The vulnerability history suggests a tendency for security flaws to emerge, even if they are patched promptly. Users should be aware that while this version might not have immediate critical threats, the underlying code may have recurring issues that require diligent patching and monitoring. The overall assessment suggests a moderately risky plugin, with the primary immediate risk stemming from the unprotected AJAX handlers, and the historical data indicating a higher likelihood of future vulnerabilities.
Key Concerns
- AJAX handlers without auth checks
- Unsanitized path flow
- History of 1 critical CVE
- History of 3 high CVEs
Easy WP SMTP – WordPress SMTP and Email Logs: Gmail, Office 365, Outlook, Custom SMTP, and more Security Vulnerabilities
CVEs by Year
Severity Breakdown
8 total CVEs
Easy WP SMTP by SendLayer <= 2.3.0 - Exposure of Sensitive Information via the UI
Easy WP SMTP <= 1.5.1 - Authenticated (Admin+) Arbitrary File Deletion
Easy WP SMTP <= 1.5.1 - Authenticated (Admin+) Remote Code Execution
Easy WP SMTP <= 1.5.1 - Authenticated (Admin+) Directory Traversal
Easy WP SMTP <= 1.4.9 - Authenticated (Administrator+) PHP Object Injection
Easy WP SMTP <= 1.4.2 - Sensitive Information Disclosure
Easy WP SMTP <= 1.3.9 - Missing Authorization to Arbitrary Options Update
Easy WP SMTP <= 1.2.4 - Cross-Site Scripting
Easy WP SMTP – WordPress SMTP and Email Logs: Gmail, Office 365, Outlook, Custom SMTP, and more Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Easy WP SMTP – WordPress SMTP and Email Logs: Gmail, Office 365, Outlook, Custom SMTP, and more Attack Surface
AJAX Handlers 21
WordPress Hooks 122
Maintenance & Trust
Easy WP SMTP – WordPress SMTP and Email Logs: Gmail, Office 365, Outlook, Custom SMTP, and more Maintenance & Trust
Maintenance Signals
Community Trust
Easy WP SMTP – WordPress SMTP and Email Logs: Gmail, Office 365, Outlook, Custom SMTP, and more Alternatives
WP Mail SMTP by WPForms – The Most Popular SMTP and Email Log Plugin
wp-mail-smtp
Make email delivery easy for WordPress. Connect with SMTP, Gmail, Outlook, SendGrid, Mailgun, SES, Zoho, + more. Rated #1 WordPress SMTP Email plugin.
SureMail – SMTP and Email Logs Plugin with Amazon SES, Postmark, and Other Providers
suremails
SureMail – SMTP and Email Logs Plugin with Amazon SES, Postmark, and Other Providers
Alternate SMTP By Brainvire
alternate-smtp
Make email delivery easy for WordPress. Connect with SMTP, Gmail, Outlook, SendGrid, Mailgun, SES, Zoho, + more. Rated #1 WordPress SMTP Email plugin.
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App
post-smtp
Improve WordPress email deliverability. Connect Gmail SMTP, Microsoft 365, Brevo, SendGrid, Mailgun, Zoho, Amazon SES, etc. #1 WordPress SMTP Plugin.
Bit SMTP – Easy SMTP Solution with Email Logs
bit-smtp
Short Description
Easy WP SMTP – WordPress SMTP and Email Logs: Gmail, Office 365, Outlook, Custom SMTP, and more Developer Profile
94 plugins · 23.5M total installs
How We Detect Easy WP SMTP – WordPress SMTP and Email Logs: Gmail, Office 365, Outlook, Custom SMTP, and more
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/easy-wp-smtp/assets/css/smtp-global.css/wp-content/plugins/easy-wp-smtp/assets/css/smtp-settings.css/wp-content/plugins/easy-wp-smtp/assets/css/smtp-wizard.css/wp-content/plugins/easy-wp-smtp/assets/js/smtp-wizard.js/wp-content/plugins/easy-wp-smtp/assets/js/smtp-wizard.jseasy-wp-smtp/assets/css/smtp-global.css?ver=easy-wp-smtp/assets/css/smtp-settings.css?ver=easy-wp-smtp/assets/css/smtp-wizard.css?ver=easy-wp-smtp/assets/js/smtp-wizard.js?ver=HTML / DOM Fingerprints
easy-wp-smtp-notice