
eMail by SMTP Security & Risk Analysis
wordpress.org/plugins/email-by-smtpeMail by SMTP gives you the possibility to change the standard wordpress eMail sending from phpMail to SMTP transmitting.
Is eMail by SMTP Safe to Use in 2026?
Generally Safe
Score 85/100eMail by SMTP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The email-by-smtp plugin v1.0 appears to have a very limited attack surface based on the provided static analysis. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, which significantly reduces the potential entry points for attackers. Furthermore, the absence of dangerous functions, raw SQL queries, file operations, external HTTP requests, and the proper use of prepared statements for all SQL queries are strong indicators of good security practices. The plugin also does not seem to bundle any external libraries, removing a common vector for vulnerability exploitation.
However, a significant concern arises from the low percentage of properly escaped output (32%). This indicates that user-supplied data or dynamically generated content might be rendered without sufficient sanitization, potentially exposing the site to Cross-Site Scripting (XSS) vulnerabilities. The lack of nonce and capability checks, while potentially mitigated by the extremely small attack surface, is a general weakness that could become a risk if new entry points are added in future versions or if an attacker finds a way to trigger code execution indirectly. The plugin's vulnerability history is clean, with no recorded CVEs, suggesting a history of secure development or a lack of past scrutiny, but the unescaped output remains a tangible risk.
In conclusion, while the plugin exhibits strong security foundations by minimizing its attack surface and adhering to safe coding practices for database interactions and external communications, the insufficient output escaping presents a notable risk. This needs to be addressed to prevent potential XSS attacks. The absence of vulnerability history is positive but does not negate the identified code-level weaknesses.
Key Concerns
- Low percentage of properly escaped output
- Missing nonce checks
- Missing capability checks
eMail by SMTP Security Vulnerabilities
eMail by SMTP Release Timeline
eMail by SMTP Code Analysis
Output Escaping
eMail by SMTP Attack Surface
WordPress Hooks 4
Maintenance & Trust
eMail by SMTP Maintenance & Trust
Maintenance Signals
Community Trust
eMail by SMTP Alternatives
Icegram Mailer – Reliable Email Deliverability, No-code SMTP Replacement & Email logs
icegram-mailer
Send free email from your site in a minute. Do not need any complex setup of SMTP or API's
WP Mail SMTP by WPForms – The Most Popular SMTP and Email Log Plugin
wp-mail-smtp
Make email delivery easy for WordPress. Connect with SMTP, Gmail, Outlook, SendGrid, Mailgun, SES, Zoho, + more. Rated #1 WordPress SMTP Email plugin.
Easy WP SMTP – WordPress SMTP and Email Logs: Gmail, Office 365, Outlook, Custom SMTP, and more
easy-wp-smtp
Make SMTP email sending and delivery easy. Configure Gmail, Outlook, Brevo, SendGrid, Mailgun, SendLayer or connect to any SMTP server.
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App
post-smtp
Improve WordPress email deliverability. Connect Gmail SMTP, Microsoft 365, Brevo, SendGrid, Mailgun, Zoho, Amazon SES, etc. #1 WordPress SMTP Plugin.
WP Mail Logging
wp-mail-logging
Log, view, and resend all emails sent from your WordPress site. Great for resolving email sending issues or keeping a copy for auditing.
eMail by SMTP Developer Profile
1 plugin · 10 total installs
How We Detect eMail by SMTP
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
ownwp_ebs_plugin