
FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider Security & Risk Analysis
wordpress.org/plugins/fluent-smtpThe Ultimate Forever Free Mail SMTP Plugin for WordPress. Connect with any SMTP, SendGrid, Mailgun, Amazon SES, Brevo, Postmark, Sparkpost, Google...
Is FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider Safe to Use in 2026?
Generally Safe
Score 93/100FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin 'fluent-smtp' v2.2.95 exhibits a mixed security posture. While it demonstrates good practices in using prepared statements for a high percentage of SQL queries and properly escaping a significant portion of its output, there are notable areas of concern. The presence of an unprotected AJAX handler is a significant risk, providing an easily accessible entry point for attackers. Furthermore, the use of the `unserialize` function, even without evident taint flows in this specific static analysis, historically represents a critical vulnerability class if not handled with extreme care regarding input sources. The plugin's vulnerability history is a substantial red flag, with a notable number of past CVEs across all severity levels, including a past critical vulnerability. This pattern suggests a recurring tendency to introduce security flaws, and the fact that the last reported vulnerability was relatively recent in 2025 indicates ongoing security challenges. Despite its strengths in data handling, the unprotected entry points and historical vulnerability trends necessitate caution.
Key Concerns
- Unprotected AJAX handler
- Dangerous function: unserialize
- Past critical vulnerability
- Past high severity vulnerability
- Past medium severity vulnerability (x2)
- Past low severity vulnerability
- Bundled library: PHPMailer
FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
FluentSMTP <= 2.2.80 - Cross-Site Request Forgery
FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider <= 2.2.82 - Unauthenticated PHP Object Injection
FluentSMTP <= 2.2.4 - Unauthenticated Stored Cross-Site Scripting via Email Subject
FluentSMTP <= 2.2.2 - Authenticated (Author+) Stored Cross-Site Scripting via Email Logs
FluentSMTP <= 2.0.0 - Authenticated (Admin+) Stored Cross-Site Scripting
FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider Attack Surface
AJAX Handlers 1
REST API Routes 1
WordPress Hooks 23
Scheduled Events 2
Maintenance & Trust
FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider Maintenance & Trust
Maintenance Signals
Community Trust
FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider Alternatives
WP Offload SES Lite
wp-ses
Fix your email delivery problems by sending your WordPress emails through Amazon SES's powerful email sending infrastructure.
WP SMTP Mailer – SMTP7
wp-mail-smtp-mailer
WP SMTP Mailer Plugin - SMTP7. Make email delivery easy from WordPress. It is easy to configure.
EmailIdea SMTP Mailer
emailidea-smtp-mailer
EmailIdea SMTP Mailer ensures reliable WordPress email delivery via secure API-based SMTP and SaaS connectivity, solving common mail issues.
GoSMTP – SMTP for WordPress
gosmtp
Send emails from your WordPress site using your preferred SMTP provider like Gmail, Outlook, AWS, Zoho, SMTP.com, Brevo (formerly Sendinblue), Mailgun …
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App
post-smtp
Improve WordPress email deliverability. Connect Gmail SMTP, Microsoft 365, Brevo, SendGrid, Mailgun, Zoho, Amazon SES, etc. #1 WordPress SMTP Plugin.
FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider Developer Profile
17 plugins · 1.3M total installs
How We Detect FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/fluent-smtp/app/assets/css/fluent-smtp.css/wp-content/plugins/fluent-smtp/app/assets/js/fluent-smtp.js/wp-content/plugins/fluent-smtp/app/assets/js/fluent-smtp.jsfluent-smtp/app/assets/css/fluent-smtp.css?ver=fluent-smtp/app/assets/js/fluent-smtp.js?ver=HTML / DOM Fingerprints
fluent_smtp_box<!-- This notice is from FluentSMTP plugin to prevent plugin
conflict. --><!-- For SMTP, you already have FluentSMTP Installed -->data-tb-margintopfluentMailApp/wp-json/fluent-smtp