
Global SMTP Security & Risk Analysis
wordpress.org/plugins/global-smtpSetup SMTP via wp-config.php.
Is Global SMTP Safe to Use in 2026?
Generally Safe
Score 85/100Global SMTP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of the global-smtp v1.0 plugin reveals a seemingly clean codebase with no identified dangerous functions, SQL injection risks, or file operations. The absence of external HTTP requests and the complete reliance on prepared statements for SQL queries are positive security indicators. Furthermore, the plugin boasts a minimal attack surface with no exposed AJAX handlers, REST API routes, shortcodes, or cron events that are not protected by authentication checks or permission callbacks. The vulnerability history is also clear, with no recorded CVEs, suggesting a potentially well-maintained plugin.
However, a significant concern arises from the output escaping. With 4 total outputs and 0% properly escaped, this indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities. Any dynamic data displayed by the plugin is likely vulnerable to injection, which could lead to session hijacking, defacement, or other malicious actions. While the plugin demonstrates good practices in other areas, this critical oversight in output sanitization presents a notable security weakness. The lack of nonce and capability checks on any potential entry points, although currently zero, could become a problem if the plugin is extended or if future versions introduce new functionalities.
Key Concerns
- Output escaping is not performed
Global SMTP Security Vulnerabilities
Global SMTP Code Analysis
Output Escaping
Global SMTP Attack Surface
WordPress Hooks 4
Maintenance & Trust
Global SMTP Maintenance & Trust
Maintenance Signals
Community Trust
Global SMTP Alternatives
Surbma | SMTP
surbma-smtp
External SMTP mail configuration via global variables in wp-config.php.
WP Mail SMTP by WPForms – The Most Popular SMTP and Email Log Plugin
wp-mail-smtp
Make email delivery easy for WordPress. Connect with SMTP, Gmail, Outlook, SendGrid, Mailgun, SES, Zoho, + more. Rated #1 WordPress SMTP Email plugin.
Easy WP SMTP – WordPress SMTP and Email Logs: Gmail, Office 365, Outlook, Custom SMTP, and more
easy-wp-smtp
Make SMTP email sending and delivery easy. Configure Gmail, Outlook, Brevo, SendGrid, Mailgun, SendLayer or connect to any SMTP server.
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App
post-smtp
Improve WordPress email deliverability. Connect Gmail SMTP, Microsoft 365, Brevo, SendGrid, Mailgun, Zoho, Amazon SES, etc. #1 WordPress SMTP Plugin.
WP Mail Logging
wp-mail-logging
Log, view, and resend all emails sent from your WordPress site. Great for resolving email sending issues or keeping a copy for auditing.
Global SMTP Developer Profile
1 plugin · 60 total installs
How We Detect Global SMTP
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
wraperrorreadonly="readonly"<h1>Global SMTP Setup</h1><p>To test your configuration, we recommend installing the <a href="https://wordpress.org/plugins/check-email/">check email plugin</a>.</p><p><strong>This page will no longer appear once a valid configuration is found.</strong></p><p><strong>Example of minimum configuration</strong> (example for gmail)</p>