
GoSMTP – SMTP for WordPress Security & Risk Analysis
wordpress.org/plugins/gosmtpSend emails from your WordPress site using your preferred SMTP provider like Gmail, Outlook, AWS, Zoho, SMTP.com, Brevo (formerly Sendinblue), Mailgun …
Is GoSMTP – SMTP for WordPress Safe to Use in 2026?
Generally Safe
Score 100/100GoSMTP – SMTP for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The goSMTP plugin v1.1.9 exhibits a generally strong security posture based on the provided static analysis. The absence of any known CVEs or vulnerabilities in its history is a significant positive indicator. Furthermore, the code analysis reveals a commendable practice of using prepared statements for all SQL queries and a high percentage of properly escaped outputs, mitigating common risks like SQL injection and XSS. The presence of nonce and capability checks on its entry points, along with no raw SQL queries or critical taint flows, further strengthens its security.
However, there are minor areas for improvement. The existence of two AJAX handlers, while currently protected by authentication checks, represents potential attack vectors that require ongoing vigilance. The file operations and external HTTP requests, while not explicitly flagged as dangerous, warrant review to ensure they do not introduce indirect vulnerabilities. Overall, goSMTP appears to be a well-developed plugin with a strong commitment to security, but continuous monitoring and adherence to best practices for its remaining entry points are recommended.
Key Concerns
- AJAX handlers present
- File operations present
- External HTTP requests present
GoSMTP – SMTP for WordPress Security Vulnerabilities
GoSMTP – SMTP for WordPress Code Analysis
Output Escaping
Data Flow Analysis
GoSMTP – SMTP for WordPress Attack Surface
AJAX Handlers 2
WordPress Hooks 8
Scheduled Events 2
Maintenance & Trust
GoSMTP – SMTP for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
GoSMTP – SMTP for WordPress Alternatives
Kingmailer WordPress SMTP
kingmailer-smtp
SMTP for sending user registration emails, order emails, contact form emails.
SMTP for SendGrid – YaySMTP
smtp-sendgrid
Send emails from WordPress through SendGrid using SMTP by YayCommerce
Super Duper SMTP
super-duper-smtp
A crazy simple SMTP plugin.
Authority Mailer SMTP – WordPress SMTP Plugin with Email Logs
authority-mailer-smtp
Fix WordPress emails not sending. SMTP plugin with Email Logs for Gmail, Outlook, SendGrid, Mailgun. Easy Setup, reliable delivery.
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App
post-smtp
Improve WordPress email deliverability. Connect Gmail SMTP, Microsoft 365, Brevo, SendGrid, Mailgun, Zoho, Amazon SES, etc. #1 WordPress SMTP Plugin.
GoSMTP – SMTP for WordPress Developer Profile
10 plugins · 4.1M total installs
How We Detect GoSMTP – SMTP for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gosmtp/main/settings.css/wp-content/plugins/gosmtp/main/admin.css/wp-content/plugins/gosmtp/main/settings.js/wp-content/plugins/gosmtp/main/admin.jsgosmtp/main/settings.css?ver=gosmtp/main/admin.css?ver=gosmtp/main/settings.js?ver=gosmtp/main/admin.js?ver=HTML / DOM Fingerprints
gosmtp-box-containergosmtp-promotiongosmtp-promotion-contentgosmtp-promotion-logo<!--GoSMTP's Mailer API connecters are derived from Fluent SMTP:<!--Main Table-->id="gosmtp-plugin-update-notice"GOSMTP_URLSOFTACULOUS_PLUGIN_UPDATE_NOTICE