
HTP SMTP – WP Mail SMTP, Amazon SES, SendGrid, MailGun and Any SMTP Connector Plugin Security & Risk Analysis
wordpress.org/plugins/htp-smtpHTP SMTP can help us to send emails via SMTP instead of the PHP mail() function.
Is HTP SMTP – WP Mail SMTP, Amazon SES, SendGrid, MailGun and Any SMTP Connector Plugin Safe to Use in 2026?
Generally Safe
Score 85/100HTP SMTP – WP Mail SMTP, Amazon SES, SendGrid, MailGun and Any SMTP Connector Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "htp-smtp" plugin version 1.1.3 exhibits a generally good security posture based on the provided static analysis. The plugin has zero known vulnerabilities (CVEs) and zero unpatched vulnerabilities, indicating a history of responsible development or limited exposure to known attack vectors. The static analysis reveals no dangerous functions, no direct SQL queries (all use prepared statements), no file operations, and no external HTTP requests, all of which are positive security indicators. The absence of critical or high severity taint analysis results further suggests that data sanitization and handling are likely robust.
However, there are minor areas for improvement. While the attack surface is currently zero, this could change with future updates. The plugin has no capability checks implemented on its entry points, which could be a concern if new entry points are introduced without proper authorization checks. Additionally, 14% of output is not properly escaped. While the taint analysis did not flag any critical issues, unescaped output can still lead to cross-site scripting (XSS) vulnerabilities, especially if the data originates from user input. In conclusion, the plugin appears secure against common attack vectors and has a clean vulnerability history. The main areas of focus for future development should be ensuring proper capability checks are implemented for all entry points and addressing the remaining unescaped output to achieve a more comprehensive security posture.
Key Concerns
- Unescaped output detected
- No capability checks on entry points
HTP SMTP – WP Mail SMTP, Amazon SES, SendGrid, MailGun and Any SMTP Connector Plugin Security Vulnerabilities
HTP SMTP – WP Mail SMTP, Amazon SES, SendGrid, MailGun and Any SMTP Connector Plugin Release Timeline
HTP SMTP – WP Mail SMTP, Amazon SES, SendGrid, MailGun and Any SMTP Connector Plugin Code Analysis
Output Escaping
HTP SMTP – WP Mail SMTP, Amazon SES, SendGrid, MailGun and Any SMTP Connector Plugin Attack Surface
WordPress Hooks 9
Maintenance & Trust
HTP SMTP – WP Mail SMTP, Amazon SES, SendGrid, MailGun and Any SMTP Connector Plugin Maintenance & Trust
Maintenance Signals
Community Trust
HTP SMTP – WP Mail SMTP, Amazon SES, SendGrid, MailGun and Any SMTP Connector Plugin Alternatives
SMTP for SendGrid – YaySMTP
smtp-sendgrid
Send emails from WordPress through SendGrid using SMTP by YayCommerce
YaySMTP and Email Logs: Amazon SES, SendGrid, Outlook, Mailgun, Brevo, Google and Any SMTP Service
yaysmtp
Send WordPress emails successfully with WP Mail SMTP via your favorite mailer
WP SMTP Mailer – SMTP7
wp-mail-smtp-mailer
WP SMTP Mailer Plugin - SMTP7. Make email delivery easy from WordPress. It is easy to configure.
Swift SMTP (formerly Welcome Email Editor)
welcome-email-editor
Swift SMTP is a free & simple SMTP Plugin for WordPress.
Bit SMTP – Easy SMTP Solution with Email Logs
bit-smtp
Short Description
HTP SMTP – WP Mail SMTP, Amazon SES, SendGrid, MailGun and Any SMTP Connector Plugin Developer Profile
1 plugin · 20 total installs
How We Detect HTP SMTP – WP Mail SMTP, Amazon SES, SendGrid, MailGun and Any SMTP Connector Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/htp-smtp/build/app.css/wp-content/plugins/htp-smtp/build/app.js/wp-content/plugins/htp-smtp/build/app.jshtp-smtp/build/app.css?ver=htp-smtp/build/app.js?ver=HTML / DOM Fingerprints
window.htp_smtp