HTP SMTP – WP Mail SMTP, Amazon SES, SendGrid, MailGun and Any SMTP Connector Plugin Security & Risk Analysis

wordpress.org/plugins/htp-smtp

HTP SMTP can help us to send emails via SMTP instead of the PHP mail() function.

20 active installs v1.1.3 PHP + WP + Updated Jun 4, 2022
htp-smtpmailsmtpwp-mail-smtpwp-smtp
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is HTP SMTP – WP Mail SMTP, Amazon SES, SendGrid, MailGun and Any SMTP Connector Plugin Safe to Use in 2026?

Generally Safe

Score 85/100

HTP SMTP – WP Mail SMTP, Amazon SES, SendGrid, MailGun and Any SMTP Connector Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "htp-smtp" plugin version 1.1.3 exhibits a generally good security posture based on the provided static analysis. The plugin has zero known vulnerabilities (CVEs) and zero unpatched vulnerabilities, indicating a history of responsible development or limited exposure to known attack vectors. The static analysis reveals no dangerous functions, no direct SQL queries (all use prepared statements), no file operations, and no external HTTP requests, all of which are positive security indicators. The absence of critical or high severity taint analysis results further suggests that data sanitization and handling are likely robust.

However, there are minor areas for improvement. While the attack surface is currently zero, this could change with future updates. The plugin has no capability checks implemented on its entry points, which could be a concern if new entry points are introduced without proper authorization checks. Additionally, 14% of output is not properly escaped. While the taint analysis did not flag any critical issues, unescaped output can still lead to cross-site scripting (XSS) vulnerabilities, especially if the data originates from user input. In conclusion, the plugin appears secure against common attack vectors and has a clean vulnerability history. The main areas of focus for future development should be ensuring proper capability checks are implemented for all entry points and addressing the remaining unescaped output to achieve a more comprehensive security posture.

Key Concerns

  • Unescaped output detected
  • No capability checks on entry points
Vulnerabilities
None known

HTP SMTP – WP Mail SMTP, Amazon SES, SendGrid, MailGun and Any SMTP Connector Plugin Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

HTP SMTP – WP Mail SMTP, Amazon SES, SendGrid, MailGun and Any SMTP Connector Plugin Release Timeline

No version history available.
Code Analysis
Analyzed Mar 16, 2026

HTP SMTP – WP Mail SMTP, Amazon SES, SendGrid, MailGun and Any SMTP Connector Plugin Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
42 escaped
Nonce Checks
3
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

86% escaped49 total outputs
Attack Surface

HTP SMTP – WP Mail SMTP, Amazon SES, SendGrid, MailGun and Any SMTP Connector Plugin Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionadmin_menuinc\Admin_Menus.php:18
actionadmin_initinc\Admin_Menus.php:19
actioninitinc\Main.php:23
actionplugins_loadedinc\Main.php:31
actionphpmailer_initinc\Main.php:32
filterplugin_action_linksinc\Main.php:33
filternetwork_admin_plugin_action_linksinc\Main.php:35
actionnetwork_admin_menuinc\Network_Admin_Menus.php:18
actionadmin_initinc\Network_Admin_Menus.php:19
Maintenance & Trust

HTP SMTP – WP Mail SMTP, Amazon SES, SendGrid, MailGun and Any SMTP Connector Plugin Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedJun 4, 2022
PHP min version
Downloads6K

Community Trust

Rating100/100
Number of ratings1
Active installs20
Developer Profile

HTP SMTP – WP Mail SMTP, Amazon SES, SendGrid, MailGun and Any SMTP Connector Plugin Developer Profile

HuTaNaTu

1 plugin · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect HTP SMTP – WP Mail SMTP, Amazon SES, SendGrid, MailGun and Any SMTP Connector Plugin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/htp-smtp/build/app.css/wp-content/plugins/htp-smtp/build/app.js
Script Paths
/wp-content/plugins/htp-smtp/build/app.js
Version Parameters
htp-smtp/build/app.css?ver=htp-smtp/build/app.js?ver=

HTML / DOM Fingerprints

JS Globals
window.htp_smtp
FAQ

Frequently Asked Questions about HTP SMTP – WP Mail SMTP, Amazon SES, SendGrid, MailGun and Any SMTP Connector Plugin