
MailHawk — Simple SMTP, Email Delivery, and Email Logging Security & Risk Analysis
wordpress.org/plugins/mailhawkAn easier SMTP service for WordPress. Improve your WordPress email deliverability!
Is MailHawk — Simple SMTP, Email Delivery, and Email Logging Safe to Use in 2026?
Generally Safe
Score 97/100MailHawk — Simple SMTP, Email Delivery, and Email Logging has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The MailHawk plugin v1.3.5 exhibits a mixed security posture. While it demonstrates good practices in areas like prepared SQL statements and output escaping, there are significant concerns regarding its attack surface and past vulnerabilities. The presence of two AJAX handlers, one of which lacks authentication checks, and a REST API route without permission callbacks, creates direct entry points for potential attackers. The static analysis also flagged the use of the `unserialize` function, a known source of vulnerabilities if not handled with extreme care, though no specific exploit flows were identified in the taint analysis. The vulnerability history is a major red flag, indicating a past critical vulnerability related to Remote File Inclusion. Although this CVE is currently unpatched, the fact that it's in the past and not marked as currently unpatched is a slight positive, but the pattern of past critical flaws warrants caution. Overall, the plugin has some solid security implementations but is undermined by unprotected entry points and a history of critical security issues.
Key Concerns
- Unprotected AJAX handler identified
- Unprotected REST API route identified
- Use of 'unserialize' function
- Past critical vulnerability (RFI)
MailHawk — Simple SMTP, Email Delivery, and Email Logging Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WordPress SMTP Service, Email Delivery Solved! — MailHawk <= 1.3.1 - Unauthenticated Local File Inclusion
MailHawk — Simple SMTP, Email Delivery, and Email Logging Release Timeline
MailHawk — Simple SMTP, Email Delivery, and Email Logging Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
MailHawk — Simple SMTP, Email Delivery, and Email Logging Attack Surface
AJAX Handlers 2
REST API Routes 1
WordPress Hooks 61
Scheduled Events 2
Maintenance & Trust
MailHawk — Simple SMTP, Email Delivery, and Email Logging Maintenance & Trust
Maintenance Signals
Community Trust
MailHawk — Simple SMTP, Email Delivery, and Email Logging Alternatives
Solid Mail – SMTP email and logging made by SolidWP
wp-smtp
Email deliverability made SOLID. Connect to your chosen email provider with an intuitive set-it-and-forget-it SMTP plugin.
YaySMTP and Email Logs: Amazon SES, SendGrid, Outlook, Mailgun, Brevo, Google and Any SMTP Service
yaysmtp
Send WordPress emails successfully with WP Mail SMTP via your favorite mailer
Swift SMTP (formerly Welcome Email Editor)
welcome-email-editor
Swift SMTP is a free & simple SMTP Plugin for WordPress.
Bit SMTP – Easy SMTP Solution with Email Logs
bit-smtp
Short Description
SmartSMTP
smart-smtp
Reliable Email Delivery with SmartSMTP
MailHawk — Simple SMTP, Email Delivery, and Email Logging Developer Profile
7 plugins · 6K total installs
How We Detect MailHawk — Simple SMTP, Email Delivery, and Email Logging
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mailhawk/assets/css/admin.css/wp-content/plugins/mailhawk/assets/css/admin-settings.css/wp-content/plugins/mailhawk/assets/css/email-logs.css/wp-content/plugins/mailhawk/assets/css/frontend.css/wp-content/plugins/mailhawk/assets/js/admin.js/wp-content/plugins/mailhawk/assets/js/admin-settings.js/wp-content/plugins/mailhawk/assets/js/email-logs.js/wp-content/plugins/mailhawk/assets/js/frontend.js/wp-content/plugins/mailhawk/assets/js/admin.js/wp-content/plugins/mailhawk/assets/js/admin-settings.js/wp-content/plugins/mailhawk/assets/js/email-logs.js/wp-content/plugins/mailhawk/assets/js/frontend.jsmailhawk/assets/css/admin.css?ver=mailhawk/assets/css/admin-settings.css?ver=mailhawk/assets/css/email-logs.css?ver=mailhawk/assets/css/frontend.css?ver=mailhawk/assets/js/admin.js?ver=mailhawk/assets/js/admin-settings.js?ver=mailhawk/assets/js/email-logs.js?ver=mailhawk/assets/js/frontend.js?ver=HTML / DOM Fingerprints
mailhawk-brandingmailhawk-admin-wrappermailhawk-email-log-tablemailhawk-log-preview-modalmailhawk-setup-wizard<!-- MailHawk -->data-mailhawk-email-iddata-mailhawk-modal-targetdata-mailhawk-nonceMailHawkAdminMailHawkFrontendmailhawk_preview_data/wp-json/mailhawk/v1/preview-email/wp-json/mailhawk/v1/logs