
MY SMTP WP Security & Risk Analysis
wordpress.org/plugins/my-smtp-wpConfigure your WordPress to send e-mails using your personal e-mail via SMTP.
Is MY SMTP WP Safe to Use in 2026?
Generally Safe
Score 85/100MY SMTP WP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "my-smtp-wp" plugin version 1.4.0 demonstrates a generally good security posture based on the provided static analysis. The absence of known vulnerabilities in its history is a significant positive. Furthermore, the plugin exhibits strong coding practices such as using prepared statements for all SQL queries, performing file operations only when necessary, and making no external HTTP requests. The presence of nonce checks further enhances security against common web attacks.
However, a notable concern arises from the very low percentage of properly escaped output (6%). With 16 total outputs, only a small fraction appear to be properly sanitized, leaving the plugin vulnerable to potential cross-site scripting (XSS) attacks. This is a significant weakness that could allow an attacker to inject malicious scripts into the application, impacting users. The lack of capability checks and no recorded instances of taint analysis also mean that some vulnerabilities might have been missed by these specific checks, or that the plugin's internal logic doesn't expose such complex flows.
In conclusion, while the plugin benefits from a clean vulnerability history and good practices in areas like database interaction and external communication, the insufficient output escaping represents a critical security flaw. This needs to be addressed to mitigate the risk of XSS vulnerabilities. The absence of known CVEs is encouraging, but the static analysis signals a clear area for improvement.
Key Concerns
- Insufficient output escaping
MY SMTP WP Security Vulnerabilities
MY SMTP WP Code Analysis
Output Escaping
MY SMTP WP Attack Surface
WordPress Hooks 7
Maintenance & Trust
MY SMTP WP Maintenance & Trust
Maintenance Signals
Community Trust
MY SMTP WP Alternatives
SMTP Mailer
smtp-mailer
Configure a SMTP server to send email from your WordPress site. Configure the wp_mail() function to use SMTP instead of the PHP mail() function.
WPO365 | MICROSOFT 365 GRAPH MAILER
wpo365-msgraphmailer
Send WordPress emails from a M365 / Exchange Online Mailbox using Microsoft Graph, leveraging OAuth for authentication which is more secure than SMTP
Configure SMTP
configure-smtp
Configure SMTP mailing in WordPress, including support for sending email via SSL/TLS (such as Gmail).
MailerSend – Official SMTP Integration
mailersend-official-smtp-integration
Improve your deliverability and avoid the spam box with MailerSend’s SMTP server. Check your analytics to improve your emails for better conversion!
SAR Friendly SMTP
sar-friendly-smtp
A friendly SMTP plugin for WordPress. No third-party, simply using WordPress native possibilities.
MY SMTP WP Developer Profile
8 plugins · 3K total installs
How We Detect MY SMTP WP
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/my-smtp-wp/css/my-smtp-wp.css/wp-content/plugins/my-smtp-wp/js/my-smtp-wp.js/wp-content/plugins/my-smtp-wp/js/my-smtp-wp.jsmy-smtp-wp/css/my-smtp-wp.css?ver=my-smtp-wp/js/my-smtp-wp.js?ver=HTML / DOM Fingerprints
window.wsOptions