
SendWP Security & Risk Analysis
wordpress.org/plugins/sendwpSay hello to the easy solution to transactional email in WordPress.
Is SendWP Safe to Use in 2026?
Generally Safe
Score 92/100SendWP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The SendWP plugin v1.4.9 exhibits a mixed security posture. On the positive side, it demonstrates good practices in database interaction by exclusively using prepared statements for its SQL queries and shows no recorded vulnerability history, suggesting a generally well-maintained codebase. However, the static analysis reveals a significant concern: one unprotected AJAX handler. This represents a direct entry point into the plugin's functionality that an attacker could potentially exploit without requiring any authentication, posing a notable risk. While the absence of critical taint flows and dangerous functions is encouraging, the single unprotected entry point is a glaring weakness that needs immediate attention. The plugin also has a low percentage of properly escaped output, which could lead to cross-site scripting (XSS) vulnerabilities if sensitive data is displayed without proper sanitization. In conclusion, while SendWP has strengths in its data handling and lack of past vulnerabilities, the presence of an unprotected AJAX endpoint and insufficient output escaping significantly lowers its overall security score and requires mitigation.
Key Concerns
- Unprotected AJAX handler found
- Low percentage of properly escaped output
SendWP Security Vulnerabilities
SendWP Release Timeline
SendWP Code Analysis
Output Escaping
SendWP Attack Surface
AJAX Handlers 1
WordPress Hooks 11
Scheduled Events 1
Maintenance & Trust
SendWP Maintenance & Trust
Maintenance Signals
Community Trust
SendWP Alternatives
Ninja Mail
ninja-mail
Ninja Mail is being sunset and no longer functions as of April 1, 2021.
Newsletter – Send awesome emails from WordPress
newsletter
An email marketing tool for your blog: subscription forms to create your lists with unlimited subscribers and newsletters.
Brevo – Email, SMS, Web Push, Chat, and more.
mailin
Turn your WordPress site into a marketing powerhouse. Grow your audience, boost engagement, and drive more sales with Brevo.
Gravity PDF
gravity-forms-pdf-extended
Automatically generate, email and download PDF documents from Gravity Forms entries
E2Pdf – Export Pdf Tool for WordPress
e2pdf
PDF Builder for CF7, Divi, Elementor Forms, Everest, Fluent, Formidable, Forminator, Gravity, JFB, Ninja, WPForms, WooCommerce, Post Meta, ACF, etc.
SendWP Developer Profile
5 plugins · 610K total installs
How We Detect SendWP
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sendwp/assets/css/admin/settings.css/wp-content/plugins/sendwp/assets/js/admin/settings.js/wp-content/plugins/sendwp/assets/css/admin/notices.css/wp-content/plugins/sendwp/assets/js/admin/settings.jssendwp/style.css?ver=sendwp/script.js?ver=HTML / DOM Fingerprints
sendwp-settings-pagesendwp-disabled-noticedata-sendwp-noncesendwpAdminsendwp_varssendwp_settings/wp-json/sendwp/v1/connect/wp-json/sendwp/v1/disconnect/wp-json/sendwp/v1/status