Site Mailer – SMTP Replacement, Email API Deliverability & Email Log Security & Risk Analysis

wordpress.org/plugins/site-mailer

Effortlessly manage transactional emails with Site Mailer. High deliverability, logs and statistics, and no SMTP plugins needed.

200K active installs v1.4.3 PHP 7.4+ WP 6.6+ Updated Feb 17, 2026
emailemail-apiemail-logsendersmtp
98
A · Safe
CVEs total1
Unpatched0
Last CVEFeb 27, 2025
Safety Verdict

Is Site Mailer – SMTP Replacement, Email API Deliverability & Email Log Safe to Use in 2026?

Generally Safe

Score 98/100

Site Mailer – SMTP Replacement, Email API Deliverability & Email Log has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Feb 27, 2025Updated 1mo ago
Risk Assessment

The 'site-mailer' plugin v1.4.3 demonstrates a generally good security posture with several positive indicators. The absence of REST API routes and shortcodes, coupled with all identified entry points (AJAX handlers) having authentication checks, significantly limits its attack surface. The code also shows strong adherence to secure coding practices, with a high percentage of SQL queries using prepared statements and output correctly escaped. Furthermore, the presence of nonce and capability checks further strengthens its defenses against common web vulnerabilities.

Despite these strengths, the plugin's vulnerability history presents a notable concern. The presence of one high-severity CVE, even though it is currently patched, indicates past security weaknesses. The common vulnerability type being Cross-site Scripting (XSS) suggests that improper input handling or output escaping was a past issue. While the current version seems to have addressed these, a history of such vulnerabilities warrants continued vigilance and thorough testing.

In conclusion, 'site-mailer' v1.4.3 has made commendable progress in implementing secure coding practices, minimizing its attack surface and utilizing robust security checks. However, the past high-severity XSS vulnerability should not be overlooked. This history suggests a potential for similar issues to re-emerge if not carefully managed. Continued monitoring of the plugin for new vulnerabilities and ensuring prompt patching remains crucial for maintaining a strong security stance.

Key Concerns

  • Past high severity vulnerability (XSS)
Vulnerabilities
1

Site Mailer – SMTP Replacement, Email API Deliverability & Email Log Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

High
1

1 total CVE

CVE-2025-1319high · 7.2Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Site Mailer <= 1.2.3 - Unauthenticated Stored Cross-Site Scripting

Feb 27, 2025 Patched in 1.2.4 (1d)
Code Analysis
Analyzed Mar 16, 2026

Site Mailer – SMTP Replacement, Email API Deliverability & Email Log Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
21 prepared
Unescaped Output
6
115 escaped
Nonce Checks
3
Capability Checks
4
File Operations
1
External Requests
1
Bundled Libraries
0

SQL Query Safety

95% prepared22 total queries

Output Escaping

95% escaped121 total outputs
Attack Surface

Site Mailer – SMTP Replacement, Email API Deliverability & Email Log Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_site_mailer_pointer_dismissedmodules\core\components\pointers.php:47
authwp_ajax_site_mailer_deactivation_feedbackmodules\deactivation\module.php:258
WordPress Hooks 30
actionrest_api_initclasses\rest\route.php:57
filterelementor_one/site_mailer_connect_authorize_urlmodules\connect\module.php:61
actionadmin_noticesmodules\core\components\conflicts.php:79
actioncurrent_screenmodules\core\components\not-connected.php:104
actionadmin_enqueue_scriptsmodules\core\components\not-connected.php:114
actionadmin_noticesmodules\core\components\not-connected.php:115
actioncurrent_screenmodules\core\components\quota-exhausted-banner.php:136
actionadmin_enqueue_scriptsmodules\core\components\quota-exhausted-banner.php:153
actionadmin_noticesmodules\core\components\quota-exhausted-banner.php:154
actioncurrent_screenmodules\core\components\renewal-notice.php:120
actionadmin_enqueue_scriptsmodules\core\components\renewal-notice.php:137
actionadmin_noticesmodules\core\components\renewal-notice.php:138
filterplugin_action_linksmodules\core\module.php:69
actionadmin_enqueue_scriptsmodules\deactivation\module.php:256
actionadmin_footermodules\deactivation\module.php:257
actionwpmodules\logs\classes\log-handler.php:124
actionwpmodules\logs\components\log-pull.php:28
filterpre_wp_mailmodules\mailer\module.php:80
actionadmin_enqueue_scriptsmodules\reviews\module.php:237
actionadmin_initmodules\reviews\module.php:238
actionrest_api_initmodules\reviews\module.php:239
filterplugin_row_metamodules\reviews\module.php:240
actionin_admin_headermodules\settings\components\settings-pointer.php:96
actioncurrent_screenmodules\settings\module.php:508
actionadmin_noticesmodules\settings\module.php:509
actionadmin_menumodules\settings\module.php:512
actionadmin_enqueue_scriptsmodules\settings\module.php:513
actionrest_api_initmodules\settings\module.php:518
actionelementor_one/switched_domainmodules\settings\module.php:524
actionplugins_loadedsite-mailer.php:41
Maintenance & Trust

Site Mailer – SMTP Replacement, Email API Deliverability & Email Log Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 17, 2026
PHP min version7.4
Downloads1.8M

Community Trust

Rating40/100
Number of ratings13
Active installs200K
Developer Profile

Site Mailer – SMTP Replacement, Email API Deliverability & Email Log Developer Profile

Elementor

15 plugins · 13.2M total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
704 days
View full developer profile
Detection Fingerprints

How We Detect Site Mailer – SMTP Replacement, Email API Deliverability & Email Log

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/site-mailer/assets/build/style-app.css/wp-content/plugins/site-mailer/assets/build/app.js
Script Paths
/wp-content/plugins/site-mailer/assets/build/app.js
Version Parameters
site-mailer/style.css?ver=site-mailer/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
site-mailer__noticesite-mailer__notice--pinksite-mailer__notice-icon
Data Attributes
data-notice-slug="site-mailer-not-connected"
JS Globals
wp.ajax.postwp.create_nonce
REST Endpoints
/wp-json/site-mailer-pointer-dismissed
FAQ

Frequently Asked Questions about Site Mailer – SMTP Replacement, Email API Deliverability & Email Log