
Site Mailer – SMTP Replacement, Email API Deliverability & Email Log Security & Risk Analysis
wordpress.org/plugins/site-mailerEffortlessly manage transactional emails with Site Mailer. High deliverability, logs and statistics, and no SMTP plugins needed.
Is Site Mailer – SMTP Replacement, Email API Deliverability & Email Log Safe to Use in 2026?
Generally Safe
Score 98/100Site Mailer – SMTP Replacement, Email API Deliverability & Email Log has a strong security track record. Known vulnerabilities have been patched promptly.
The 'site-mailer' plugin v1.4.3 demonstrates a generally good security posture with several positive indicators. The absence of REST API routes and shortcodes, coupled with all identified entry points (AJAX handlers) having authentication checks, significantly limits its attack surface. The code also shows strong adherence to secure coding practices, with a high percentage of SQL queries using prepared statements and output correctly escaped. Furthermore, the presence of nonce and capability checks further strengthens its defenses against common web vulnerabilities.
Despite these strengths, the plugin's vulnerability history presents a notable concern. The presence of one high-severity CVE, even though it is currently patched, indicates past security weaknesses. The common vulnerability type being Cross-site Scripting (XSS) suggests that improper input handling or output escaping was a past issue. While the current version seems to have addressed these, a history of such vulnerabilities warrants continued vigilance and thorough testing.
In conclusion, 'site-mailer' v1.4.3 has made commendable progress in implementing secure coding practices, minimizing its attack surface and utilizing robust security checks. However, the past high-severity XSS vulnerability should not be overlooked. This history suggests a potential for similar issues to re-emerge if not carefully managed. Continued monitoring of the plugin for new vulnerabilities and ensuring prompt patching remains crucial for maintaining a strong security stance.
Key Concerns
- Past high severity vulnerability (XSS)
Site Mailer – SMTP Replacement, Email API Deliverability & Email Log Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Site Mailer <= 1.2.3 - Unauthenticated Stored Cross-Site Scripting
Site Mailer – SMTP Replacement, Email API Deliverability & Email Log Code Analysis
SQL Query Safety
Output Escaping
Site Mailer – SMTP Replacement, Email API Deliverability & Email Log Attack Surface
AJAX Handlers 2
WordPress Hooks 30
Maintenance & Trust
Site Mailer – SMTP Replacement, Email API Deliverability & Email Log Maintenance & Trust
Maintenance Signals
Community Trust
Site Mailer – SMTP Replacement, Email API Deliverability & Email Log Alternatives
WP Mail SMTP by WPForms – The Most Popular SMTP and Email Log Plugin
wp-mail-smtp
Make email delivery easy for WordPress. Connect with SMTP, Gmail, Outlook, SendGrid, Mailgun, SES, Zoho, + more. Rated #1 WordPress SMTP Email plugin.
Easy WP SMTP – WordPress SMTP and Email Logs: Gmail, Office 365, Outlook, Custom SMTP, and more
easy-wp-smtp
Make SMTP email sending and delivery easy. Configure Gmail, Outlook, Brevo, SendGrid, Mailgun, SendLayer or connect to any SMTP server.
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App
post-smtp
Improve WordPress email deliverability. Connect Gmail SMTP, Microsoft 365, Brevo, SendGrid, Mailgun, Zoho, Amazon SES, etc. #1 WordPress SMTP Plugin.
WP Mail Logging
wp-mail-logging
Log, view, and resend all emails sent from your WordPress site. Great for resolving email sending issues or keeping a copy for auditing.
SureMail – SMTP and Email Logs Plugin with Amazon SES, Postmark, and Other Providers
suremails
SureMail – SMTP and Email Logs Plugin with Amazon SES, Postmark, and Other Providers
Site Mailer – SMTP Replacement, Email API Deliverability & Email Log Developer Profile
15 plugins · 13.2M total installs
How We Detect Site Mailer – SMTP Replacement, Email API Deliverability & Email Log
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/site-mailer/assets/build/style-app.css/wp-content/plugins/site-mailer/assets/build/app.js/wp-content/plugins/site-mailer/assets/build/app.jssite-mailer/style.css?ver=site-mailer/script.js?ver=HTML / DOM Fingerprints
site-mailer__noticesite-mailer__notice--pinksite-mailer__notice-icondata-notice-slug="site-mailer-not-connected"wp.ajax.postwp.create_nonce/wp-json/site-mailer-pointer-dismissed