
SmartrMail – Email Marketing for WooCommerce Security & Risk Analysis
wordpress.org/plugins/smartrmail-personalized-email-marketingSmartrMail lets you send personalized shopping emails, to get more sales
Is SmartrMail – Email Marketing for WooCommerce Safe to Use in 2026?
Generally Safe
Score 92/100SmartrMail – Email Marketing for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "smartrmail-personalized-email-marketing" plugin v2.2.6 exhibits a concerning security posture due to a significant number of unprotected entry points. All 5 identified entry points, including both AJAX handlers and REST API routes, lack proper authorization checks. This exposes the plugin to potential unauthorized access and manipulation. Furthermore, the presence of the dangerous `unserialize` function, coupled with a high-severity taint flow with an unsanitized path, indicates a potential for arbitrary code execution or data manipulation if these functions are triggered with malicious input.
The static analysis reveals a lack of robust security practices, with no nonce checks and only one capability check across all entry points. While the plugin shows some good practices, like the majority of SQL queries using prepared statements and a moderate rate of proper output escaping, these strengths are overshadowed by the critical vulnerabilities in its access control and data handling. The absence of any recorded CVEs or past vulnerabilities is a positive sign, suggesting a lack of previously discovered exploits. However, this does not mitigate the immediate risks identified in the current version's code.
In conclusion, while the plugin has not historically been a target for known vulnerabilities, the current version presents significant security risks due to its unprotected attack surface and potential for code execution. Immediate attention is required to implement proper authentication and authorization mechanisms for all AJAX and REST API endpoints, and to carefully review and sanitize any data processed by the `unserialize` function and the identified unsanitized taint flow.
Key Concerns
- AJAX handlers without auth checks
- REST API routes without permission callbacks
- Dangerous function: unserialize
- Taint flow with unsanitized path (high severity)
- No nonce checks
- Only 1 capability check
SmartrMail – Email Marketing for WooCommerce Security Vulnerabilities
SmartrMail – Email Marketing for WooCommerce Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
SmartrMail – Email Marketing for WooCommerce Attack Surface
AJAX Handlers 2
REST API Routes 3
WordPress Hooks 16
Maintenance & Trust
SmartrMail – Email Marketing for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
SmartrMail – Email Marketing for WooCommerce Alternatives
Newsletter – Send awesome emails from WordPress
newsletter
An email marketing tool for your blog: subscription forms to create your lists with unlimited subscribers and newsletters.
Email marketing for WordPress by GetResponse Official
getresponse-official
Maximize visitor potential! Capture emails, automate marketing, track visits, and transfer ecommerce data to GetResponse for precision campaigns.
SureContact – Newsletters, Email Marketing, Automation, Revenue Tracking & CRM
surecontact
Send newsletters, set up email automations, manage contacts and track ecommerce revenue in a CRM for WordPress.
EmailWish
emailwish
EmailWish is an email marketing solution designed for ecommerce, offering powerful automation tools to drive the growth of businesses of every size.
Hostinger Reach – AI-Powered Email Marketing for WordPress
hostinger-reach
Launch and grow your email marketing effortlessly with Hostinger Reach. Collect contacts, sync subscribers, and send emails – all in one, AI powered.
SmartrMail – Email Marketing for WooCommerce Developer Profile
1 plugin · 40 total installs
How We Detect SmartrMail – Email Marketing for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/smartrmail-personalized-email-marketing/assets/js/smartrmail_popup.js/wp-content/plugins/smartrmail-personalized-email-marketing/assets/js/main.js/wp-content/plugins/smartrmail-personalized-email-marketing/assets/css/style.csswp-content/plugins/smartrmail-personalized-email-marketing/assets/js/smartrmail_popup.jswp-content/plugins/smartrmail-personalized-email-marketing/assets/js/main.jssmartrmail-personalized-email-marketing/assets/js/main.js?ver=3.2.1smartrmail-personalized-email-marketing/assets/css/style.css?ver=1.0.0HTML / DOM Fingerprints
smartrmail-apidata-smartrmail-urlsmartrmail_localizeWooCommerce/wp-json/swi-api/v1/javascript/wp-json/smartrmail/v1/customers/wp-json/smartrmail/v1/products