
SMTP for Amazon SES – YaySMTP Security & Risk Analysis
wordpress.org/plugins/smtp-amazon-sesSend WordPress emails through Amazon SES server using YaySMTP
Is SMTP for Amazon SES – YaySMTP Safe to Use in 2026?
Generally Safe
Score 94/100SMTP for Amazon SES – YaySMTP has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The smtp-amazon-ses plugin v1.9.1 exhibits a mixed security posture. On one hand, the static analysis shows a minimal attack surface with no apparent unprotected entry points such as AJAX handlers, REST API routes, or shortcodes. Additionally, a high percentage of SQL queries utilize prepared statements, and a significant majority of output is properly escaped, indicating good development practices in these areas. However, the plugin's vulnerability history is a significant concern. With three known CVEs, including two high and one medium severity, it suggests past issues with fundamental security vulnerabilities like SQL Injection and Cross-Site Scripting. The fact that the last vulnerability was recent (2025-07-16) and that there are currently no unpatched vulnerabilities is a positive sign, but the pattern of past exploitation warrants caution.
The absence of reported taint flows with unsanitized paths is encouraging, but the limited scope of taint analysis might not cover all potential scenarios. The presence of bundled libraries like PHPMailer and Guzzle, while common, could be a potential vector if they are not kept up-to-date and have known vulnerabilities. The number of file operations and external HTTP requests, while not directly flagged as insecure, represent areas that could be susceptible to misconfiguration or future vulnerabilities if not managed carefully.
In conclusion, while the current version of smtp-amazon-ses v1.9.1 appears to have a low immediate risk based on the provided static analysis of entry points and sanitization, its past vulnerability history casts a shadow. The presence of multiple past high and medium severity CVEs, particularly for SQL Injection and XSS, indicates a history of weaknesses that require diligent monitoring and prompt patching of future updates. The plugin's strengths lie in its limited attack surface and good use of prepared statements and output escaping, but its historical context demands a degree of vigilance.
Key Concerns
- Multiple past high severity CVEs
- One past medium severity CVE
- Bundled library (PHPMailer)
- Bundled library (Guzzle)
SMTP for Amazon SES – YaySMTP Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
SMTP for Amazon SES <= 1.9 - Authenticated (Administrator+) SQL Injection
SMTP for Amazon SES – YaySMTP <= 1.8 - Unauthenticated Stored Cross-Site Scripting via Email Logs
Vulnerability: SMTP for Amazon SES <= 1.8 - Unauthenticated Stored Cross-Site Scripting via Email Logs
SMTP for Amazon SES – YaySMTP Release Timeline
SMTP for Amazon SES – YaySMTP Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
SMTP for Amazon SES – YaySMTP Attack Surface
WordPress Hooks 8
Maintenance & Trust
SMTP for Amazon SES – YaySMTP Maintenance & Trust
Maintenance Signals
Community Trust
SMTP for Amazon SES – YaySMTP Alternatives
FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider
fluent-smtp
The Ultimate Forever Free Mail SMTP Plugin for WordPress. Connect with any SMTP, SendGrid, Mailgun, Amazon SES, Brevo, Postmark, Sparkpost, Google...
GoSMTP – SMTP for WordPress
gosmtp
Send emails from your WordPress site using your preferred SMTP provider like Gmail, Outlook, AWS, Zoho, SMTP.com, Brevo (formerly Sendinblue), Mailgun …
WP Offload SES Lite
wp-ses
Fix your email delivery problems by sending your WordPress emails through Amazon SES's powerful email sending infrastructure.
MBC SMTP Flex
mbc-smtp-flex
Extends wp_mail function to allow you to define the server, port, connection security and credentials.
Nanomailer for AWS SES
nanomailer-for-aws-ses
A lightweight plugin that sends all WordPress emails via Amazon Simple Email Service (SES) to improve deliverability and reliability.
SMTP for Amazon SES – YaySMTP Developer Profile
16 plugins · 78K total installs
How We Detect SMTP for Amazon SES – YaySMTP
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/smtp-amazon-ses/assets/css/yay-smtp-admin.css/wp-content/plugins/smtp-amazon-ses/assets/js/yay-smtp-admin.js/wp-content/plugins/smtp-amazon-ses/assets/js/purify.min.js/wp-content/plugins/smtp-amazon-ses/assets/js/yay-smtp-admin.js/wp-content/plugins/smtp-amazon-ses/assets/js/purify.min.jssmtp-amazon-ses/assets/css/yay-smtp-admin.css?ver=smtp-amazon-ses/assets/js/yay-smtp-admin.js?ver=smtp-amazon-ses/assets/js/purify.min.js?ver=HTML / DOM Fingerprints
data-page-id="yaysmtp-amazonses"yay_smtp_amazonses_wp_data