
SMTP for WP Security & Risk Analysis
wordpress.org/plugins/smtp-for-wpConfigure SMTP details to send emails using your SMTP account.
Is SMTP for WP Safe to Use in 2026?
Generally Safe
Score 85/100SMTP for WP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of smtp-for-wp v1.1 reveals a generally good security posture with no identified CVEs and a complete lack of dangerous functions or raw SQL queries. The plugin also avoids external HTTP requests and file operations, which are common attack vectors. However, the limited attack surface and the use of prepared statements might mask underlying issues, as the taint analysis shows 2 flows with unsanitized paths, although they were not classified as critical or high severity. This suggests a potential for vulnerabilities if these paths are ever exposed to user input. The most significant concern is the output escaping, with only 36% of outputs being properly escaped. This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected and executed within the WordPress admin area or on the frontend if the plugin's output is displayed there. The plugin's vulnerability history is clean, but this does not negate the risks identified in the code analysis.
Key Concerns
- Low percentage of properly escaped output
- Unsanitized paths found in taint analysis
SMTP for WP Security Vulnerabilities
SMTP for WP Release Timeline
SMTP for WP Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
SMTP for WP Attack Surface
WordPress Hooks 12
Maintenance & Trust
SMTP for WP Maintenance & Trust
Maintenance Signals
Community Trust
SMTP for WP Alternatives
SMTP Mailer
smtp-mailer
Configure a SMTP server to send email from your WordPress site. Configure the wp_mail() function to use SMTP instead of the PHP mail() function.
WPO365 | MICROSOFT 365 GRAPH MAILER
wpo365-msgraphmailer
Send WordPress emails from a M365 / Exchange Online Mailbox using Microsoft Graph, leveraging OAuth for authentication which is more secure than SMTP
Configure SMTP
configure-smtp
Configure SMTP mailing in WordPress, including support for sending email via SSL/TLS (such as Gmail).
MailerSend – Official SMTP Integration
mailersend-official-smtp-integration
Improve your deliverability and avoid the spam box with MailerSend’s SMTP server. Check your analytics to improve your emails for better conversion!
SAR Friendly SMTP
sar-friendly-smtp
A friendly SMTP plugin for WordPress. No third-party, simply using WordPress native possibilities.
SMTP for WP Developer Profile
6 plugins · 610 total installs
How We Detect SMTP for WP
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/smtp-for-wp/assets/css/style.css/wp-content/plugins/smtp-for-wp/assets/js/jquery.form.js/wp-content/plugins/smtp-for-wp/assets/js/jquery.form.jssmtp-for-wp/assets/css/style.css?ver=smtp-for-wp/assets/js/jquery.form.js?ver=HTML / DOM Fingerprints
sn_ws_admin_url