
SMTP for SendGrid – YaySMTP Security & Risk Analysis
wordpress.org/plugins/smtp-sendgridSend emails from WordPress through SendGrid using SMTP by YayCommerce
Is SMTP for SendGrid – YaySMTP Safe to Use in 2026?
Generally Safe
Score 97/100SMTP for SendGrid – YaySMTP has a strong security track record. Known vulnerabilities have been patched promptly.
The 'smtp-sendgrid' plugin v1.5.1 exhibits a generally strong security posture based on the provided static analysis. The absence of identified AJAX handlers, REST API routes, shortcodes, and cron events with unprotected entry points suggests a limited attack surface. Furthermore, the code demonstrates good practices with a high percentage of SQL queries using prepared statements and a majority of outputs being properly escaped. The presence of nonce and capability checks, along with a single external HTTP request, are also positive indicators.
Key Concerns
- High historical high/medium CVE count
- Bundled PHPMailer library
- Some SQL queries not prepared
- Some outputs not escaped
SMTP for SendGrid – YaySMTP Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
SMTP for SendGrid – YaySMTP <= 1.5 - Authenticated (Administrator+) SQL Injection
SMTP for SendGrid – YaySMTP <= 1.4 - Unauthenticated Stored Cross-Site Scripting via Email Logs
SMTP for SendGrid – YaySMTP Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
SMTP for SendGrid – YaySMTP Attack Surface
WordPress Hooks 8
Maintenance & Trust
SMTP for SendGrid – YaySMTP Maintenance & Trust
Maintenance Signals
Community Trust
SMTP for SendGrid – YaySMTP Alternatives
WP SMTP Mailer – SMTP7
wp-mail-smtp-mailer
WP SMTP Mailer Plugin - SMTP7. Make email delivery easy from WordPress. It is easy to configure.
MailHawk — Simple SMTP, Email Delivery, and Email Logging
mailhawk
An easier SMTP service for WordPress. Improve your WordPress email deliverability!
MailHog for WordPress
wp-mailhog-smtp
Zero configuration MailHog plugin for your development machine.
HTP SMTP – WP Mail SMTP, Amazon SES, SendGrid, MailGun and Any SMTP Connector Plugin
htp-smtp
HTP SMTP can help us to send emails via SMTP instead of the PHP mail() function.
GoSMTP – SMTP for WordPress
gosmtp
Send emails from your WordPress site using your preferred SMTP provider like Gmail, Outlook, AWS, Zoho, SMTP.com, Brevo (formerly Sendinblue), Mailgun …
SMTP for SendGrid – YaySMTP Developer Profile
16 plugins · 78K total installs
How We Detect SMTP for SendGrid – YaySMTP
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/smtp-sendgrid/assets/css/yay-smtp-admin.css/wp-content/plugins/smtp-sendgrid/assets/js/yay-smtp-admin.js/wp-content/plugins/smtp-sendgrid/assets/js/purify.min.js/wp-content/plugins/smtp-sendgrid/assets/js/yay-smtp-admin.js/wp-content/plugins/smtp-sendgrid/assets/js/purify.min.jssmtp-sendgrid/assets/css/yay-smtp-admin.css?ver=smtp-sendgrid/assets/js/yay-smtp-admin.js?ver=smtp-sendgrid/assets/js/purify.min.js?ver=HTML / DOM Fingerprints
data-pageid="yaysmtp-sendgrid-settings"window.yay_smtp_sendgrid_wp_data