
Brevo SMTP – YaySMTP Security & Risk Analysis
wordpress.org/plugins/smtp-sendinblueSend emails from WordPress through Brevo using SMTP by YayCommerce
Is Brevo SMTP – YaySMTP Safe to Use in 2026?
Generally Safe
Score 98/100Brevo SMTP – YaySMTP has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The smtp-sendinblue plugin v1.3.1 presents a mixed security posture. On the positive side, the static analysis reveals a minimal attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events exposed without authentication. The code also demonstrates good practices with a high percentage of SQL queries using prepared statements and properly escaped output. The presence of nonce and capability checks, though limited, is also a positive sign.
However, concerns arise from the plugin's vulnerability history. Two known CVEs, one high and one medium severity, have been reported, indicating past weaknesses in handling SQL injection and Cross-Site Scripting vulnerabilities. While there are no currently unpatched vulnerabilities, the history suggests a tendency for these types of issues to emerge. The presence of file operations and external HTTP requests, while not inherently problematic, could be vectors for exploitation if not meticulously secured. The use of bundled libraries, such as PHPMailer, warrants attention as outdated versions of these can introduce vulnerabilities.
In conclusion, while the current version appears to have a controlled attack surface and good basic coding practices, the historical presence of critical vulnerability types necessitates ongoing vigilance. The limited number of vulnerability history points (2) and the absence of currently unpatched issues are strengths. The primary weakness lies in the past occurrence of SQL injection and XSS, which require careful code auditing and a robust patching strategy. The plugin's security can be considered moderate, with room for improvement to mitigate the risks indicated by its history.
Key Concerns
- High severity unpatched CVE
- Medium severity unpatched CVE
- Bundled library (PHPMailer) potential risk
- SQL queries not using prepared statements
- Output not properly escaped
Brevo SMTP – YaySMTP Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
YaySMTP <= 1.3 - Authenticated (Administrator+) SQL Injection
SMTP for Sendinblue – YaySMTP <= 1.2 - Unauthenticated Stored Cross-Site Scripting via Email Logs
Brevo SMTP – YaySMTP Release Timeline
Brevo SMTP – YaySMTP Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Brevo SMTP – YaySMTP Attack Surface
WordPress Hooks 8
Maintenance & Trust
Brevo SMTP – YaySMTP Maintenance & Trust
Maintenance Signals
Community Trust
Brevo SMTP – YaySMTP Alternatives
Brevo – Email, SMS, Web Push, Chat, and more.
mailin
Turn your WordPress site into a marketing powerhouse. Grow your audience, boost engagement, and drive more sales with Brevo.
ClickSyncr for Brevo – Contact Form 7 Integration
clicksyncr-for-brevo
Connect Contact Form 7 to Brevo. Sync each submission to a Brevo list, map contact attributes, and update existing contacts — no code.
Integration for Elementor forms – Sendinblue
integration-for-elementor-forms-sendinblue
Connect your Elementor Pro forms to Sendinblue/Brevo to easily capture and manage contacts from your website.
Add-on Brevo for Gravity Forms
addon-gravityforms-sendinblue-free
Connect Gravity Forms to Brevo (Sendinblue). Sync form fields with Brevo attributes and automatically generate contacts in specified lists.
Magic Emails & Autologin URLs
bh-wp-autologin-urls
Adds magic email link to login screen. Adds single-use passwords to WordPress emails' URLs for frictionless login.
Brevo SMTP – YaySMTP Developer Profile
16 plugins · 78K total installs
How We Detect Brevo SMTP – YaySMTP
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/smtp-sendinblue/assets/css/yay-smtp-admin.css/wp-content/plugins/smtp-sendinblue/assets/js/yay-smtp-admin.js/wp-content/plugins/smtp-sendinblue/assets/js/purify.min.js/wp-content/plugins/smtp-sendinblue/assets/js/yay-smtp-admin.js/wp-content/plugins/smtp-sendinblue/assets/js/purify.min.jssmtp-sendinblue/assets/css/yay-smtp-admin.css?ver=smtp-sendinblue/assets/js/yay-smtp-admin.js?ver=smtp-sendinblue/assets/js/purify.min.js?ver=HTML / DOM Fingerprints
data-yaysmtp-page-idyay_smtp_sendinblue_wp_data