
SMTP for Sendinblue – YaySMTP Security & Risk Analysis
wordpress.org/plugins/smtp-sendinblueSend emails from WordPress through Sendinblue using SMTP by YayCommerce
Is SMTP for Sendinblue – YaySMTP Safe to Use in 2026?
Generally Safe
Score 97/100SMTP for Sendinblue – YaySMTP has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The smtp-sendinblue plugin v1.3.1 presents a mixed security posture. On the positive side, the static analysis reveals a minimal attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events exposed without authentication. The code also demonstrates good practices with a high percentage of SQL queries using prepared statements and properly escaped output. The presence of nonce and capability checks, though limited, is also a positive sign.
However, concerns arise from the plugin's vulnerability history. Two known CVEs, one high and one medium severity, have been reported, indicating past weaknesses in handling SQL injection and Cross-Site Scripting vulnerabilities. While there are no currently unpatched vulnerabilities, the history suggests a tendency for these types of issues to emerge. The presence of file operations and external HTTP requests, while not inherently problematic, could be vectors for exploitation if not meticulously secured. The use of bundled libraries, such as PHPMailer, warrants attention as outdated versions of these can introduce vulnerabilities.
In conclusion, while the current version appears to have a controlled attack surface and good basic coding practices, the historical presence of critical vulnerability types necessitates ongoing vigilance. The limited number of vulnerability history points (2) and the absence of currently unpatched issues are strengths. The primary weakness lies in the past occurrence of SQL injection and XSS, which require careful code auditing and a robust patching strategy. The plugin's security can be considered moderate, with room for improvement to mitigate the risks indicated by its history.
Key Concerns
- High severity unpatched CVE
- Medium severity unpatched CVE
- Bundled library (PHPMailer) potential risk
- SQL queries not using prepared statements
- Output not properly escaped
SMTP for Sendinblue – YaySMTP Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
YaySMTP <= 1.3 - Authenticated (Administrator+) SQL Injection
SMTP for Sendinblue – YaySMTP <= 1.2 - Unauthenticated Stored Cross-Site Scripting via Email Logs
SMTP for Sendinblue – YaySMTP Release Timeline
SMTP for Sendinblue – YaySMTP Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
SMTP for Sendinblue – YaySMTP Attack Surface
WordPress Hooks 8
Maintenance & Trust
SMTP for Sendinblue – YaySMTP Maintenance & Trust
Maintenance Signals
Community Trust
SMTP for Sendinblue – YaySMTP Alternatives
Brevo – Email, SMS, Web Push, Chat, and more.
mailin
Turn your WordPress site into a marketing powerhouse. Grow your audience, boost engagement, and drive more sales with Brevo.
Integration for Elementor forms – Sendinblue
integration-for-elementor-forms-sendinblue
Connect your Elementor Pro forms to Sendinblue/Brevo to easily capture and manage contacts from your website.
Add-on Brevo for Gravity Forms
addon-gravityforms-sendinblue-free
Connect Gravity Forms to Brevo (Sendinblue). Sync form fields with Brevo attributes and automatically generate contacts in specified lists.
BrevWoo
brevwoo
Add WooCommerce customers to Brevo on product purchase.
Stars SMTP Mailer
stars-smtp-mailer
Every email your WordPress website sends is important — whether it’s a contact form message, password reset, order update, or newsletter.
SMTP for Sendinblue – YaySMTP Developer Profile
16 plugins · 78K total installs
How We Detect SMTP for Sendinblue – YaySMTP
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/smtp-sendinblue/assets/css/yay-smtp-admin.css/wp-content/plugins/smtp-sendinblue/assets/js/yay-smtp-admin.js/wp-content/plugins/smtp-sendinblue/assets/js/purify.min.js/wp-content/plugins/smtp-sendinblue/assets/js/yay-smtp-admin.js/wp-content/plugins/smtp-sendinblue/assets/js/purify.min.jssmtp-sendinblue/assets/css/yay-smtp-admin.css?ver=smtp-sendinblue/assets/js/yay-smtp-admin.js?ver=smtp-sendinblue/assets/js/purify.min.js?ver=HTML / DOM Fingerprints
data-yaysmtp-page-idyay_smtp_sendinblue_wp_data