Yandex Mail SMTP Server for WordPress Security & Risk Analysis

wordpress.org/plugins/smtp-yandex-mail-server

Connect to Yandex SMTP server to automatically send emails from your WordPress site through the Yandex SMTP server instead of PHP mail().

2K active installs v1.0.2 PHP + WP 4.0+ Updated Dec 2, 2019
smtpsmtp-serveryandexyandex-mailyandex-smtp
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Yandex Mail SMTP Server for WordPress Safe to Use in 2026?

Generally Safe

Score 85/100

Yandex Mail SMTP Server for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The "smtp-yandex-mail-server" plugin, version 1.0.2, exhibits a strong security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the attack surface. The code also adheres to good practices by avoiding dangerous functions, performing all SQL queries using prepared statements, and not making external HTTP requests. The lack of file operations and the absence of recorded vulnerabilities in its history further contribute to its positive security assessment.

However, a notable concern arises from the output escaping. With only 33% of the six identified outputs being properly escaped, there is a risk of cross-site scripting (XSS) vulnerabilities. If user-controlled data is being outputted without adequate sanitization in the unescaped portions, an attacker could potentially inject malicious scripts. The plugin also lacks nonce and capability checks, which are standard security mechanisms for protecting against certain types of attacks, especially if new entry points are introduced in future versions. While the current attack surface is zero, the absence of these checks could become a weakness if the plugin evolves.

In conclusion, the plugin demonstrates good foundational security with a minimal attack surface and secure database practices. The primary weakness lies in the insufficient output escaping, presenting a potential XSS risk. The lack of recorded vulnerabilities is positive but doesn't negate the identified code-level concerns. Developers should prioritize addressing the output escaping issues to fully secure the plugin.

Key Concerns

  • Insufficient output escaping
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Yandex Mail SMTP Server for WordPress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Yandex Mail SMTP Server for WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

33% escaped6 total outputs
Attack Surface

Yandex Mail SMTP Server for WordPress Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actioninitclass-yandex-smtp.php:10
actionadmin_menuclass-yandex-smtp.php:11
actionadmin_initclass-yandex-smtp.php:12
actionadmin_noticesclass-yandex-smtp.php:13
filterplugin_action_linksclass-yandex-smtp.php:14
actioninityandex-smtp.php:20
actionphpmailer_inityandex-smtp.php:31
Maintenance & Trust

Yandex Mail SMTP Server for WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested5.3.21
Last updatedDec 2, 2019
PHP min version
Downloads25K

Community Trust

Rating90/100
Number of ratings8
Active installs2K
Developer Profile

Yandex Mail SMTP Server for WordPress Developer Profile

Ozan Canakli

3 plugins · 2K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Yandex Mail SMTP Server for WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/smtp-yandex-mail-server/js/admin-scripts.js/wp-content/plugins/smtp-yandex-mail-server/css/admin-styles.css
Script Paths
/wp-content/plugins/smtp-yandex-mail-server/js/admin-scripts.js
Version Parameters
smtp-yandex-mail-server/js/admin-scripts.js?ver=smtp-yandex-mail-server/css/admin-styles.css?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Yandex Mail SMTP Server for WordPress