SMTP.com Security & Risk Analysis

wordpress.org/plugins/smtpcom

SMTP.com is a powerful and reliable SMTP delivery service that enables you to send and track high volume emails effortlessly.

80 active installs v1.0.0 PHP 7.2+ WP 4.4.1+ Updated Feb 23, 2026
emailmailphpmailersmtpwp_mail
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is SMTP.com Safe to Use in 2026?

Generally Safe

Score 100/100

SMTP.com has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "smtpcom" plugin v1.0.0 presents a mixed security posture. On the positive side, the plugin demonstrates good practices regarding SQL queries, utilizing prepared statements exclusively, and showing a high percentage of properly escaped output. The absence of file operations and external HTTP requests, along with no recorded vulnerability history, are also encouraging signs. However, significant concerns arise from the attack surface analysis. With three identified AJAX handlers, all three lack authentication checks, creating a direct avenue for potential unauthorized actions. The presence of a single nonce check is insufficient to cover all these unprotected entry points.

The lack of capability checks on AJAX handlers is particularly worrying, as it means any authenticated user, regardless of their role or permissions, could potentially trigger these functions. This could lead to issues ranging from information disclosure to more serious forms of manipulation if these AJAX actions have unintended side effects. The bundled Guzzle library v1.1 is also noted, which, while not explicitly flagged as vulnerable in the provided data, could represent an outdated component requiring attention in a real-world scenario. In conclusion, while the plugin avoids common pitfalls like raw SQL and unescaped output, the unauthenticated AJAX endpoints represent a critical weakness that overshadows its strengths. The absence of any recorded vulnerabilities might be due to its version or limited usage, and should not be interpreted as an indication of inherent security.

Key Concerns

  • Unprotected AJAX handlers
  • Missing capability checks on AJAX
  • Bundled outdated library (Guzzle v1.1)
Vulnerabilities
None known

SMTP.com Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

SMTP.com Release Timeline

v1.0.0Current
Code Analysis
Analyzed Mar 16, 2026

SMTP.com Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
9 prepared
Unescaped Output
11
60 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Guzzle1.1

SQL Query Safety

100% prepared9 total queries

Output Escaping

85% escaped71 total outputs
Attack Surface
3 unprotected

SMTP.com Attack Surface

Entry Points3
Unprotected3

AJAX Handlers 3

authwp_ajax_saveSettings_smtpadmin\ajax-call.php:13
authwp_ajax_send_test_smtp_comadmin\ajax-call.php:150
authwp_ajax_sort_messages__smtpadmin\ajax-call.php:273
WordPress Hooks 8
filterwp_mail_fromadmin\class-smtp-com-action-mail.php:18
actionphpmailer_initadmin\class-smtp-com-action-mail.php:37
actionwp_mail_failedadmin\class-smtp-com-action-mail.php:65
actionplugins_loadedincludes\class-smtp-com-mail.php:154
actionadmin_enqueue_scriptsincludes\class-smtp-com-mail.php:169
actionadmin_enqueue_scriptsincludes\class-smtp-com-mail.php:170
actionadmin_menuincludes\settings.php:21
filterplugin_action_linkssmtp-com-mail.php:46
Maintenance & Trust

SMTP.com Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 23, 2026
PHP min version7.2
Downloads3K

Community Trust

Rating80/100
Number of ratings7
Active installs80
Developer Profile

SMTP.com Developer Profile

SMTP.com

1 plugin · 80 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect SMTP.com

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/smtp-com-mail/admin/css/datepicker.css/wp-content/plugins/smtp-com-mail/admin/css/smtp-com-mail-admin.css/wp-content/plugins/smtp-com-mail/admin/js/datepicker.js/wp-content/plugins/smtp-com-mail/admin/js/smtp-com-mail-admin.js
Script Paths
admin/js/datepicker.jsadmin/js/smtp-com-mail-admin.js
Version Parameters
smtp-com-mail/admin/css/datepicker.css?ver=smtp-com-mail/admin/css/smtp-com-mail-admin.css?ver=smtp-com-mail/admin/js/datepicker.js?ver=smtp-com-mail/admin/js/smtp-com-mail-admin.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about SMTP.com