
Stars SMTP Mailer Security & Risk Analysis
wordpress.org/plugins/stars-smtp-mailerEvery email your WordPress website sends is important — whether it’s a contact form message, password reset, order update, or newsletter.
Is Stars SMTP Mailer Safe to Use in 2026?
Generally Safe
Score 98/100Stars SMTP Mailer has a strong security track record. Known vulnerabilities have been patched promptly.
The "stars-smtp-mailer" v2.2.1 plugin exhibits a mixed security posture. While it demonstrates some good practices, such as a relatively high percentage of SQL queries using prepared statements and a significant number of output escaping routines, there are notable areas of concern. The static analysis reveals an attack surface with 5 entry points, of which 3 lack authentication checks, presenting a significant risk for unauthorized access or manipulation. Furthermore, the taint analysis identified 4 flows with unsanitized paths, all classified as high severity, indicating potential for serious security vulnerabilities like cross-site scripting or remote code execution if these flows are exploited.
The plugin's vulnerability history, with 2 known CVEs including a high and a medium severity one, reinforces these concerns. Although there are currently no unpatched vulnerabilities, the past occurrence of "Cross-site Scripting" and "Unrestricted Upload of File with Dangerous Type" suggests recurring weaknesses in input validation and file handling. The "Cross-site Scripting" vulnerability in particular aligns with the high-severity unsanitized taint flows, indicating a potential pattern of issues related to how user-supplied data is processed and rendered. In conclusion, while the plugin shows some positive security implementations, the presence of unprotected entry points, high-severity taint flows, and a history of significant vulnerabilities necessitate careful consideration and immediate patching of any newly discovered issues.
Key Concerns
- 3 unprotected AJAX handlers
- 4 high severity unsanitized taint flows
- 1 high severity CVE (historical)
- 1 medium severity CVE (historical)
- Only 1 capability check on 5 entry points
- 36% of output is not properly escaped
Stars SMTP Mailer Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Stars SMTP Mailer <= 1.7 - Reflected Cross-Site Scripting
Stars SMTP Mailer <= 1.7 - Authenticated (Subscriber+) Arbitrary File Upload
Stars SMTP Mailer Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Stars SMTP Mailer Attack Surface
AJAX Handlers 5
WordPress Hooks 12
Scheduled Events 1
Maintenance & Trust
Stars SMTP Mailer Maintenance & Trust
Maintenance Signals
Community Trust
Stars SMTP Mailer Alternatives
WP SMTP Mailer
wp-smtp-mailer
WP SMTP Mailer is a simple and flexible plugin to configure SMTP settings in WordPress. It allows you to set up SMTP credentials, test email sending, …
WP Mail SMTP by WPForms – The Most Popular SMTP and Email Log Plugin
wp-mail-smtp
Make email delivery easy for WordPress. Connect with SMTP, Gmail, Outlook, SendGrid, Mailgun, SES, Zoho, + more. Rated #1 WordPress SMTP Email plugin.
Easy WP SMTP – WordPress SMTP and Email Logs: Gmail, Office 365, Outlook, Custom SMTP, and more
easy-wp-smtp
Make SMTP email sending and delivery easy. Configure Gmail, Outlook, Brevo, SendGrid, Mailgun, SendLayer or connect to any SMTP server.
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App
post-smtp
Improve WordPress email deliverability. Connect Gmail SMTP, Microsoft 365, Brevo, SendGrid, Mailgun, Zoho, Amazon SES, etc. #1 WordPress SMTP Plugin.
WP Mail Logging
wp-mail-logging
Log, view, and resend all emails sent from your WordPress site. Great for resolving email sending issues or keeping a copy for auditing.
Stars SMTP Mailer Developer Profile
1 plugin · 10 total installs
How We Detect Stars SMTP Mailer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/stars-smtp-mailer/assets/css/stars-smtp-style.css/wp-content/plugins/stars-smtp-mailer/assets/js/stars-smtp-script.js/wp-content/plugins/stars-smtp-mailer/assets/js/stars-smtp-script.jsstars-smtp-mailer/assets/css/stars-smtp-style.css?ver=stars-smtp-mailer/assets/js/stars-smtp-script.js?ver=HTML / DOM Fingerprints
stars-smtp-mailer<!-- Stars SMTP Mailer Plugin for sending emails through SMTP --><!-- Myriad Solutionz, 2019, All Rights Reserved --><!-- This code is released under the GPL licence version 3 or later, available here --><!-- Table 1: SMTP Settings -->+4 morestars_smtpm_plugin_urlstars_smtpm_plugin_dir