
Super Duper SMTP Security & Risk Analysis
wordpress.org/plugins/super-duper-smtpA crazy simple SMTP plugin.
Is Super Duper SMTP Safe to Use in 2026?
Generally Safe
Score 85/100Super Duper SMTP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "super-duper-smtp" v1.0.3 plugin exhibits a mixed security posture. On the positive side, it has a remarkably small attack surface, with no apparent AJAX handlers, REST API routes, shortcodes, or cron events exposed without authentication. Furthermore, all SQL queries are confirmed to use prepared statements, and there are no recorded vulnerabilities or CVEs, indicating a potentially stable and well-maintained codebase. However, significant concerns arise from the static analysis. The complete absence of nonce checks and capability checks across all potential entry points, combined with a concerning output escaping rate of 0%, leaves the plugin highly vulnerable to cross-site scripting (XSS) attacks and potentially other injection vulnerabilities if any untrusted input were to reach output without proper sanitization. The presence of external HTTP requests also warrants scrutiny, as these could be exploited for various malicious purposes if not handled securely. The taint analysis revealing a flow with unsanitized paths, despite no critical or high severity ratings, is a direct indicator of potential risks.
Key Concerns
- 0% output escaping
- No capability checks
- No nonce checks
- Taint flow with unsanitized paths
- 3 external HTTP requests
Super Duper SMTP Security Vulnerabilities
Super Duper SMTP Code Analysis
Output Escaping
Data Flow Analysis
Super Duper SMTP Attack Surface
WordPress Hooks 8
Maintenance & Trust
Super Duper SMTP Maintenance & Trust
Maintenance Signals
Community Trust
Super Duper SMTP Alternatives
GoSMTP – SMTP for WordPress
gosmtp
Send emails from your WordPress site using your preferred SMTP provider like Gmail, Outlook, AWS, Zoho, SMTP.com, Brevo (formerly Sendinblue), Mailgun …
SMTP for SendGrid – YaySMTP
smtp-sendgrid
Send emails from WordPress through SendGrid using SMTP by YayCommerce
Kingmailer WordPress SMTP
kingmailer-smtp
SMTP for sending user registration emails, order emails, contact form emails.
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App
post-smtp
Improve WordPress email deliverability. Connect Gmail SMTP, Microsoft 365, Brevo, SendGrid, Mailgun, Zoho, Amazon SES, etc. #1 WordPress SMTP Plugin.
SureMail – SMTP and Email Logs Plugin with Amazon SES, Postmark, and Other Providers
suremails
SureMail – SMTP and Email Logs Plugin with Amazon SES, Postmark, and Other Providers
Super Duper SMTP Developer Profile
1 plugin · 10 total installs
How We Detect Super Duper SMTP
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/super-duper-smtp/css/super-duper-smtp-admin.css/wp-content/plugins/super-duper-smtp/js/super-duper-smtp-admin.js/wp-content/plugins/super-duper-smtp/js/super-duper-smtp-admin.jssuper-duper-smtp/css/super-duper-smtp-admin.css?ver=super-duper-smtp/js/super-duper-smtp-admin.js?ver=