Surbma | SMTP Security & Risk Analysis

wordpress.org/plugins/surbma-smtp

External SMTP mail configuration via global variables in wp-config.php.

20 active installs v2.3 PHP 7.0+ WP 5.0+ Updated Nov 26, 2023
emailmailgunmultisitesendgridsmtp
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Surbma | SMTP Safe to Use in 2026?

Generally Safe

Score 85/100

Surbma | SMTP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the surbma-smtp plugin version 2.3 appears to have a strong security posture. The static analysis reveals a completely clean codebase with no dangerous functions, no direct SQL queries (all prepared statements), and all output is properly escaped. There are no file operations or external HTTP requests, and crucially, no identifiable attack surface points like AJAX handlers, REST API routes, or shortcodes. This indicates robust development practices focused on minimizing potential vulnerabilities.

The lack of any recorded vulnerabilities in its history further reinforces this positive assessment. With zero known CVEs, no unpatched vulnerabilities, and no history of common vulnerability types, the plugin has a proven track record of security. This suggests a mature and well-maintained codebase that has not been a target for or succumbed to known exploit methods.

While the plugin exhibits excellent security characteristics in its current analysis and history, the absence of certain security mechanisms like nonce and capability checks on entry points (though there are no entry points found) is noted. However, given the complete lack of an attack surface, this absence does not present an immediate risk. Overall, surbma-smtp v2.3 demonstrates a commendable commitment to security, with strengths in code hygiene and a clean vulnerability history.

Vulnerabilities
None known

Surbma | SMTP Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Surbma | SMTP Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Surbma | SMTP Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionphpmailer_initsurbma-smtp.php:24
Maintenance & Trust

Surbma | SMTP Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedNov 26, 2023
PHP min version7.0
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Surbma | SMTP Developer Profile

Surbma

27 plugins · 30K total installs

71
trust score
Avg Security Score
88/100
Avg Patch Time
127 days
View full developer profile
Detection Fingerprints

How We Detect Surbma | SMTP

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Surbma | SMTP