SureMail – SMTP and Email Logs Plugin with Amazon SES, Postmark, and Other Providers Security & Risk Analysis

wordpress.org/plugins/suremails

SureMail – SMTP and Email Logs Plugin with Amazon SES, Postmark, and Other Providers

200K active installs v1.9.3 PHP 7.4+ WP 5.4+ Updated Feb 27, 2026
emailemail-logsgmail-smtpoutlooksmtp
97
A · Safe
CVEs total1
Unpatched0
Last CVEDec 1, 2025
Safety Verdict

Is SureMail – SMTP and Email Logs Plugin with Amazon SES, Postmark, and Other Providers Safe to Use in 2026?

Generally Safe

Score 97/100

SureMail – SMTP and Email Logs Plugin with Amazon SES, Postmark, and Other Providers has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Dec 1, 2025Updated 1mo ago
Risk Assessment

The suremails v1.9.3 plugin demonstrates a generally strong security posture in its static analysis. All identified AJAX handlers have appropriate authentication checks, and there are no exposed REST API routes or shortcodes, significantly limiting the attack surface. The code also adheres to secure coding practices, with 100% of SQL queries using prepared statements and all output properly escaped. Furthermore, the presence of nonce and capability checks, along with robust file operation handling, indicates a good level of developer awareness regarding common WordPress vulnerabilities.

However, the plugin's vulnerability history is a notable concern. It has one recorded high-severity vulnerability, "Unrestricted Upload of File with Dangerous Type," which was last observed on 2025-12-01. Although currently patched, this history points to a potential recurring weakness in how file uploads are handled. The absence of taint analysis results could mean that such flows were not analyzed or were found to be clean, but the historical vulnerability type warrants vigilance. The significant number of external HTTP requests (20) could also present a minor risk if any of these endpoints were compromised or if the plugin did not properly validate incoming data from these requests.

In conclusion, while the current static analysis of suremails v1.9.3 shows excellent adherence to secure coding standards and a well-protected attack surface, the past high-severity vulnerability related to file uploads is a significant red flag. This suggests a need for ongoing scrutiny of file handling functionalities and a proactive approach to security monitoring, especially considering the plugin's previous issues.

Key Concerns

  • Unpatched high severity CVE history
  • High number of external HTTP requests (20)
Vulnerabilities
1

SureMail – SMTP and Email Logs Plugin with Amazon SES, Postmark, and Other Providers Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

High
1

1 total CVE

CVE-2025-13516high · 8.1Unrestricted Upload of File with Dangerous Type

SureMail – SMTP and Email Logs Plugin with Amazon SES, Postmark, and Other Providers <= 1.9.0 - Unauthenticated Arbitrary File Upload

Dec 1, 2025 Patched in 1.9.1 (1d)
Code Analysis
Analyzed Mar 16, 2026

SureMail – SMTP and Email Logs Plugin with Amazon SES, Postmark, and Other Providers Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
6 prepared
Unescaped Output
0
208 escaped
Nonce Checks
4
Capability Checks
13
File Operations
8
External Requests
20
Bundled Libraries
0

SQL Query Safety

100% prepared6 total queries

Output Escaping

100% escaped208 total outputs
Attack Surface

SureMail – SMTP and Email Logs Plugin with Amazon SES, Postmark, and Other Providers Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_suremails-activate_plugininc\ajax\ajax.php:24
authwp_ajax_suremails-activate_themeinc\ajax\ajax.php:25
WordPress Hooks 24
actionsuremails_cleanup_croninc\admin\crons.php:35
actionsuremails_weekly_summaryinc\admin\crons.php:36
actionsuremails_retry_failed_emailinc\admin\crons.php:47
actionadmin_initinc\admin\plugin.php:35
actionadmin_menuinc\admin\plugin.php:36
actionadmin_enqueue_scriptsinc\admin\plugin.php:37
actionadmin_enqueue_scriptsinc\admin\plugin.php:38
actionadmin_noticesinc\admin\plugin.php:39
actionadmin_noticesinc\admin\plugin.php:40
actionadmin_enqueue_scriptsinc\admin\plugin.php:41
actionadmin_headinc\admin\plugin.php:42
actionadmin_initinc\admin\update.php:53
actionsuremails_update_beforeinc\admin\update.php:54
filterwp_redirectinc\ajax\ajax.php:71
filterbsf_core_statsinc\analytics\analytics.php:30
actionrest_api_initinc\api\api-init.php:32
actionsuremails_retry_failed_emailinc\controller\emails.php:39
filtersuremails_process_get_logsinc\db\email-log.php:42
filtersuremails_before_send_emailinc\emails\handler\mail-handler.php:69
actionadmin_footerinc\nps-notice.php:46
actionplugins_loadedloader.php:58
actionplugins_loadedloader.php:59
actionplugin_loadedloader.php:60
actionadmin_initsuremails.php:34

Scheduled Events 3

suremails_cleanup_cron
suremails_weekly_summary
suremails_retry_failed_email
Maintenance & Trust

SureMail – SMTP and Email Logs Plugin with Amazon SES, Postmark, and Other Providers Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 27, 2026
PHP min version7.4
Downloads1.2M

Community Trust

Rating96/100
Number of ratings22
Active installs200K
Developer Profile

SureMail – SMTP and Email Logs Plugin with Amazon SES, Postmark, and Other Providers Developer Profile

Brainstorm Force

32 plugins · 8.6M total installs

78
trust score
Avg Security Score
98/100
Avg Patch Time
196 days
View full developer profile
Detection Fingerprints

How We Detect SureMail – SMTP and Email Logs Plugin with Amazon SES, Postmark, and Other Providers

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/suremails/build/admin-notice.css/wp-content/plugins/suremails/build/admin-notice.js
Script Paths
/wp-content/plugins/suremails/build/admin-notice.js
Version Parameters
suremails/build/admin-notice.css?ver=suremails/build/admin-notice.js?ver=

HTML / DOM Fingerprints

CSS Classes
suremails-admin-notice
JS Globals
suremailsNotice
FAQ

Frequently Asked Questions about SureMail – SMTP and Email Logs Plugin with Amazon SES, Postmark, and Other Providers