
SureMail – SMTP and Email Logs Plugin with Amazon SES, Postmark, and Other Providers Security & Risk Analysis
wordpress.org/plugins/suremailsSureMail – SMTP and Email Logs Plugin with Amazon SES, Postmark, and Other Providers
Is SureMail – SMTP and Email Logs Plugin with Amazon SES, Postmark, and Other Providers Safe to Use in 2026?
Generally Safe
Score 97/100SureMail – SMTP and Email Logs Plugin with Amazon SES, Postmark, and Other Providers has a strong security track record. Known vulnerabilities have been patched promptly.
The suremails v1.9.3 plugin demonstrates a generally strong security posture in its static analysis. All identified AJAX handlers have appropriate authentication checks, and there are no exposed REST API routes or shortcodes, significantly limiting the attack surface. The code also adheres to secure coding practices, with 100% of SQL queries using prepared statements and all output properly escaped. Furthermore, the presence of nonce and capability checks, along with robust file operation handling, indicates a good level of developer awareness regarding common WordPress vulnerabilities.
However, the plugin's vulnerability history is a notable concern. It has one recorded high-severity vulnerability, "Unrestricted Upload of File with Dangerous Type," which was last observed on 2025-12-01. Although currently patched, this history points to a potential recurring weakness in how file uploads are handled. The absence of taint analysis results could mean that such flows were not analyzed or were found to be clean, but the historical vulnerability type warrants vigilance. The significant number of external HTTP requests (20) could also present a minor risk if any of these endpoints were compromised or if the plugin did not properly validate incoming data from these requests.
In conclusion, while the current static analysis of suremails v1.9.3 shows excellent adherence to secure coding standards and a well-protected attack surface, the past high-severity vulnerability related to file uploads is a significant red flag. This suggests a need for ongoing scrutiny of file handling functionalities and a proactive approach to security monitoring, especially considering the plugin's previous issues.
Key Concerns
- Unpatched high severity CVE history
- High number of external HTTP requests (20)
SureMail – SMTP and Email Logs Plugin with Amazon SES, Postmark, and Other Providers Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
SureMail – SMTP and Email Logs Plugin with Amazon SES, Postmark, and Other Providers <= 1.9.0 - Unauthenticated Arbitrary File Upload
SureMail – SMTP and Email Logs Plugin with Amazon SES, Postmark, and Other Providers Code Analysis
SQL Query Safety
Output Escaping
SureMail – SMTP and Email Logs Plugin with Amazon SES, Postmark, and Other Providers Attack Surface
AJAX Handlers 2
WordPress Hooks 24
Scheduled Events 3
Maintenance & Trust
SureMail – SMTP and Email Logs Plugin with Amazon SES, Postmark, and Other Providers Maintenance & Trust
Maintenance Signals
Community Trust
SureMail – SMTP and Email Logs Plugin with Amazon SES, Postmark, and Other Providers Alternatives
WP Mail SMTP by WPForms – The Most Popular SMTP and Email Log Plugin
wp-mail-smtp
Make email delivery easy for WordPress. Connect with SMTP, Gmail, Outlook, SendGrid, Mailgun, SES, Zoho, + more. Rated #1 WordPress SMTP Email plugin.
Easy WP SMTP – WordPress SMTP and Email Logs: Gmail, Office 365, Outlook, Custom SMTP, and more
easy-wp-smtp
Make SMTP email sending and delivery easy. Configure Gmail, Outlook, Brevo, SendGrid, Mailgun, SendLayer or connect to any SMTP server.
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App
post-smtp
Improve WordPress email deliverability. Connect Gmail SMTP, Microsoft 365, Brevo, SendGrid, Mailgun, Zoho, Amazon SES, etc. #1 WordPress SMTP Plugin.
Bit SMTP – Easy SMTP Solution with Email Logs
bit-smtp
Short Description
Alternate SMTP By Brainvire
alternate-smtp
Make email delivery easy for WordPress. Connect with SMTP, Gmail, Outlook, SendGrid, Mailgun, SES, Zoho, + more. Rated #1 WordPress SMTP Email plugin.
SureMail – SMTP and Email Logs Plugin with Amazon SES, Postmark, and Other Providers Developer Profile
32 plugins · 8.6M total installs
How We Detect SureMail – SMTP and Email Logs Plugin with Amazon SES, Postmark, and Other Providers
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/suremails/build/admin-notice.css/wp-content/plugins/suremails/build/admin-notice.js/wp-content/plugins/suremails/build/admin-notice.jssuremails/build/admin-notice.css?ver=suremails/build/admin-notice.js?ver=HTML / DOM Fingerprints
suremails-admin-noticesuremailsNotice