
TWP email Security & Risk Analysis
wordpress.org/plugins/twp-emailsimple smtp mail setup for wordpress
Is TWP email Safe to Use in 2026?
Generally Safe
Score 85/100TWP email has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'twp-email' plugin, version 1.3.7, presents a mixed security posture. On one hand, the absence of known vulnerabilities (CVEs) and a relatively small attack surface with no direct AJAX handlers, REST API routes, shortcodes, or cron events are positive indicators. The code also shows some good practices, with a significant portion of SQL queries utilizing prepared statements and a moderate level of output escaping. However, significant concerns arise from the static analysis. The presence of a taint flow with unsanitized paths, even if classified as high severity and not critical, is a notable risk that could lead to code execution or data manipulation if exploited. Furthermore, the complete lack of nonce checks and the single capability check across all potential entry points suggest a potential weakness in authorization mechanisms, leaving functionalities vulnerable if an attack vector is discovered.
While the plugin has no recorded vulnerability history, this cannot be solely relied upon as an indicator of inherent security. The taint analysis reveals a specific weakness that could be exploited in the absence of traditional CVEs. The limited number of entry points is a strength, but the lack of robust authentication and authorization checks on these potential vectors is a weakness. The plugin's strengths lie in its apparent lack of external dependencies and direct attack vectors, but its weaknesses are in how it handles potentially untrusted data and verifies user permissions.
Key Concerns
- Taint flow with unsanitized path (high severity)
- No nonce checks across all entry points
- Limited capability checks
- 50% of SQL queries not using prepared statements
- 49% of outputs not properly escaped
TWP email Security Vulnerabilities
TWP email Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
TWP email Attack Surface
WordPress Hooks 6
Maintenance & Trust
TWP email Maintenance & Trust
Maintenance Signals
Community Trust
TWP email Alternatives
WP Mail SMTP by WPForms – The Most Popular SMTP and Email Log Plugin
wp-mail-smtp
Make email delivery easy for WordPress. Connect with SMTP, Gmail, Outlook, SendGrid, Mailgun, SES, Zoho, + more. Rated #1 WordPress SMTP Email plugin.
Easy WP SMTP – WordPress SMTP and Email Logs: Gmail, Office 365, Outlook, Custom SMTP, and more
easy-wp-smtp
Make SMTP email sending and delivery easy. Configure Gmail, Outlook, Brevo, SendGrid, Mailgun, SendLayer or connect to any SMTP server.
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App
post-smtp
Improve WordPress email deliverability. Connect Gmail SMTP, Microsoft 365, Brevo, SendGrid, Mailgun, Zoho, Amazon SES, etc. #1 WordPress SMTP Plugin.
WP Mail Logging
wp-mail-logging
Log, view, and resend all emails sent from your WordPress site. Great for resolving email sending issues or keeping a copy for auditing.
Site Mailer – SMTP Replacement, Email API Deliverability & Email Log
site-mailer
Effortlessly manage transactional emails with Site Mailer. High deliverability, logs and statistics, and no SMTP plugins needed.
TWP email Developer Profile
2 plugins · 0 total installs
How We Detect TWP email
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/twp-email/style.csstwp-email/style.css?ver=