
Swift SMTP (formerly Welcome Email Editor) Security & Risk Analysis
wordpress.org/plugins/welcome-email-editorSwift SMTP is a free & simple SMTP Plugin for WordPress.
Is Swift SMTP (formerly Welcome Email Editor) Safe to Use in 2026?
Generally Safe
Score 99/100Swift SMTP (formerly Welcome Email Editor) has a strong security track record. Known vulnerabilities have been patched promptly.
The "welcome-email-editor" plugin v6.3 exhibits a mixed security posture. On the positive side, the code analysis shows good practices such as 100% of SQL queries using prepared statements and all output being properly escaped, indicating an effort to prevent common web vulnerabilities. The absence of critical or high-severity taint flows and dangerous functions is also encouraging. However, a significant concern is the presence of one AJAX handler without authentication checks. This directly contributes to the plugin's limited attack surface but leaves it exposed to potential unauthorized actions if exploited. The vulnerability history reveals two known medium-severity CVEs, specifically related to Cross-Site Request Forgery and Missing Authorization. While there are no currently unpatched vulnerabilities, the pattern of past issues, particularly missing authorization, aligns with the static analysis finding of an unprotected AJAX endpoint, suggesting a recurring area of weakness. In conclusion, while the plugin demonstrates good coding hygiene in many areas, the unprotected AJAX handler and historical vulnerabilities related to authorization represent a notable risk that requires attention.
Key Concerns
- Unprotected AJAX handler
- Two medium severity CVEs in history
- History of Missing Authorization
Swift SMTP (formerly Welcome Email Editor) Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Swift SMTP <= 5.0.6 - Cross-Site Request Forgery
Welcome Email Editor <= 5.0.5 - Missing Authorization via ajax_handler
Swift SMTP (formerly Welcome Email Editor) Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Swift SMTP (formerly Welcome Email Editor) Attack Surface
AJAX Handlers 1
WordPress Hooks 42
Maintenance & Trust
Swift SMTP (formerly Welcome Email Editor) Maintenance & Trust
Maintenance Signals
Community Trust
Swift SMTP (formerly Welcome Email Editor) Alternatives
YaySMTP and Email Logs: Amazon SES, SendGrid, Outlook, Mailgun, Brevo, Google and Any SMTP Service
yaysmtp
Send WordPress emails successfully with WP Mail SMTP via your favorite mailer
Bit SMTP – Easy SMTP Solution with Email Logs
bit-smtp
Short Description
SMTP for SendGrid – YaySMTP
smtp-sendgrid
Send emails from WordPress through SendGrid using SMTP by YayCommerce
MailHawk — Simple SMTP, Email Delivery, and Email Logging
mailhawk
An easier SMTP service for WordPress. Improve your WordPress email deliverability!
MailHog for WordPress
wp-mailhog-smtp
Zero configuration MailHog plugin for your development machine.
Swift SMTP (formerly Welcome Email Editor) Developer Profile
10 plugins · 121K total installs
How We Detect Swift SMTP (formerly Welcome Email Editor)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/welcome-email-editor/modules/logs/css/email-logs-detail.cssHTML / DOM Fingerprints
weed_email_log_tableweed_email_log_view<!-- wp:paragraph --><!-- /wp:paragraph --><!-- wp:heading --><!-- /wp:heading -->+4 moredata-post-iddata-idweed_current_email_log/wp-json/weed/v1/email-logs