WordSMTP Simple SMTP Solution Security & Risk Analysis

wordpress.org/plugins/wordsmtp

WordSMTP Simple SMTP Solution mailer. Easy & simple setup. All your WordPress / WooCommerce sending emails will be used your verified domain name.

0 active installs v1.1.0 PHP 7.3+ WP 5.5+ Updated Apr 24, 2025
custom-domain-mailer-solutionemail-solution-for-woocommercesend-emails-from-own-domainsmtpsmtp-email-solution
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WordSMTP Simple SMTP Solution Safe to Use in 2026?

Generally Safe

Score 92/100

WordSMTP Simple SMTP Solution has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The 'wordsmtp' plugin v1.1.0 exhibits a strong security posture based on the provided static analysis. The complete absence of critical or high severity taint flows, coupled with the fact that all SQL queries utilize prepared statements, indicates good development practices for handling sensitive operations. Furthermore, the plugin demonstrates a commitment to security by implementing nonce and capability checks for its identified entry points, effectively mitigating common attack vectors. The low percentage of unescaped output (6%) is also a positive sign, although it's worth noting that even a small percentage can present a risk.

The vulnerability history is exceptionally clean, with no recorded CVEs. This suggests a history of responsible development and prompt patching of any past security issues, contributing to its current stability. The plugin's attack surface is minimal, with only one AJAX handler and no REST API routes, shortcodes, or cron events, further reducing potential exposure. The bundling of the DataTables library, while common, is a minor point to monitor for potential vulnerabilities in the library itself, although none are indicated here.

Overall, 'wordsmtp' v1.1.0 appears to be a securely developed plugin. Its strengths lie in its minimal attack surface, robust handling of database queries, and strong use of security checks. The lack of any past or present vulnerabilities is highly reassuring. The primary area for slight improvement would be to eliminate the remaining unescaped outputs to achieve a perfect score in that category.

Key Concerns

  • Unescaped output detected
Vulnerabilities
None known

WordSMTP Simple SMTP Solution Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

WordSMTP Simple SMTP Solution Release Timeline

v1.1.0Current
v1.0.0
Code Analysis
Analyzed Apr 16, 2026

WordSMTP Simple SMTP Solution Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
4
64 escaped
Nonce Checks
1
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

DataTables

SQL Query Safety

100% prepared4 total queries

Output Escaping

94% escaped68 total outputs
Attack Surface

WordSMTP Simple SMTP Solution Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_sc_wordsmtp_test_emailincludes/sc-wordsmtp-ajaxhandler.class.php:40
WordPress Hooks 12
actionadmin_enqueue_scriptsincludes/sc-wordsmtp-ajaxhandler.class.php:39
actionphpmailer_initincludes/sc-wordsmtp-ajaxhandler.class.php:41
actionwp_mail_failedincludes/sc-wordsmtp-ajaxhandler.class.php:42
actionwp_mail_succeededincludes/sc-wordsmtp-ajaxhandler.class.php:43
filterwp_mail_fromincludes/sc-wordsmtp-ajaxhandler.class.php:45
filterwp_mail_from_nameincludes/sc-wordsmtp-ajaxhandler.class.php:46
filterwp_mail_content_typeincludes/sc-wordsmtp-ajaxhandler.class.php:47
actionadmin_initincludes/sc-wordsmtp.class.php:21
actionadmin_menuincludes/sc-wordsmtp.class.php:22
actionadmin_noticesincludes/sc-wordsmtp.class.php:23
actionplugins_loadedincludes/sc-wordsmtp.class.php:24
filterplugin_row_metaincludes/sc-wordsmtp.class.php:25
Maintenance & Trust

WordSMTP Simple SMTP Solution Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedApr 24, 2025
PHP min version7.3
Downloads655

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

WordSMTP Simple SMTP Solution Developer Profile

softcoy

4 plugins · 30 total installs

90
trust score
Avg Security Score
94/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WordSMTP Simple SMTP Solution

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wordsmtp/public/images/test-email.gif/wp-content/plugins/wordsmtp/admin/css/dataTables.css/wp-content/plugins/wordsmtp/admin/css/fontawesome-all.min.css/wp-content/plugins/wordsmtp/admin/css/jquery-ui.css/wp-content/plugins/wordsmtp/admin/css/sc-wordsmtp-misc-styles.css/wp-content/plugins/wordsmtp/admin/js/dataTables.js/wp-content/plugins/wordsmtp/admin/js/sc-wordsmtp-misc-script.js
Script Paths
/wp-content/plugins/wordsmtp/admin/js/dataTables.js/wp-content/plugins/wordsmtp/admin/js/sc-wordsmtp-misc-script.js
Version Parameters
sc-wordsmtp-datatable-style?ver=sc-wordsmtp-fontawesome?ver=sc-wordsmtp-jquery-ui-style?ver=sc-wordsmtp-style?ver=sc-wordsmtp-datatable-script?ver=sc-wordsmtp-misc-script?ver=

HTML / DOM Fingerprints

CSS Classes
sc-wordsmtp-settings
HTML Comments
<!-- WordSMTP Simple SMTP Solution --><!-- Copyright 2023 softcoy.com --><!-- WordSMTP settings --><!-- WordSMTP - Testing Email -->+39 more
Data Attributes
data-wordsmtp-noncedata-wordsmtp-action
JS Globals
sc_wordsmtp_metabox_script_obj
REST Endpoints
/wp-json/wordsmtp/v1/send_test_email
FAQ

Frequently Asked Questions about WordSMTP Simple SMTP Solution