
WP Gmail SMTP Security & Risk Analysis
wordpress.org/plugins/wp-gmail-smtpWith WP Gmail SMTP plugin you can connect Gmail to your WordPress website for sending emails. It bypasses the normal WP mail function and sends email …
Is WP Gmail SMTP Safe to Use in 2026?
High Risk
Score 41/100WP Gmail SMTP carries significant security risk with 2 known CVEs, 2 still unpatched. Consider switching to a maintained alternative.
The wp-gmail-smtp plugin exhibits a mixed security posture. While the static analysis shows a good practice in not exposing a significant attack surface through AJAX, REST API, shortcodes, or cron events, and SQL queries are properly prepared, there are notable concerns. The plugin's reliance on external HTTP requests and the presence of a nonce check are positive, but the complete absence of capability checks is a significant weakness. Furthermore, only 73% of output is properly escaped, leaving potential for cross-site scripting vulnerabilities. The vulnerability history is concerning, with two known medium-severity CVEs, both of which are currently unpatched. The historical presence of CSRF and sensitive information exposure vulnerabilities suggests a pattern of weaknesses in input validation and state management. The plugin's strengths lie in its limited attack surface and secure SQL practices, but the unpatched vulnerabilities and lack of robust authorization checks present a substantial risk.
Key Concerns
- 2 unpatched medium severity CVEs
- Missing capability checks
- 27% of output is not properly escaped
- External HTTP requests (potential for SSRF/MITM)
WP Gmail SMTP Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Gmail SMTP <= 1.0.7 - Cross-Site Request Forgery
WP Gmail SMTP <= 1.0.7 - Sensitive Information Exposure
WP Gmail SMTP Code Analysis
Output Escaping
WP Gmail SMTP Attack Surface
WordPress Hooks 8
Maintenance & Trust
WP Gmail SMTP Maintenance & Trust
Maintenance Signals
Community Trust
WP Gmail SMTP Alternatives
GoSMTP – SMTP for WordPress
gosmtp
Send emails from your WordPress site using your preferred SMTP provider like Gmail, Outlook, AWS, Zoho, SMTP.com, Brevo (formerly Sendinblue), Mailgun …
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App
post-smtp
Improve WordPress email deliverability. Connect Gmail SMTP, Microsoft 365, Brevo, SendGrid, Mailgun, Zoho, Amazon SES, etc. #1 WordPress SMTP Plugin.
SureMail – SMTP and Email Logs Plugin with Amazon SES, Postmark, and Other Providers
suremails
SureMail – SMTP and Email Logs Plugin with Amazon SES, Postmark, and Other Providers
WP Offload SES Lite
wp-ses
Fix your email delivery problems by sending your WordPress emails through Amazon SES's powerful email sending infrastructure.
YaySMTP and Email Logs: Amazon SES, SendGrid, Outlook, Mailgun, Brevo, Google and Any SMTP Service
yaysmtp
Send WordPress emails successfully with WP Mail SMTP via your favorite mailer
WP Gmail SMTP Developer Profile
5 plugins · 3K total installs
How We Detect WP Gmail SMTP
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-gmail-smtp/assets/js/main.js/wp-content/plugins/wp-gmail-smtp/assets/css/style.css/wp-content/plugins/wp-gmail-smtp/assets/js/main.jswp-gmail-smtp/assets/js/main.js?ver=wp-gmail-smtp/assets/css/style.css?ver=