
WP Mail Gateway Security & Risk Analysis
wordpress.org/plugins/wp-mail-gatewaySend email from your Wordpress site via SMTP and other 3rd party mail gateway provider. Current it supports Amazon SES, Mailgun, Mandrill, Mailjet, Po …
Is WP Mail Gateway Safe to Use in 2026?
Generally Safe
Score 85/100WP Mail Gateway has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-mail-gateway v1.8 plugin exhibits a mixed security posture. On the positive side, it shows good practices with 100% of its SQL queries using prepared statements and no recorded vulnerabilities in its history. However, there are significant concerns arising from the static analysis. The plugin has a small but entirely unprotected attack surface with three AJAX handlers lacking any authentication or capability checks. Furthermore, the presence of the `unserialize` function without any apparent sanitization or context, coupled with only 50% of outputs being properly escaped, raises red flags for potential code injection and cross-site scripting (XSS) vulnerabilities. The lack of nonce checks on AJAX handlers is a critical oversight that could allow attackers to trigger actions on behalf of authenticated users.
Key Concerns
- 3 AJAX handlers without auth checks
- Use of unserialize() without checks
- 50% of outputs not properly escaped
- 0 Nonce checks
- 0 Capability checks
WP Mail Gateway Security Vulnerabilities
WP Mail Gateway Code Analysis
Dangerous Functions Found
Bundled Libraries
Output Escaping
WP Mail Gateway Attack Surface
AJAX Handlers 3
WordPress Hooks 5
Maintenance & Trust
WP Mail Gateway Maintenance & Trust
Maintenance Signals
Community Trust
WP Mail Gateway Alternatives
Send Emails with Mandrill
send-emails-with-mandrill
'Send Emails with Mandrill' sends emails that are generated by WordPress through Mandrill, a transactional email service powered by MailChimp.
BLAZING Email Transfer Payment Gateway
woocommerce-email-money-transfer-gateway
Many customers in Canada prefer to pay for the merchandise they buy, by e-Transfer (formerly Email Money Transfer).
Contact Form 7 to Mailjet
cf7-to-mailjet
Link Contact Form 7 with Mailjet contact list
Freshjet
freshjet
Send email through wp_mail() but super-powered by Mailjet transactional email. This plugin is probably the most convenient way to use Mailjet transact …
Surbma | SMTP
surbma-smtp
External SMTP mail configuration via global variables in wp-config.php.
WP Mail Gateway Developer Profile
5 plugins · 470 total installs
How We Detect WP Mail Gateway
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-mail-gateway/assets/css/bootstrap-wmg.css/wp-content/plugins/wp-mail-gateway/assets/css/sweetalert2.min.css/wp-content/plugins/wp-mail-gateway/assets/css/main.css/wp-content/plugins/wp-mail-gateway/assets/js/popper.min.js/wp-content/plugins/wp-mail-gateway/assets/js/bootstrap.min.js/wp-content/plugins/wp-mail-gateway/assets/js/sweetalert2.min.js/wp-content/plugins/wp-mail-gateway/assets/js/main.js/wp-content/plugins/wp-mail-gateway/assets/js/popper.min.js/wp-content/plugins/wp-mail-gateway/assets/js/bootstrap.min.js/wp-content/plugins/wp-mail-gateway/assets/js/sweetalert2.min.js/wp-content/plugins/wp-mail-gateway/assets/js/main.jswp-mail-gateway/assets/css/bootstrap-wmg.css?ver=wp-mail-gateway/assets/css/sweetalert2.min.css?ver=wp-mail-gateway/assets/css/main.css?ver=wp-mail-gateway/assets/js/popper.min.js?ver=wp-mail-gateway/assets/js/bootstrap.min.js?ver=wp-mail-gateway/assets/js/sweetalert2.min.js?ver=wp-mail-gateway/assets/js/main.js?ver=HTML / DOM Fingerprints
wmgwp-mail-gateway-plugin-adminpagedata-target="#mailgunModal"data-target="#mailjetModal"data-target="#awsSesModal"data-target="#mandrillModal"data-target="#postmarkModal"data-target="#sendgridModal"+1 morewindow.wp_mail_gateway_admin_data