
WP Mail SMTP by WPForms – The Most Popular SMTP and Email Log Plugin Security & Risk Analysis
wordpress.org/plugins/wp-mail-smtpMake email delivery easy for WordPress. Connect with SMTP, Gmail, Outlook, SendGrid, Mailgun, SES, Zoho, + more. Rated #1 WordPress SMTP Email plugin.
Is WP Mail SMTP by WPForms – The Most Popular SMTP and Email Log Plugin Safe to Use in 2026?
Generally Safe
Score 99/100WP Mail SMTP by WPForms – The Most Popular SMTP and Email Log Plugin has a strong security track record. Known vulnerabilities have been patched promptly.
The "wp-mail-smtp" v4.7.1 plugin demonstrates a generally good security posture with strong adherence to secure coding practices. The high percentage of prepared statements for SQL queries and properly escaped output are positive indicators. Nonce and capability checks are also utilized extensively, suggesting a solid defense against common WordPress attacks. The absence of critical or high-severity vulnerabilities in its history, and currently no unpatched CVEs, further bolster this assessment. The plugin also benefits from bundling the Guzzle library, which is a well-regarded HTTP client.
However, there are notable areas of concern that warrant attention. The static analysis revealed 3 AJAX handlers that lack authentication checks, presenting a potential attack surface for unauthorized actions. While taint analysis did not uncover critical or high-severity flows, the presence of one flow with unsanitized paths is a flag that requires investigation and remediation. The plugin's vulnerability history, while not critical, includes past issues related to storing passwords in a recoverable format and cross-site scripting, indicating a need for continuous vigilance and robust testing to prevent recurrence.
In conclusion, "wp-mail-smtp" v4.7.1 exhibits strengths in its implementation of secure coding standards and a commendable vulnerability history with no active critical threats. Nevertheless, the unprotected AJAX endpoints and the identified unsanitized path flow represent specific risks that need to be addressed to maintain a high level of security. Ongoing monitoring and prompt patching of any future vulnerabilities are crucial for this plugin.
Key Concerns
- Unprotected AJAX handlers
- Flows with unsanitized paths
- Past medium severity vulnerability
- Past low severity vulnerability
WP Mail SMTP by WPForms – The Most Popular SMTP and Email Log Plugin Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
WP Mail SMTP <= 4.0.1 - Authenticated (Admin+) SMTP Password Exposure
WP Mail SMTP by WPForms <= 1.3.3 - Unspecified Cross-Site Scripting
WP Mail SMTP by WPForms – The Most Popular SMTP and Email Log Plugin Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Mail SMTP by WPForms – The Most Popular SMTP and Email Log Plugin Attack Surface
AJAX Handlers 23
WordPress Hooks 121
Maintenance & Trust
WP Mail SMTP by WPForms – The Most Popular SMTP and Email Log Plugin Maintenance & Trust
Maintenance Signals
Community Trust
WP Mail SMTP by WPForms – The Most Popular SMTP and Email Log Plugin Alternatives
Easy WP SMTP – WordPress SMTP and Email Logs: Gmail, Office 365, Outlook, Custom SMTP, and more
easy-wp-smtp
Make SMTP email sending and delivery easy. Configure Gmail, Outlook, Brevo, SendGrid, Mailgun, SendLayer or connect to any SMTP server.
SureMail – SMTP and Email Logs Plugin with Amazon SES, Postmark, and Other Providers
suremails
SureMail – SMTP and Email Logs Plugin with Amazon SES, Postmark, and Other Providers
Alternate SMTP By Brainvire
alternate-smtp
Make email delivery easy for WordPress. Connect with SMTP, Gmail, Outlook, SendGrid, Mailgun, SES, Zoho, + more. Rated #1 WordPress SMTP Email plugin.
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App
post-smtp
Improve WordPress email deliverability. Connect Gmail SMTP, Microsoft 365, Brevo, SendGrid, Mailgun, Zoho, Amazon SES, etc. #1 WordPress SMTP Plugin.
Bit SMTP – Easy SMTP Solution with Email Logs
bit-smtp
Short Description
WP Mail SMTP by WPForms – The Most Popular SMTP and Email Log Plugin Developer Profile
94 plugins · 23.5M total installs
How We Detect WP Mail SMTP by WPForms – The Most Popular SMTP and Email Log Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-mail-smtp/assets/css/admin.css/wp-content/plugins/wp-mail-smtp/assets/js/admin.js/wp-content/plugins/wp-mail-smtp/assets/css/wp-mail-smtp-admin-bar.css/wp-content/plugins/wp-mail-smtp/assets/js/wp-mail-smtp-admin-bar.js/wp-content/plugins/wp-mail-smtp/assets/js/vendor/jquery/jquery.min.js/wp-content/plugins/wp-mail-smtp/assets/js/admin.js/wp-content/plugins/wp-mail-smtp/assets/js/wp-mail-smtp-admin-bar.jswp-mail-smtp/assets/css/admin.css?ver=wp-mail-smtp/assets/js/admin.js?ver=wp-mail-smtp/assets/css/wp-mail-smtp-admin-bar.css?ver=wp-mail-smtp/assets/js/wp-mail-smtp-admin-bar.js?ver=wp-mail-smtp/assets/js/vendor/jquery/jquery.min.js?ver=HTML / DOM Fingerprints
wp-mail-smtp-setting-field-wrapwp-mail-smtp-setting-fieldwp-mail-smtp-smtp-settingswp-mail-smtp-setting-field-labelwp-mail-smtp-setting-field-controlwp-mail-smtp-setting-field-togglewp-mail-smtp-setting-field-input-textwp-mail-smtp-setting-field-select<!-- WP Mail SMTP :: Settings --><!-- WP Mail SMTP :: License/Upgrade Box --><!-- WP Mail SMTP :: About Page --><!-- WP Mail SMTP :: Admin Bar Menu -->+1 moredata-error-messagedata-error-codedata-api-noncedata-test-email-noncewp_mail_smtp_adminwp_mail_smtp_admin_barwp_mail_smtp_mail_preview/wp-json/wp-mail-smtp/v1/settings/wp-json/wp-mail-smtp/v1/test-email/wp-json/wp-mail-smtp/v1/license/wp-json/wp-mail-smtp/v1/email-log