
Solid Mail – SMTP email and logging made by SolidWP Security & Risk Analysis
wordpress.org/plugins/wp-smtpEmail deliverability made SOLID. Connect to your chosen email provider with an intuitive set-it-and-forget-it SMTP plugin.
Is Solid Mail – SMTP email and logging made by SolidWP Safe to Use in 2026?
Generally Safe
Score 95/100Solid Mail – SMTP email and logging made by SolidWP has a strong security track record. Known vulnerabilities have been patched promptly.
The wp-smtp plugin, version 2.2.3, presents a mixed security posture. While it demonstrates good practices in several areas, notably with a high percentage of properly escaped outputs and the use of prepared statements for most SQL queries, significant concerns arise from its attack surface. The presence of two AJAX handlers without authentication checks represents a direct pathway for potential unauthorized actions or information disclosure if these handlers are exploitable. The plugin also bundles PHPMailer, which historically has been a target for vulnerabilities, although no specific outdated version is indicated here. The vulnerability history is a notable weakness, with two high-severity CVEs related to Cross-site Scripting and SQL Injection. Although currently unpatched vulnerabilities are reported as zero, the past occurrence of such critical types suggests potential for future issues if not diligently maintained. The lack of critical or high severity taint flows in static analysis is positive, but this must be weighed against the historical vulnerability data and the unprotected entry points.
Key Concerns
- Unprotected AJAX handlers
- 2 High severity CVEs historically
- Bundled PHPMailer
Solid Mail – SMTP email and logging made by SolidWP Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Solid Mail – SMTP email and logging made by SolidWP <= 2.1.5 - Unauthenticated Stored Cross-Site Scripting via Email
WP SMTP 1.2 - 1.2.6 - Authenticated (Admin+) SQL Injection
Solid Mail – SMTP email and logging made by SolidWP Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Solid Mail – SMTP email and logging made by SolidWP Attack Surface
AJAX Handlers 2
WordPress Hooks 21
Maintenance & Trust
Solid Mail – SMTP email and logging made by SolidWP Maintenance & Trust
Maintenance Signals
Community Trust
Solid Mail – SMTP email and logging made by SolidWP Alternatives
Comfort Email SMTP, Logger & Email Api
cbxwpemaillogger
This plugin helps to send email using SMTP and Email Api. It helps to log email and displays in admin panel and more.
WP Mail SMTP by WPForms – The Most Popular SMTP and Email Log Plugin
wp-mail-smtp
Make email delivery easy for WordPress. Connect with SMTP, Gmail, Outlook, SendGrid, Mailgun, SES, Zoho, + more. Rated #1 WordPress SMTP Email plugin.
Easy WP SMTP – WordPress SMTP and Email Logs: Gmail, Office 365, Outlook, Custom SMTP, and more
easy-wp-smtp
Make SMTP email sending and delivery easy. Configure Gmail, Outlook, Brevo, SendGrid, Mailgun, SendLayer or connect to any SMTP server.
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App
post-smtp
Improve WordPress email deliverability. Connect Gmail SMTP, Microsoft 365, Brevo, SendGrid, Mailgun, Zoho, Amazon SES, etc. #1 WordPress SMTP Plugin.
WP Mail Logging
wp-mail-logging
Log, view, and resend all emails sent from your WordPress site. Great for resolving email sending issues or keeping a copy for auditing.
Solid Mail – SMTP email and logging made by SolidWP Developer Profile
1 plugin · 70K total installs
How We Detect Solid Mail – SMTP email and logging made by SolidWP
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-smtp/assets/css/admin.css/wp-content/plugins/wp-smtp/assets/css/frontend.css/wp-content/plugins/wp-smtp/assets/js/admin.js/wp-content/plugins/wp-smtp/assets/js/frontend.js/wp-content/plugins/wp-smtp/assets/js/admin.js/wp-content/plugins/wp-smtp/assets/js/frontend.jswp-smtp/assets/css/admin.css?ver=wp-smtp/assets/css/frontend.css?ver=wp-smtp/assets/js/admin.js?ver=wp-smtp/assets/js/frontend.js?ver=HTML / DOM Fingerprints
wp-smtp-admin-wrapperPlugin was originally created by BoLiQuanshould we init solid 'solid_mail_settings' here?table should be deleted on uninstallingdata-solid-mail-connections-listwp_smtp_admin_params/solid-mail/v1/connections/solid-mail/v1/connections/(?P<id>[a-zA-Z0-9_-]+)