Great Plugin
Great Plugin easy to config and troubleshoot.
Great plugin, read the instructions 🙂
Excellent plugin. I didn’t read the instructions initially and had trouble getting it to work. If you are using Google Cloud and Gmail for smtp, you have to use their API. No worries, I read the instructions and they were spot on. SMTP team was worried I had issues and reached out to help. I told them what happen and all is good. Recommended!
How many vulnerabilities are you introducing with each release?
It seems with each release a new critical vulnerability. I’m guessing the vibe coding over there is going well… Colour me not impressed.
defmans7
November 20, 2025
|
1 reply
Steals your email address without asking, violates GDPR
As soon as activating the plug-in, it will scrape your email address from your Wordpress installation user profile and start sending you emails & periodic newsletter spam without explicit permission. There is no “enter email address” field, no “subscribe” button, no “verify email address” button… it just automatically starts sending emails. Even if you don’t click the link in the verification email, other emails start arriving. If there was an explicit opt-in for that kind of thing it would be fine, but automatically doing it violates GDPR laws.
Critical and high severity vulnerabilities over and over again
We’ve been using Post SMTP for years. Initially, we started with WP Mail SMTP, but the free version didn’t include logging, while Post SMTP did, and that occasionally came in handy. So we switched to Post SMTP across all our projects. About two years ago, several websites we manage were hacked due to a vulnerability in Post SMTP. Well, you could argue that maybe something like that can happen ONCE. But it already caused a serious loss of trust for us. Fortunately, we haven’t had any further breaches related to this plugin since then, but that’s only because we’ve been extremely cautious about updating it. However, over the past two years, the plugin has had FIVE high-severity and TWO critical vulnerabilities. That’s simply unacceptable for serious projects. After the latest “Unauthenticated Stored Cross-Site Scripting” issue, I’m done with this plugin for good, and we’re switching to WP Mail SMTP everywhere. I’ve already subscribed. I’d rather pay for a reliable and secure plugin than use a free one that keeps leaving the door wide open to attackers once or twice every year. After the last critical issue, I even opened a support request in November, where support claimed that “security remains an absolute top priority.” And now here we are again, 6 months later, with another “unauthenticated” vulnerability – even if it’s “just” XSS this time, and depends on stack and setup. That’s enough for me. It feels like nothing has really changed. This is not a serious plugin, and it should NOT be used for serious projects. I’ve never left a one-star rating before, but this time I had to. Just take a look at the vulnerabilities of Post SMTP on Wordfence Vulnerability Database, their severity, and how often they occur. And compare it with something else, like WP Mail SMTP. We’re moving on and not looking back. Goodbye Post SMTP, hello paid WP Mail SMTP.If you still decide to stick with this plugin, only use it with auto-updates enabled.
Excellent support for a great plugin
After purchasing PostSMTP Pro and facing some incompatibility issues with other plugins I asked for help and I was impressed by the awesome and rapid support given by M Aqib Khan to solve the issue.Great thanks! Just as an information for people who are using AIOS Security and Firewall : the Open Email Tracking needs the option “Advanced Character String Filter” to be disabled (AIOS => Firewall => PHP rules => String filtering). I highly recommend this plugin.
Excellent support for a great plugin
After purchasing PostSMTP Pro and facing some incompatibility issues with other plugins I asked for help and I was impressed by the awesome and rapid support given by M Aqib Khan to solve the issue.Great thanks! Just as an information for people who are using AIOS Security and Firewall : the Open Email Tracking needs the option “Advanced Character String Filter” to be disabled (AIOS => Firewall => PHP rules => String filtering). I highly recommend this plugin.
Great Plugin
Great Plugin easy to config and troubleshoot.
Great Support for the setup of PostSMTP
Aqib was very helpful in setting up PostSMTP on my site. The plug-in is working very well.
Steals your email address without asking, violates GDPR
As soon as activating the plug-in, it will scrape your email address from your Wordpress installation user profile and start sending you emails & periodic newsletter spam without explicit permission. There is no “enter email address” field, no “subscribe” button, no “verify email address” button… it just automatically starts sending emails. Even if you don’t click the link in the verification email, other emails start arriving. If there was an explicit opt-in for that kind of thing it would be fine, but automatically doing it violates GDPR laws.
Critical and high severity vulnerabilities over and over again
We’ve been using Post SMTP for years. Initially, we started with WP Mail SMTP, but the free version didn’t include logging, while Post SMTP did, and that occasionally came in handy. So we switched to Post SMTP across all our projects. About two years ago, several websites we manage were hacked due to a vulnerability in Post SMTP. Well, you could argue that maybe something like that can happen ONCE. But it already caused a serious loss of trust for us. Fortunately, we haven’t had any further breaches related to this plugin since then, but that’s only because we’ve been extremely cautious about updating it. However, over the past two years, the plugin has had FIVE high-severity and TWO critical vulnerabilities. That’s simply unacceptable for serious projects. After the latest “Unauthenticated Stored Cross-Site Scripting” issue, I’m done with this plugin for good, and we’re switching to WP Mail SMTP everywhere. I’ve already subscribed. I’d rather pay for a reliable and secure plugin than use a free one that keeps leaving the door wide open to attackers once or twice every year. After the last critical issue, I even opened a support request in November, where support claimed that “security remains an absolute top priority.” And now here we are again, 6 months later, with another “unauthenticated” vulnerability – even if it’s “just” XSS this time, and depends on stack and setup. That’s enough for me. It feels like nothing has really changed. This is not a serious plugin, and it should NOT be used for serious projects. I’ve never left a one-star rating before, but this time I had to. Just take a look at the vulnerabilities of Post SMTP on Wordfence Vulnerability Database, their severity, and how often they occur. And compare it with something else, like WP Mail SMTP. We’re moving on and not looking back. Goodbye Post SMTP, hello paid WP Mail SMTP.If you still decide to stick with this plugin, only use it with auto-updates enabled.
How many vulnerabilities are you introducing with each release?
It seems with each release a new critical vulnerability. I’m guessing the vibe coding over there is going well… Colour me not impressed.
defmans7
November 20, 2025
|
1 reply