Plugin Pulse
← Pulse

Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App

by Saad Iqbal · Email & Marketing

Also makes 49 other plugins · 1.3M+ installs across the portfolio →

Improve WordPress email deliverability. Connect Gmail SMTP, Microsoft 365, Brevo, SendGrid, Mailgun, Zoho, Amazon SES, etc. #1 WordPress SMTP Plugin.

How scoring works →
93 Health · A
Maintenance 100/100
Rating quality 93/100
Support 81/100

93 health vs 63 average across 1,298 Email & Marketing plugins

Directory ranking optimization

How it's scored →

How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.

95 / 100

Excellent listing optimization

Well tuned across the board

Update recency 100/100
WP compatibility 100/100
Rating quality 93/100
Listing tuning 100/100
Support resolution 73/100

Daily downloads

Since 2022-10-05 · 1,421 days · wp.org + Plugin Pulse archive

-55% vs prior 30d
1.7KDownloads · Aug 26

30-day downloads

Rolling 30-day volume · peaks are release surges

56.8K

now · peak 943.5K

109.9K30d downloads · Aug 26

Directory rank vs rivals

wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you

Post SMTP · #162 you SureMail · #267 Bit SMTP · #4319 WP Mail SMTP by WPFo · #12

Rating trend

Star average over time · dips mark rough releases

4.7Stars · Aug 26

Update activity

How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.

366per 1k installs · Aug 26

Release cadence

Actively maintained
from wp.org release tags

How often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.

15

releases in the last 12 months

2mo ago

latest release · v3.9.5

177

tagged releases on record

Recent releases

3.9.5 · 2mo ago4.0.0-beta.1 · 3mo ago3.9.4 · 3mo ago3.9.3 · 3mo ago3.9.2 · 3mo ago3.9.1 · 5mo ago3.9.0 · 5mo ago3.8.0 · 7mo ago3.7.0 · 8mo ago3.6.3 · 8mo ago3.6.2 · 9mo ago3.6.1 · 10mo ago3.6.0 · 11mo ago3.5.0 · 11mo ago

What its installed base runs

via wordpress.org

Share of active installs on each version of this plugin. Green is the current release; a big slice on older versions is a user base that has stopped updating.

v3.9 62%
v3.6 5.8%
v2.9 5%
Older / other versions 27%

Estimated active installs

The public count shows “300K+”. Our estimate pins where the real number sits.

tracked estimate
300K–400K ≈340K

Refined from the date this plugin crossed into its current band.

Install history · since 2017-10-16 · 1,471 observations

300KInstalls · Aug 26

Estimated value

What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.

Est. annual revenue

N/A

Est. acquisition value

N/A

No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price. A declining trend compresses what a buyer would pay.

Details

Version
4.0.0-beta.1
Last updated
yesterday
Added
2017-10-15 · 8 yrs old
Requires WP
5.6.0
Tested up to
7.0.4
Requires PHP
7.1

Recent reviews

All reviews on wp.org ↗
  1. gregersen1
    1mo ago

    The built-in email log has saved me multiple times when troubleshooting delivery issues. Much better visibility than what I had before switching from another SMTP plugin.

    Read on wp.org ↗
  2. aliciaweston
    3mo ago

    I’m a bit of a beginner, and I have to update my PHP. The PHP checker told me that this wasn’t compatible with the latest version of PHP, which I thought was a bit odd because it had been updated only five days before; it didn’t seem like an abandoned plugin. I wrote to them, and they’ve been really helpful and said it’s fully compatible with all the latest versions of PHP. Very nice people, thank you very much for the support.

    Read on wp.org ↗
  3. decupe
    3mo ago

    It’s a fantastic plugin. I’ve replaced it on all my websites. The customer support is fast and very helpful, excellent service! I highly recommend it!

    Read on wp.org ↗
  4. franktastic300
    3mo ago

    20mb zipped file while others just are a fraction of this. Stay away from poorly coded plugins. This topic was modified 1 month, 3 weeks ago by franktastic300.

    Read on wp.org ↗
  5. jkejke
    3mo ago

    Dishonest about the cost of product. It’s free unless you have 365. Then it cost a yearly amount. They’re just fleecing people who they think will pay anyway.

    Read on wp.org ↗
  6. adamzea
    5mo ago

    As soon as activating the plug-in, it will scrape your email address from your WordPress installation user profile and start sending you emails & periodic newsletter spam without explicit permission. There is no “enter email address” field, no “subscribe” button, no “verify email address” button… it just automatically starts sending emails. Even if you don’t click the link in the verification email, other emails start arriving. If there was an explicit opt-in for that kind of thing it would be fine, but automatically doing it violates GDPR laws. This topic was modified 3 months, 2 weeks ago by adamzea.

    Read on wp.org ↗
  7. jcalmeida
    6mo ago

    Great Plugin easy to config and troubleshoot.

    Read on wp.org ↗
  8. AdamJB13
    6mo ago

    Aqib was very helpful in setting up PostSMTP on my site. The plug-in is working very well.

    Read on wp.org ↗

Latest updates

via wp.org changelog

Recent releases and news for this plugin

  1. Version 3.9.5 TWEAK – Updated dashboard banners and removed the Extensions screen from the plugin menu. 3.9.5
  2. Version 3.9.4 FIX – Resolved failed builds reported by Plugintests.com FIX – Addressed PHP deprecation notices related to using null as an array offset FIX – Fixed compatibility issues with the Google Site Kit plugin FIX – Resolved El 3.9.4
  3. Version 3.9.3 TWEAK – Rolled back to version 3.9.1 due to socket-related errors. 3.9.3
  4. Version 3.9.2 TWEAK – Added WordPress 7.0 compatibility. FIX – Addressed PHP deprecation notices related to using null as an array offset. FIX – Fixed compatibility issues with the Google Site Kit plugin. 3.9.2
  5. Version 3.9.1 TWEAK – Updated Emailit API to v2. FIX – Added Header support in Maileroo. FIX – Resolved qrstr class conflict. FIX – Emailit API status handling (status code 201 was incorrectly marked as failed instead of pending/succe 3.9.1
  6. Version 3.9.0 TWEAK – Updated the Setup Wizard UI for Mailers and improved related content. FIX – Resolved REST error: rest_cookie_invalid_nonce (Cookie check failed – 403). FIX – Added support for the pre_wp_mail function for custom 3.9.0

Known vulnerabilities

via Wordfence Intelligence

26 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.

  1. 2026-05-28 CVE-2026-48838 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.6.2 Patched in 3.6.3
  2. 2026-04-30 CVE-2024-13362 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.0.0 Patched in 3.1.0
  3. 2026-03-17 CVE-2026-2559 Missing Authorization Affects <= 3.8.0 Patched in 3.9.0
  4. 2026-03-17 CVE-2026-3090 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.8.0 Patched in 3.9.0
  5. 2025-12-03 CVE-2025-12887 Missing Authorization Affects <= 3.6.1 Patched in 3.6.2
  6. 2025-10-31 CVE-2025-11833 Missing Authorization Affects <= 3.6.0 Patched in 3.6.1
  7. 2025-09-02 CVE-2025-9219 Missing Authorization Affects <= 3.4.1 Patched in 3.4.2
  8. 2025-07-21 CVE-2025-24000 Missing Authorization Affects <= 3.2.0 Patched in 3.3.0
  9. 2025-03-07 CVE-2024-13844 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 3.1.2 Patched in 3.1.3
  10. 2025-02-17 CVE-2025-0521 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.0.2 Patched in 3.1.0
  11. 2025-01-07 CVE-2025-22800 Missing Authorization Affects <= 2.9.11 Patched in 2.9.12
  12. 2024-11-15 CVE-2024-52436 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 2.9.9 Patched in 2.9.10
  13. 2024-05-22 CVE-2024-5207 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 2.9.3 Patched in 2.9.4
  14. 2024-01-10 CVE-2023-6875 Authorization Bypass Through User-Controlled Key Affects <= 2.8.7 Patched in 2.8.8
  15. 2024-01-02 CVE-2023-6629 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.8.6 Patched in 2.8.7
  16. 2024-01-02 CVE-2023-7027 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.8.7 Patched in 2.8.8
  17. 2023-12-21 CVE-2023-6620 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 2.8.6 Patched in 2.8.7
  18. 2023-11-06 CVE-2023-5958 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.7.0 Patched in 2.7.1
  19. 2023-10-03 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 2.6.1 Patched in 2.6.1
  20. 2023-07-18 CVE-2023-33999 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects 2.1.2-beta.1 - 2.5.7 Patched in 2.5.9-beta.1
  21. 2023-07-11 CVE-2023-3082 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.5.7 Patched in 2.5.8
  22. 2023-06-26 CVE-2023-3179 Cross-Site Request Forgery (CSRF) Affects <= 2.5.6 Patched in 2.5.7
  23. 2023-06-26 CVE-2023-3178 Cross-Site Request Forgery (CSRF) Affects <= 2.5.6 Patched in 2.5.7
  24. 2022-09-05 CVE-2022-2352 Server-Side Request Forgery (SSRF) Affects <= 2.1.6 Patched in 2.1.7
  25. 2022-08-18 CVE-2022-2351 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.1.3 Patched in 2.1.4
  26. 2021-03-01 CVE-2021-4422 Cross-Site Request Forgery (CSRF) Affects <= 2.0.20 Patched in 2.0.21

Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.

CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.

Behavioral tests

via WP Hive

Automated install-time checks, tested on PHP 8.1.12 · WP 7.0.1

Low memory footprint
Low page-speed impact
Runs on latest PHP + WP
No PHP errors
No JS errors
Activates cleanly
No resource errors
No external HTTP errors
Optimized database use
Frequently updated

Languages

via translate.wordpress.org

Translated into 38 languages, 3 at 90% or more

Dutch 100%
Dutch (Formal) 100%
Portuguese (Brazil) 100%
Korean 85%
Spanish (Chile) 75%
Spanish (Spain) 73%
Swedish 63%
Russian 57%
German (Formal) 56%
German 55%
Chinese (Taiwan) 52%
English (UK) 50%
French (France) 49%
Danish 44%
Polish 44%
Spanish (Colombia) 37%
Spanish (Ecuador) 37%
Spanish (Venezuela) 37%
Japanese 35%
Romanian 35%
Italian 33%
Greek 32%
Latvian 31%
Chinese (China) 25%

Plus 14 more locales with partial translations.

Growth timeline

Install-tier crossings we have observed, and how long each tier took to outgrow

  1. 2026-04-25 400K+ → 300K+ down after 4 days in tier
  2. 2026-04-21 300K+ → 400K+ up after 1 days in tier
  3. 2026-04-20 400K+ → 300K+ down after 1 days in tier
  4. 2026-04-19 300K+ → 400K+ up after 2 days in tier
  5. 2026-04-17 400K+ → 300K+ down after 2 days in tier
  6. 2026-04-15 300K+ → 400K+ up after 1 days in tier
  7. 2026-04-14 400K+ → 300K+ down after 32 days in tier
  8. 2026-03-13 300K+ → 400K+ up after 4 days in tier

Competes with

The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).

Compare head to head →

Embed this report card

Drop a live Pulse card for Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App into a readme, a review or a deck. It updates itself.

<iframe src="https://plugins.wpmayor.com/embed/post-smtp" width="480" height="300" style="border:0" loading="lazy" title="Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App — Plugin Pulse"></iframe>
Preview card ↗

Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App: 300K+ active installs, 4.7★ (524 reviews). Plugin Pulse (WP Mayor), as of 2026-08-25. https://plugins.wpmayor.com/plugin/post-smtp