A small SMTP plugin that does three things and nothing else: it sends your mail
over SMTP, it writes down what happened, and it tells a webhook when a message
fails.
We built it because the SMTP plugin we had relied on for years kept growing.
More features, more integrations, more settings — most of which we simply
didn’t need. Eventually, that added complexity started causing problems on
production sites.
Many alternatives had gone the same way: email logs behind paid tiers, API
providers, OAuth flows, deliverability dashboards, upgrade banners, and entire
mail suites around what should be a simple job.
We wanted the opposite: connect to a mail server, send the email, log the
result, and stay out of the way.
Email is critical infrastructure. Every additional feature is another dependency
and another potential failure point — and when mail breaks, customers notice
immediately.
So we built the slim alternative we wanted ourselves, and we run it in our own
production environment and on our client sites.
What it does
wp_mail() call over your SMTP server — WooCommerce, contactdocker-compose passed in.What it deliberately does not do
No API providers, no OAuth, no fallback connections, no deliverability score, no
dashboard widget, no newsletter integration, no pro tier, no advertising for
one, and no upsell notices. If you need those, one of the big plugins will serve
you better, and that is a fine outcome.
Safety rails
mail() — installing it cannot take your emailEvery setting can be defined as a constant in wp-config.php, following
one mechanical rule: the option name in upper case. That keeps credentials out
of the database and out of any dump copied to a staging site, and lets a Docker
container pass them in as environment variables:
define( ‘WONDERFUL_SMTP_MAILER_AND_LOG_HOST’, getenv( ‘SMTP_HOST’ ) );
define( ‘WONDERFUL_SMTP_MAILER_AND_LOG_PASSWORD’, getenv( ‘SMTP_PASSWORD’ ) );
A defined constant wins over the settings field, and the field is then shown
read-only so the two cannot silently disagree.
wp_mail() keeps reporting success — and theHow it is built
Development is test driven, and the suite covers the behaviour that decides
whether your mail actually leaves the building: that an unconfigured plugin keeps
its hands off PHPMailer entirely, that “none” really disables TLS instead of
quietly upgrading, that a sender another plugin set on purpose survives, that a
corrupt delivery-mode value falls back to sending rather than silently swallowing
your mail, that log-only mode never once reaches the mailer, that the retention
purge deletes what is past the cutoff and nothing else, and that a webhook fires
with the failure details but no credentials.
Those tests run together with the WordPress coding standards, a PHP 7.4
compatibility lint and WordPress.org’s own Plugin Check every single time, before
a release is built at all. An error in any of them stops the release — the
pipeline refuses, it is not a checklist someone waves through.
The tests themselves stay in the repository and are not part of this download.
Nothing ships here that your site does not need at runtime: a small set of PHP
classes and four assets, with no vendor directory and no framework.
That discipline is also why the feature list is short. Every feature is a promise
that has to keep working.
This plugin contacts two kinds of external endpoints, both of which you
configure yourself. It has no vendor backend, sends no telemetry, and phones
home nowhere.
1. Your SMTP server
The host you enter in the settings receives your outgoing messages: sender,
recipients, subject, body, attachments, and — if authentication is enabled — the
username and password you configured. This is the entire purpose of the plugin.
Which company that server belongs to, and which terms and privacy policy apply,
is determined by you when you enter the host name. No connection is made until
you configure one.
2. Your failure webhook (optional, off by default)
If, and only if, you fill in the webhook field, a JSON request of the form
{“text”: “…”} is sent to that URL whenever a message fails. It contains your
site URL, the recipient address, the subject and the error the mail server
returned. It contains no message body and no credentials. Nothing is sent while
the field is empty. The receiving service is one you choose — Zapier, n8n, Make,
Slack or your own endpoint — and its terms and privacy policy apply to what you
send it.
Message contents and log entries stay in your own database. No data is
transmitted to Wonderful Plugins.