Title: Suremail Vulnerabilities
Last modified: September 16, 2026

---

# Suremail Vulnerabilities

 *  [bloggista](https://wordpress.org/support/users/bloggista/)
 * (@bloggista)
 * [2 weeks, 1 day ago](https://wordpress.org/support/topic/suremail-vulnerabilities/)
 * My malware scanner flagged these two files as risky and suspicious:
    - wp-content/uploads/suremails/index.php
    - wp-content/uploads/suremails/attachments/index.php
 * Please advise.

Viewing 1 replies (of 1 total)

 *  Plugin Support [bsfsubin](https://wordpress.org/support/users/bsfsubin/)
 * (@bsfsubin)
 * [2 weeks, 1 day ago](https://wordpress.org/support/topic/suremail-vulnerabilities/#post-19021193)
 * Thanks for flagging this, good news, these two files are not malware, they’re
   created intentionally by SureMail itself as a security measure.
   When SureMail
   sets up its uploads folder (`wp-content/uploads/suremails/` and the `attachments/`
   subfolder, where email attachments are temporarily stored), it adds a small `
   index.php` file containing:
 * <?php // Silence is golden. http_response_code( 403 ); exit;
 * This is a standard WordPress hardening technique used by many plugins to block
   directory listing and prevent direct access to files in that folder. It doesn’t
   execute any user input and has no functionality beyond returning a 403. Alongside
   it, SureMail also drops `.htaccess`, `.user.ini`, and (on IIS) `web.config` files
   in the same folders for the same reason, extra layers of protection around your
   attachments.
   Most malware scanners flag _any_ PHP file inside `wp-content/uploads/`
   by default, since that directory is a common target for malicious uploads, but
   they typically don’t inspect the actual file content before flagging. If you 
   open the file and see just the snippet above, it’s safe and expected.If your 
   scanner lets you whitelist specific files/paths, you can safely exclude these
   two. Let us know if you have any other questions!

Viewing 1 replies (of 1 total)

You must be [logged in](https://login.wordpress.org/?redirect_to=https%3A%2F%2Fwordpress.org%2Fsupport%2Ftopic%2Fsuremail-vulnerabilities%2F%3Foutput_format%3Dmd&locale=en_US)
to reply to this topic.

 * ![](https://ps.w.org/suremails/assets/icon-256x256.gif?rev=3235320)
 * [SureMail – SMTP and Email Logs Plugin with Amazon SES, Postmark, and Other Providers](https://wordpress.org/plugins/suremails/)
 * [Frequently Asked Questions](https://wordpress.org/plugins/suremails/#faq)
 * [Support Threads](https://wordpress.org/support/plugin/suremails/)
 * [Active Topics](https://wordpress.org/support/plugin/suremails/active/)
 * [Unresolved Topics](https://wordpress.org/support/plugin/suremails/unresolved/)
 * [Reviews](https://wordpress.org/support/plugin/suremails/reviews/)

 * 1 reply
 * 2 participants
 * Last reply from: [bsfsubin](https://wordpress.org/support/users/bsfsubin/)
 * Last activity: [2 weeks, 1 day ago](https://wordpress.org/support/topic/suremail-vulnerabilities/#post-19021193)
 * Status: not resolved