XOAuth Mailer For Google Workspace Wordpress Plugin - Rating, Reviews, Demo & Download
Plugin Description
XOAuth Mailer for Google Workspace replaces WordPress’s default PHP mail() with a reliable Google Workspace SMTP connection.
It is built for one job and kept deliberately small: it speaks Google’s XOAUTH2 SMTP mechanism directly on top of the PHPMailer that ships with WordPress, so there is no Composer dependency, no Google API client and no OAuth library bundled.
Features:
- Two authentication methods: App Password (quick setup) or OAuth2 (recommended for production)
- Full OAuth2 flow with automatic token refresh; your Google password is never stored
- OAuth callback on its own REST API route, so other plugins’ OAuth handlers can’t intercept it
- Live debug log with PHPMailer output
- Test email sender with one click
- Clean uninstall: removes all data on deletion
Why OAuth2 over App Password?
App Passwords are simpler to set up, but the App Password itself is stored in your database and works until you delete it in your Google account. With OAuth2 the plugin stores your OAuth Client ID and Secret plus a refresh token instead: your Google password is never used, access tokens expire after about an hour, and access can be revoked at any time from your Google account or from the plugin. That makes it the better choice for production sites.
You can keep the App Password or Client Secret out of the database entirely by defining them in wp-config.php:
define( 'XOAM_APP_PASSWORD', 'your-app-password' );
define( 'XOAM_CLIENT_SECRET', 'your-client-secret' );
External services
This plugin connects to Google services to deliver your site’s email. Nothing is sent until you configure the plugin.
Google SMTP server (smtp.gmail.com)
Used for every email WordPress sends once the plugin is configured. Sent: the full message (sender, recipients, subject, body, attachments), your Google account email address, and either your App Password or an OAuth2 access token.
Google OAuth 2.0 (accounts.google.com, oauth2.googleapis.com)
Used only when the OAuth2 method is selected.
- When you click “Connect Google Account”, your browser is sent to accounts.google.com with your Client ID and this site’s redirect URI.
- After you approve, the plugin sends the authorization code, Client ID and Client Secret to oauth2.googleapis.com to obtain tokens.
- When the access token expires (about every hour while emails are being sent), the plugin sends the refresh token, Client ID and Client Secret to oauth2.googleapis.com to get a new one.
- When you disconnect with “Also revoke access at Google” checked, the refresh token is sent to oauth2.googleapis.com/revoke.
These services are provided by Google: Terms of Service, Privacy Policy, Google API Services User Data Policy.
Screenshots
No screenshots provided
