
Anti Spam and list cleaner – AcyChecker Security & Risk Analysis
wordpress.org/plugins/acycheckerBlock fake accounts and delete users using a fake email address
Is Anti Spam and list cleaner – AcyChecker Safe to Use in 2026?
Generally Safe
Score 100/100Anti Spam and list cleaner – AcyChecker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The acychecker v1.8.1 plugin exhibits a mixed security posture. On the positive side, it demonstrates a commendable lack of known historical vulnerabilities and a robust approach to its attack surface, with no exposed AJAX handlers, REST API routes, shortcodes, or cron events that lack authentication or permission checks. The use of prepared statements for a high percentage of SQL queries and the presence of nonce checks further indicate good security practices.
However, there are significant concerns within the code analysis. The presence of the `unserialize` function is a critical risk, as it can lead to Remote Code Execution if an attacker can control the serialized data passed to it. Furthermore, a very low percentage (21%) of output is properly escaped, meaning there's a high likelihood of Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is displayed without adequate sanitization. The plugin also performs file operations and external HTTP requests, which, combined with the lack of input validation suggested by the low output escaping rate, could potentially be exploited.
Given the absence of historical CVEs, the plugin's track record appears clean, suggesting a diligent development approach in the past. Nevertheless, the static analysis reveals critical potential vulnerabilities in the current version. The main strengths lie in its well-defined attack surface and SQL query handling, while its weaknesses are the presence of `unserialize` and the severely insufficient output escaping, which significantly elevate the risk profile.
Key Concerns
- Dangerous function: unserialize found
- Low output escaping percentage (21%)
- 0 capability checks found
Anti Spam and list cleaner – AcyChecker Security Vulnerabilities
Anti Spam and list cleaner – AcyChecker Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Anti Spam and list cleaner – AcyChecker Attack Surface
WordPress Hooks 10
Maintenance & Trust
Anti Spam and list cleaner – AcyChecker Maintenance & Trust
Maintenance Signals
Community Trust
Anti Spam and list cleaner – AcyChecker Alternatives
Reoon Email Verifier
reoon-email-verifier
Safeguard your online forms against invalid, temporary, disposable, and harmful email addresses with real-time verification.
DeBounce Email Validator
debounce-io-email-validator
Real-time email validation for WordPress forms. Block invalid, disposable, and risky emails to keep your database clean and improve deliverability.
Email and Domain Blocker for WooCommerce
email-and-domain-blocker
Block emails or domains from WooCommerce signups. Supports wildcards, logging, CSV export, and test email checker.
Blacklist Unwanted Email – Formidable Forms
block-email-formidable-form
This is a free add-on plugin for Formidable Forms , which validates the email field and restrict unwanted email submission as well as allowed only bus …
Spam Email Domain Exclusion for CF7
spam-email-domain-exclusion-cf7
Spam Email Domain Exclusion for CF7 provides a seamless solution to block submissions from specific email domains.
Anti Spam and list cleaner – AcyChecker Developer Profile
20 plugins · 8K total installs
How We Detect Anti Spam and list cleaner – AcyChecker
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/acychecker/assets/css/style.css/wp-content/plugins/acychecker/assets/js/script.js/wp-content/plugins/acychecker/assets/js/script.jsacychecker/style.css?ver=script.js?ver=HTML / DOM Fingerprints
acychecker-noticedata-acychecker-admin-urlACYC_AJAX_URLACYC_IS_ADMIN