
Block Disposable Email Security & Risk Analysis
wordpress.org/plugins/block-disposable-email-addressesThis plugin detects one-time email addresses (disposable email, trashmail, mailinator, 10minutemail) and helps to keep your userbase and comments clea …
Is Block Disposable Email Safe to Use in 2026?
Generally Safe
Score 85/100Block Disposable Email has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'block-disposable-email-addresses' plugin version 0.8 exhibits a mixed security posture. On the positive side, it demonstrates good practices by having a remarkably small attack surface with zero identified entry points (AJAX, REST API, shortcodes, cron events) and also utilizes prepared statements for all its SQL queries. The absence of known CVEs and a clean vulnerability history further suggests a generally well-maintained codebase in terms of disclosed vulnerabilities.
However, significant concerns arise from the static analysis. The most critical finding is that 100% of its five identified output points are not properly escaped. This represents a high risk for Cross-Site Scripting (XSS) vulnerabilities, where malicious code could be injected and executed in the user's browser. Additionally, while the taint analysis found no critical or high severity unsanitized paths, the presence of two flows with unsanitized paths, even if deemed of lower severity by the analysis, warrants attention. The lack of nonce and capability checks on its (albeit zero) entry points is a missed opportunity for defense-in-depth, though less critical given the absence of actual entry points.
In conclusion, while the plugin's small attack surface and SQL practices are commendable, the complete lack of output escaping is a major security flaw that exposes users to XSS attacks. The vulnerability history is clean, but this should not lull developers into a false sense of security, as the code analysis itself reveals significant potential weaknesses. Addressing the output escaping issue should be the absolute top priority.
Key Concerns
- 0% of output properly escaped
- 2 flows with unsanitized paths
- 0 nonce checks
- 0 capability checks
Block Disposable Email Security Vulnerabilities
Block Disposable Email Code Analysis
Output Escaping
Data Flow Analysis
Block Disposable Email Attack Surface
WordPress Hooks 7
Maintenance & Trust
Block Disposable Email Maintenance & Trust
Maintenance Signals
Community Trust
Block Disposable Email Alternatives
Email Blocklist
email-blocklist
Keep your WordPress site clean by blocking signups and comments from temporary or disposable email domains. 100% free, no paid APIs.
Temp Mail Detector – Block Temporary Emails
temp-mail-detector-block-temporary-emails
Detect and block temporary emails from registering on your website using the Temp Mail Detector plugin.
Akismet Anti-spam: Spam Protection
akismet
The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam solution for WordPress and WooCommerce.
Disable Comments – Remove Comments & Stop Spam [Multi-Site Support]
disable-comments
Allows administrators to globally disable comments on their site. Comments can be disabled according to post type. Multisite friendly.
Antispam Bee
antispam-bee
Sophisticated antispam plugin for effective daily comment and trackback spam-fighting. Built with data protection and privacy in mind.
Block Disposable Email Developer Profile
1 plugin · 10 total installs
How We Detect Block Disposable Email
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.