
eMail Domain Check Processor for Caldera Forms Security & Risk Analysis
wordpress.org/plugins/cf-email-domain-checkProcessor for Caldera Forms to check if the domain of the eMail given is most likely capable recieving eMails. Useful to aviod misusage or mistyped eM …
Is eMail Domain Check Processor for Caldera Forms Safe to Use in 2026?
Generally Safe
Score 85/100eMail Domain Check Processor for Caldera Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "cf-email-domain-check" plugin v1.1.0 presents a seemingly secure profile based on the provided static analysis. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the attack surface. Furthermore, the code analysis reveals no dangerous functions, file operations, or external HTTP requests, and all SQL queries utilize prepared statements, which are excellent security practices. The lack of any recorded vulnerabilities in its history is also a positive indicator of past security diligence.
However, the static analysis does highlight a critical weakness: 100% of the single output found is not properly escaped. This represents a significant risk, as unsanitized output can lead to Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the user's browser. While the attack surface is minimal, this single unescaped output presents a tangible threat that could be exploited if the plugin generates any visible output. The absence of nonce and capability checks, while not directly exploitable due to the limited attack surface, indicates a potential for future security gaps if new entry points are introduced without corresponding security measures.
In conclusion, while the plugin benefits from a very small attack surface and a clean vulnerability history, the unescaped output is a significant concern that requires immediate attention. The lack of security checks on potential entry points, although currently mitigated by their absence, suggests that future development should prioritize robust authentication and authorization mechanisms.
Key Concerns
- Unescaped output found
eMail Domain Check Processor for Caldera Forms Security Vulnerabilities
eMail Domain Check Processor for Caldera Forms Code Analysis
Output Escaping
eMail Domain Check Processor for Caldera Forms Attack Surface
WordPress Hooks 1
Maintenance & Trust
eMail Domain Check Processor for Caldera Forms Maintenance & Trust
Maintenance Signals
Community Trust
eMail Domain Check Processor for Caldera Forms Alternatives
Contact Form 7 Email Validation
email-domain-verification-in-cf7
Contact Form 7 Email Validation plugin adds an extended validation to verify domain in email address for email fields of Contact Form 7 plugin.
Gravity Forms Block Email Domains
gf-block-email-domains
Easily set a list of email domains to block on email fields in Gravity Forms.
Contact Form 7 – Blacklist Unwanted Email
block-email-cf7
This is a free add-on plugin for contact form 7, which validates the email field and restrict unwanted email submission as well as allowed only busine …
Email and Domain Blocker for WooCommerce
email-and-domain-blocker
Block emails or domains from WooCommerce signups. Supports wildcards, logging, CSV export, and test email checker.
User Domain Whitelist
user-domain-whitelist
The User Domain Whitelist/Blacklist plugin limits user registration to only registrants with an email address from the domain white list provided by t …
eMail Domain Check Processor for Caldera Forms Developer Profile
1 plugin · 10 total installs
How We Detect eMail Domain Check Processor for Caldera Forms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
data-field-iddata-field-typedata-field-requireddata-field-magicdata-field-label