Clearout Email Validator – Real-Time Email Verification on WordPress Forms Security & Risk Analysis

wordpress.org/plugins/clearout-email-validator

Block invalid emails like temporary, disposable, etc. with our real-time email verification. Verify email address during form-fill and stop form spam.

600 active installs v3.3.1 PHP + WP 4.6+ Updated Feb 18, 2026
email-checkeremail-validationemail-verificationemail-verifierwoocommerce
99
A · Safe
CVEs total1
Unpatched0
Last CVEMar 27, 2025
Download
Safety Verdict

Is Clearout Email Validator – Real-Time Email Verification on WordPress Forms Safe to Use in 2026?

Generally Safe

Score 99/100

Clearout Email Validator – Real-Time Email Verification on WordPress Forms has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Mar 27, 2025Updated 1mo ago
Risk Assessment

The "clearout-email-validator" v3.3.1 plugin presents a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for SQL queries and not performing file operations or bundling external libraries. The absence of critical or high-severity taint flows and the fact that all known vulnerabilities are patched are encouraging signs.

However, there are significant concerns. The plugin exposes one AJAX handler without any authentication checks, creating a direct attack vector. While the static analysis shows a low number of total entry points, this single unprotected entry point is a critical weakness. Furthermore, only 70% of output is properly escaped, indicating a potential for cross-site scripting (XSS) vulnerabilities, especially given the plugin's history of XSS-related CVEs.

The historical vulnerability data, while currently unpatched, shows a past medium-severity XSS vulnerability. This pattern suggests that input sanitization and output escaping should be a primary focus for this plugin. The current version addresses past vulnerabilities, but the lingering concern around unescaped output in the static analysis warrants attention. Overall, the plugin has strengths in its SQL handling and vulnerability patching but is weakened by an unprotected AJAX endpoint and a concerning rate of unescaped output.

Key Concerns

  • AJAX handler without authentication
  • Unescaped output (30% of outputs)
  • Past medium severity vulnerability
Vulnerabilities
1

Clearout Email Validator – Real-Time Email Verification on WordPress Forms Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-30789medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Clearout Email Validator <= 3.2.0 - Authenticated (Administrator+) Stored Cross-Site Scripting

Mar 27, 2025 Patched in 3.2.1 (7d)
Code Analysis
Analyzed Mar 16, 2026

Clearout Email Validator – Real-Time Email Verification on WordPress Forms Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
16
37 escaped
Nonce Checks
2
Capability Checks
2
File Operations
0
External Requests
5
Bundled Libraries
0

Output Escaping

70% escaped53 total outputs
Data Flows
All sanitized

Data Flow Analysis

1 flows
<clearout-validator> (src\clearout-validator.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Clearout Email Validator – Real-Time Email Verification on WordPress Forms Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_co_test_plugin_setting_actionsrc\clearout-plugin.php:11
WordPress Hooks 25
actionadmin_menusrc\clearout-plugin.php:9
actionadmin_noticessrc\clearout-plugin.php:10
actionadmin_initsrc\clearout-plugin.php:12
actionupdate_option_clearout_email_validatorsrc\clearout-plugin.php:13
actionadmin_initsrc\clearout-plugin.php:14
filterwpcf7_validate_emailsrc\clearout-plugin.php:22
filterwpcf7_validate_email*src\clearout-plugin.php:23
actionfrm_validate_entrysrc\clearout-plugin.php:28
filtercntctfrm_check_formsrc\clearout-plugin.php:33
filterninja_forms_submit_datasrc\clearout-plugin.php:38
filtergform_field_validationsrc\clearout-plugin.php:43
actionregistration_errorssrc\clearout-plugin.php:48
actionpre_comment_on_postsrc\clearout-plugin.php:53
actioncomment_postsrc\clearout-plugin.php:54
filterwpforms_process_beforesrc\clearout-plugin.php:59
filteris_emailsrc\clearout-plugin.php:64
filtermailster_verify_subscribersrc\clearout-plugin.php:69
filterwoocommerce_after_checkout_validationsrc\clearout-plugin.php:74
filterpmpro_registration_checkssrc\clearout-plugin.php:79
actionelementor_pro/forms/validation/emailsrc\clearout-plugin.php:84
filterfluentform_validate_input_item_input_emailsrc\clearout-plugin.php:89
filterwsf_action_email_email_validatesrc\clearout-plugin.php:94
filterforminator_custom_form_submit_errorssrc\clearout-plugin.php:99
actionwoocommerce_register_postsrc\clearout-plugin.php:105
filteris_emailsrc\clearout-plugin.php:112
Maintenance & Trust

Clearout Email Validator – Real-Time Email Verification on WordPress Forms Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 18, 2026
PHP min version
Downloads32K

Community Trust

Rating84/100
Number of ratings13
Active installs600
Developer Profile

Clearout Email Validator – Real-Time Email Verification on WordPress Forms Developer Profile

clearoutio

1 plugin · 600 total installs

99
trust score
Avg Security Score
99/100
Avg Patch Time
7 days
View full developer profile
Detection Fingerprints

How We Detect Clearout Email Validator – Real-Time Email Verification on WordPress Forms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/clearout-email-validator/assets/css/clearout-styles.css/wp-content/plugins/clearout-email-validator/assets/js/clearout-scripts.js
Script Paths
/wp-content/plugins/clearout-email-validator/assets/js/clearout-scripts.js
Version Parameters
clearout-email-validator/assets/css/clearout-styles.css?ver=clearout-email-validator/assets/js/clearout-scripts.js?ver=

HTML / DOM Fingerprints

CSS Classes
clearout-wrapperclearout-error-messageclearout-success-messageclearout-validation-wrapper
Data Attributes
data-clearout-email-validationdata-clearout-field-id
JS Globals
clearout_optionsclearout_validation_active
FAQ

Frequently Asked Questions about Clearout Email Validator – Real-Time Email Verification on WordPress Forms