
CM E-Mail Blacklist – Simple email filtering for safer registration Security & Risk Analysis
wordpress.org/plugins/cm-email-blacklistBlock unwanted email registrations on your site with this email blacklist plugin. Protect your site by preventing spam sign-ups.
Is CM E-Mail Blacklist – Simple email filtering for safer registration Safe to Use in 2026?
Generally Safe
Score 96/100CM E-Mail Blacklist – Simple email filtering for safer registration has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "cm-email-blacklist" v1.6.4 plugin exhibits a mixed security posture. On the positive side, it makes good use of prepared statements for SQL queries and includes nonce checks on some entry points. However, significant concerns arise from its attack surface, particularly with three out of four AJAX handlers lacking authentication checks, making them vulnerable to unauthorized actions. Additionally, while the taint analysis shows no critical or high severity flows, one flow with an unsanitized path warrants attention for potential injection vulnerabilities. The plugin's vulnerability history, with three previously disclosed medium-severity CVEs for Cross-Site Scripting and CSRF, and the most recent vulnerability dated in the future (implying potential for future undiscovered issues or misrepresentation), suggests a pattern of past security weaknesses that, while currently patched, could indicate ongoing development or maintenance practices that may overlook certain security considerations.
Key Concerns
- AJAX handlers without authentication checks
- Output escaping is not consistently applied
- One unsanitized path in taint analysis
- Past medium severity vulnerabilities
CM E-Mail Blacklist – Simple email filtering for safer registration Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
CM E-Mail Blacklist <= 1.6.2 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'black_email' Parameter
CM E-Mail Blacklist – Simple email filtering for safer registration <= 1.5.5 - Reflected Cross-Site Scripting
CM Email Registration Blacklist and Whitelist <= 1.4.8 - Cross-Site Request Forgery
CM E-Mail Blacklist – Simple email filtering for safer registration Release Timeline
CM E-Mail Blacklist – Simple email filtering for safer registration Code Analysis
Output Escaping
Data Flow Analysis
CM E-Mail Blacklist – Simple email filtering for safer registration Attack Surface
AJAX Handlers 4
Shortcodes 4
WordPress Hooks 15
Maintenance & Trust
CM E-Mail Blacklist – Simple email filtering for safer registration Maintenance & Trust
Maintenance Signals
Community Trust
CM E-Mail Blacklist – Simple email filtering for safer registration Alternatives
Advanced Email Filter for Elementor Forms
advanced-email-filter-for-elementor-forms
Enhance Elementor Pro Forms with advanced email filtering capabilities including global blocklists/whitelist and per-form controls.
Maspik – Ultimate Spam Protection
contact-forms-anti-spam
No more fake leads or unwanted submissions — Maspik blocks spam instantly across all forms without using CAPTCHA.
Exact Match Disallowed Comment & Contact Forms
exact-match-disallowed-comment-contact-forms
Change the default WordPress comment blocklist functionality to exact match and save entries marked as spam for review.
Back List
back-list
Adds Whitelist and Blacklist options for Trackbacks and Pingbacks
WP-Mail-Validator
wp-mail-validator
WP-Mail-Validator is an anti-spam plugin. It provides mail-address validation in 5 ways:
CM E-Mail Blacklist – Simple email filtering for safer registration Developer Profile
19 plugins · 22K total installs
How We Detect CM E-Mail Blacklist – Simple email filtering for safer registration
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cm-email-blacklist/assets/css/cm-email-blacklist.css/wp-content/plugins/cm-email-blacklist/assets/js/cm-email-blacklist.js/wp-content/plugins/cm-email-blacklist/assets/js/cm-email-blacklist.jscm-email-blacklist/assets/css/cm-email-blacklist.css?ver=cm-email-blacklist/assets/js/cm-email-blacklist.js?ver=HTML / DOM Fingerprints
cmseparator