Email Blacklist For Elementor Forms Security & Risk Analysis

wordpress.org/plugins/email-blacklist-for-elementor-forms

Adds a text area control called "Blacklist" to the Elementor Forms control. Blocks outgoing emails if they match with any on the blacklist.

1K active installs v1.1.0 PHP 8.1+ WP 6.0+ Updated Dec 30, 2024
elementorelementor-formsemailemail-blacklistemail-block
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Email Blacklist For Elementor Forms Safe to Use in 2026?

Generally Safe

Score 92/100

Email Blacklist For Elementor Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The plugin 'email-blacklist-for-elementor-forms' version 1.1.0 exhibits a generally strong security posture based on the provided static analysis. The absence of known CVEs, critical taint flows, dangerous functions, and file operations is highly encouraging. Furthermore, the plugin demonstrates good practices by utilizing prepared statements for all SQL queries and avoiding external HTTP requests. This indicates a developer focused on fundamental security principles.

However, there are a couple of areas for improvement. The fact that only 50% of output is properly escaped suggests a potential for cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled meticulously before being displayed. Additionally, the complete absence of nonce checks and capability checks across all identified entry points is a significant concern. While the attack surface appears minimal (0 entry points), if any functionalities were to be added or exposed in the future without these checks, it would create substantial security risks, particularly if those functionalities involve sensitive operations.

In conclusion, the plugin is currently in a secure state due to its clean vulnerability history and adherence to critical security practices like prepared statements. The primary weakness lies in the incomplete output escaping and the lack of authentication/authorization mechanisms on potential (even if currently non-existent) entry points. These are important to address proactively to maintain security as the plugin evolves.

Key Concerns

  • Half of output is not properly escaped
  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

Email Blacklist For Elementor Forms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Email Blacklist For Elementor Forms Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

50% escaped2 total outputs
Attack Surface

Email Blacklist For Elementor Forms Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_noticesemail-blacklist-for-elementor-forms.php:27
actionplugins_loadedemail-blacklist-for-elementor-forms.php:31
actionelementor/element/form/section_form_fields/before_section_endemail-blacklist-for-elementor-forms.php:64
actionelementor_pro/forms/validation/emailemail-blacklist-for-elementor-forms.php:127
Maintenance & Trust

Email Blacklist For Elementor Forms Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedDec 30, 2024
PHP min version8.1
Downloads7K

Community Trust

Rating100/100
Number of ratings3
Active installs1K
Developer Profile

Email Blacklist For Elementor Forms Developer Profile

DeveloperWil

5 plugins · 3K total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Email Blacklist For Elementor Forms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Email Blacklist For Elementor Forms