Email Checker for Contact Form 7 Security & Risk Analysis

wordpress.org/plugins/email-checker-for-contact-form-7

Emails Checker will allow you to avoid spam email inboxes and spam contact form filling by verifying the user's email address using emails-checke …

100 active installs v2.5 PHP 7.1+ WP 4.6+ Updated Aug 26, 2025
contact-form-7email-checkeremail-checker-for-contact-form-7email-validatoremails-checker
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Email Checker for Contact Form 7 Safe to Use in 2026?

Generally Safe

Score 100/100

Email Checker for Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7mo ago
Risk Assessment

The "email-checker-for-contact-form-7" plugin, version 2.5, exhibits a generally strong security posture based on the static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits its attack surface. Furthermore, the plugin demonstrates good security practices by utilizing prepared statements for all SQL queries and including nonce and capability checks. The lack of known CVEs and a clean vulnerability history are positive indicators of past development attention to security.

However, there are areas for improvement. The output escaping is only properly handled for 27% of outputs, which is a notable concern. This could potentially lead to cross-site scripting (XSS) vulnerabilities if the unsanitized output is rendered within the browser. While the taint analysis identified one flow with an unsanitized path, it did not reach a critical or high severity, and the static analysis did not uncover any dangerous functions or file operations. The presence of external HTTP requests, though not inherently a vulnerability, warrants careful monitoring to ensure they are not exploited for malicious purposes.

In conclusion, the plugin has a solid foundation with a minimal attack surface and good adherence to core WordPress security best practices. The primary weakness identified is the insufficient output escaping, which requires remediation. The vulnerability history is encouraging, suggesting a well-maintained plugin. While the single unsanitized taint flow is not currently critical, it is a point to address alongside the output escaping to further harden the plugin's security.

Key Concerns

  • Low output escaping (27% proper)
  • Unsanitized path in taint flow
Vulnerabilities
None known

Email Checker for Contact Form 7 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Email Checker for Contact Form 7 Release Timeline

v2.3
v2.2
v2.1
v2.0
v1.2
v1.1
v1.0
Code Analysis
Analyzed Mar 16, 2026

Email Checker for Contact Form 7 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
11
4 escaped
Nonce Checks
1
Capability Checks
2
File Operations
0
External Requests
3
Bundled Libraries
0

Output Escaping

27% escaped15 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

3 flows1 with unsanitized paths
settings (email-checker-for-cf7.php:196)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Email Checker for Contact Form 7 Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionadmin_initemail-checker-for-cf7.php:47
actionadmin_menuemail-checker-for-cf7.php:49
actionadmin_initemail-checker-for-cf7.php:50
filterplugin_action_linksemail-checker-for-cf7.php:52
filterwpcf7_validate_emailemail-checker-for-cf7.php:56
filterwpcf7_validate_email*email-checker-for-cf7.php:57
actionadmin_noticesemail-checker-for-cf7.php:65
actionadmin_noticesemail-checker-for-cf7.php:138
Maintenance & Trust

Email Checker for Contact Form 7 Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedAug 26, 2025
PHP min version7.1
Downloads6K

Community Trust

Rating60/100
Number of ratings2
Active installs100
Developer Profile

Email Checker for Contact Form 7 Developer Profile

Kalpraj Solutions

2 plugins · 140 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Email Checker for Contact Form 7

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
notice-warning
FAQ

Frequently Asked Questions about Email Checker for Contact Form 7