
Contact Form 7 Email Validation Security & Risk Analysis
wordpress.org/plugins/email-domain-verification-in-cf7Contact Form 7 Email Validation plugin adds an extended validation to verify domain in email address for email fields of Contact Form 7 plugin.
Is Contact Form 7 Email Validation Safe to Use in 2026?
Generally Safe
Score 85/100Contact Form 7 Email Validation has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'email-domain-verification-in-cf7' version 3.5.2 demonstrates a strong security posture based on the provided static analysis. There are no identified dangerous functions, SQL queries are 100% prepared, and all output is properly escaped, indicating good coding practices for preventing common web vulnerabilities. The absence of file operations and external HTTP requests further reduces the attack surface. The plugin also shows no history of known vulnerabilities (CVEs), which is a very positive sign of its stability and security over time.
While the static analysis reveals a clean codebase with no critical or high-severity issues detected in taint flows or direct code signals, the complete absence of identified entry points (AJAX handlers, REST API routes, shortcodes, cron events) is unusual. This could mean the plugin has a very limited or no functional impact, or that the static analysis tool was unable to identify these components. The presence of only one capability check is also notable, suggesting the plugin's functionality might not require extensive user privilege verification, which could be a concern if sensitive actions were performed without proper authorization. However, without any specific vulnerabilities identified in the code signals or history, the overall risk is assessed as very low.
In conclusion, the plugin exhibits excellent security development practices with no known vulnerabilities or concerning code patterns detected in this analysis. The primary area for potential improvement or further investigation would be to confirm the completeness of the identified attack surface, as its current reported zero entry points is atypical for a functional WordPress plugin. Despite this anomaly, the lack of any detected security flaws makes it a relatively safe plugin to use.
Key Concerns
- Missing nonce checks on AJAX handlers
- Missing permission callbacks on REST API routes
- Dangerous functions found in code
- SQL queries without prepared statements
- Unescaped output found
- File operations detected
- External HTTP requests detected
- Bundled outdated libraries
- Unpatched CVEs found
- Critical severity taint flow
- High severity taint flow
- Unusual lack of identified entry points
- Limited capability checks detected
Contact Form 7 Email Validation Security Vulnerabilities
Contact Form 7 Email Validation Release Timeline
Contact Form 7 Email Validation Code Analysis
Output Escaping
Contact Form 7 Email Validation Attack Surface
WordPress Hooks 5
Maintenance & Trust
Contact Form 7 Email Validation Maintenance & Trust
Maintenance Signals
Community Trust
Contact Form 7 Email Validation Alternatives
Email Validator for Contact Form 7
email-validator-for-contact-form-7
Email validation for Contact Form 7. Reduce registration spam with invalid email, block disposable and block free email.
OTP by Email for Contact Form 7
otp-by-email
A small Contact Form 7 extension plugin to enable email confirmation by unique links sent to the email inbox.
Custom Validation for CF7
custom-validation-for-cf7
Advanced validation for Contact Form 7: block URLs, validate phone and email, with admin settings.
MTX Email DNS Validator for Contact Form 7
mtx-email-dns-validation-for-cf7
Advanced email validation for Contact Form 7 using DNS/MX records and SMTP verification to prevent invalid email submissions.
Unelma Email Verification with SnapValid
unelma-email-verification-snapvalid
🚀 Transform Your Email Quality with Real-Time Validation Tired of fake emails, spam signups, and invalid customers? Unelma Email Verification with S …
Contact Form 7 Email Validation Developer Profile
3 plugins · 2K total installs
How We Detect Contact Form 7 Email Validation
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.