
Email Validator for Contact Form 7 Security & Risk Analysis
wordpress.org/plugins/email-validator-for-contact-form-7Email validation for Contact Form 7. Reduce registration spam with invalid email, block disposable and block free email.
Is Email Validator for Contact Form 7 Safe to Use in 2026?
Generally Safe
Score 100/100Email Validator for Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "email-validator-for-contact-form-7" plugin v1.8.1 exhibits several concerning security weaknesses despite having no recorded vulnerability history. The static analysis reveals a significant risk due to a single unprotected AJAX handler, which represents the entire attack surface of the plugin. This unprotected entry point is a prime target for attackers seeking to exploit vulnerabilities without needing authentication. Furthermore, the plugin heavily relies on raw SQL queries, with 100% of them lacking prepared statements. This is a serious security flaw that can lead to SQL injection vulnerabilities, especially when combined with unsanitized user input. The taint analysis confirms a high-severity flow with unsanitized paths, further indicating a potential for critical vulnerabilities like SQL injection or path traversal. The low percentage of properly escaped output (14%) also suggests a risk of Cross-Site Scripting (XSS) vulnerabilities.
Key Concerns
- Unprotected AJAX handler
- SQL queries without prepared statements
- High severity taint flow with unsanitized paths
- Low percentage of output escaping
- No nonce checks on AJAX entry points
Email Validator for Contact Form 7 Security Vulnerabilities
Email Validator for Contact Form 7 Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Email Validator for Contact Form 7 Attack Surface
AJAX Handlers 1
WordPress Hooks 10
Maintenance & Trust
Email Validator for Contact Form 7 Maintenance & Trust
Maintenance Signals
Community Trust
Email Validator for Contact Form 7 Alternatives
GEV Email Validator
gev-email-validator
The Cheapest advanced Email Address Validation to forms. Prevents typos in email address field and eliminates spam submissions with fake email address …
Antideo Email Validator
antideo-email-validator
Form email validation, Email Blacklist, Domain Blacklist, Form email check, Real time email validator Requires at least: 4.7 Tested up to: 6.9.
Reoon Email Verifier
reoon-email-verifier
Safeguard your online forms against invalid, temporary, disposable, and harmful email addresses with real-time verification.
QuickEmailVerification
quickemailverification
The QuickEmailVerification email verification plugin to avoid fake, bad and nonexistent emails.
Dilli Email Validator
dilli-email-validator
Validates email addresses in real-time and blocks form submissions with invalid or fake emails. Reduce spam, fix typos, and capture quality leads.
Email Validator for Contact Form 7 Developer Profile
2 plugins · 520 total installs
How We Detect Email Validator for Contact Form 7
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/email-validator-for-contact-form-7/assets/js/mbv.js/wp-content/plugins/email-validator-for-contact-form-7/assets/js/jquery.tagsinput.min.jshttps://cdnjs.cloudflare.com/ajax/libs/Chart.js/2.8.0/Chart.min.jshttps://cdnjs.cloudflare.com/ajax/libs/jquery-tagsinput/1.3.6/jquery.tagsinput.min.cssemail-validator-for-contact-form-7/assets/js/mbv.js?ver=email-validator-for-contact-form-7/assets/js/jquery.tagsinput.min.js?ver=HTML / DOM Fingerprints
mbv_wpcf7_nocf7_noticeChartjQuery