Email Verification for Elementor Forms Security & Risk Analysis

wordpress.org/plugins/email-verification-elementor-forms

Add email verification to Elementor forms: users confirm via code, ensuring valid submissions and reducing spam.

100 active installs v1.2.2 PHP 8.0+ WP 6.0+ Updated Sep 26, 2024
elementoremail-verificationformsspam-prevention
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Email Verification for Elementor Forms Safe to Use in 2026?

Generally Safe

Score 92/100

Email Verification for Elementor Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The plugin "email-verification-elementor-forms" v1.2.2 exhibits a generally strong security posture based on the provided static analysis. The absence of any reported CVEs or past vulnerabilities, coupled with the lack of critical findings in taint analysis, suggests a well-maintained and secure codebase. Notably, the plugin demonstrates good practices by avoiding dangerous functions, using prepared statements exclusively for SQL queries, and conducting at least one nonce check. The limited attack surface, with no AJAX handlers, REST API routes, shortcodes, or cron events without authentication, further enhances its security.

However, there are areas for improvement. A significant concern is the 72% output escaping rate, meaning 28% of outputs are not properly escaped. This leaves a potential opening for cross-site scripting (XSS) vulnerabilities if user-supplied data is directly outputted without sufficient sanitization. Additionally, the complete lack of capability checks, while not immediately indicative of a vulnerability in this version due to the minimal attack surface, is a weakness that could become exploitable if new entry points are added in future versions without corresponding authorization checks.

In conclusion, the plugin is currently in a good security state, primarily due to the lack of known vulnerabilities and the robust handling of SQL and attack surface. The main area of concern is the unescaped output, which warrants attention. The absence of capability checks, while not a direct flaw here, represents a missed opportunity for defensive programming and a potential future risk.

Key Concerns

  • Unescaped output (28% of total)
  • No capability checks
Vulnerabilities
None known

Email Verification for Elementor Forms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Email Verification for Elementor Forms Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
13 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

72% escaped18 total outputs
Attack Surface

Email Verification for Elementor Forms Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionelementor_pro/forms/fields/registeremail-verification-elementor-forms.php:69
actionwp_enqueue_scriptsemail-verification-elementor-forms.php:72
actioninitemail-verification-elementor-forms.php:73
actionadmin_noticesemail-verification-elementor-forms.php:96
actionplugins_loadedemail-verification-elementor-forms.php:105
actionwp_enqueue_scriptsincludes\email-verification-field.php:18
actionelementor/editor/after_enqueue_scriptsincludes\email-verification-field.php:19
Maintenance & Trust

Email Verification for Elementor Forms Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedSep 26, 2024
PHP min version8.0
Downloads3K

Community Trust

Rating100/100
Number of ratings2
Active installs100
Developer Profile

Email Verification for Elementor Forms Developer Profile

rloes

1 plugin · 100 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Email Verification for Elementor Forms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/email-verification-elementor-forms/assets/dist/css/styles.min.css/wp-content/plugins/email-verification-elementor-forms/assets/dist/js/frontend.min.js
Script Paths
/wp-content/plugins/email-verification-elementor-forms/assets/dist/js/frontend.min.js
Version Parameters
email-verification-elementor-forms/assets/dist/css/styles.min.css?ver=email-verification-elementor-forms/assets/dist/js/frontend.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
elementor-email-verification-fieldevef-email-verification-field
Data Attributes
data-email-field
JS Globals
EVEF
FAQ

Frequently Asked Questions about Email Verification for Elementor Forms