
Email verification on signups Security & Risk Analysis
wordpress.org/plugins/email-verification-on-signupsSend verification links to newly registered users and ask them to confirm their email address to activate their account.
Is Email verification on signups Safe to Use in 2026?
Generally Safe
Score 92/100Email verification on signups has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'email-verification-on-signups' v1.1.7 plugin exhibits a generally good security posture based on the provided static analysis. The absence of known vulnerabilities and CVEs is a significant positive indicator. Furthermore, the plugin demonstrates good practices by not utilizing dangerous functions, performing all SQL queries using prepared statements, and having no file operations or external HTTP requests. The limited attack surface, with only two AJAX handlers and no REST API routes, shortcodes, or cron events, also contributes to its strong security.
However, there are areas for improvement. The most notable concern is the low percentage (28%) of properly escaped output. This could potentially lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is displayed without adequate sanitization. The complete lack of nonce checks on the AJAX handlers is another significant risk, as it makes these entry points vulnerable to Cross-Site Request Forgery (CSRF) attacks. While the plugin does implement capability checks, these alone are not sufficient to protect against CSRF. The absence of taint analysis results is noted, but its zero findings in the limited scope suggest no immediate critical flows were identified.
Key Concerns
- Low output escaping percentage
- Missing nonce checks on AJAX handlers
Email verification on signups Security Vulnerabilities
Email verification on signups Code Analysis
Output Escaping
Email verification on signups Attack Surface
AJAX Handlers 2
WordPress Hooks 11
Maintenance & Trust
Email verification on signups Maintenance & Trust
Maintenance Signals
Community Trust
Email verification on signups Alternatives
Customer Email Verification for WooCommerce
emails-verification-for-woocommerce
Enhance WooCommerce security and credibility with Email Verification best plugin. Ensure genuine customer interactions, eliminate spam, and elevate em …
miniOrange OTP Login, Verification and SMS Notifications
miniorange-otp-verification
OTP Verification via Email/SMS/WhatsApp,SMS Notifications for WooCommerce,OTP Login with Phone,PasswordLess Login.Custom Gateway for OTP Verification
User Verification by PickPlugins
user-verification
Email verification for user registration to protect spam.
Double Opt-In for Contact Form 7 & Avada – Secure, GDPR-Compliant Email Verification
double-opt-in
Protect your forms with GDPR-compliant Double Opt-In. Ensure valid emails, prevent fake signups, and stay compliant with Contact Form 7 and Avada.
ZeroBounce Email Verification & Validation
zerobounce
ZeroBounce validates emails on your WordPress site in real-time, blocking invalid and risky emails to improve deliverability and reduce bounce rates.
Email verification on signups Developer Profile
2 plugins · 2K total installs
How We Detect Email verification on signups
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/email-verification-on-signups/assets/js/verify-email.jsHTML / DOM Fingerprints
dwverify[dw-verify-email]