
Email Verify Security & Risk Analysis
wordpress.org/plugins/email-verifyVerifies your Users email addresses and blocks them from register to your site.
Is Email Verify Safe to Use in 2026?
Generally Safe
Score 100/100Email Verify has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "email-verify" plugin v1.1.6 exhibits a mixed security posture. On one hand, it boasts a zero attack surface from common entry points like AJAX, REST API, shortcodes, and cron events, and all SQL queries are properly prepared. This indicates good practices in limiting exposure and handling database interactions securely. However, several concerning code signals were detected. The presence of the `exec` function, even if not immediately exploitable due to a lack of identified flows, is a significant red flag. Furthermore, zero output escaping on all detected outputs represents a critical vulnerability that could lead to cross-site scripting (XSS) attacks. The absence of nonce and capability checks across the board exacerbates these risks, as any identified entry points or functions could be executed without proper authorization or validation.
The vulnerability history for this plugin is remarkably clean, with no recorded CVEs. This suggests a history of responsible development or perhaps a lack of targeted security research against it. While this is positive, it does not negate the immediate risks identified in the static analysis. The combination of a clean history and significant code-level vulnerabilities means that while the plugin hasn't been historically problematic, the current version has clear weaknesses that need addressing. The strengths lie in its limited attack surface and secure database practices, but the weaknesses in output escaping, the presence of `exec`, and lack of authorization checks are substantial concerns that outweigh these positives in the short term.
Key Concerns
- Presence of dangerous function 'exec'
- 0% output escaping
- 0 Nonce checks
- 0 Capability checks
Email Verify Security Vulnerabilities
Email Verify Release Timeline
Email Verify Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Email Verify Attack Surface
WordPress Hooks 4
Maintenance & Trust
Email Verify Maintenance & Trust
Maintenance Signals
Community Trust
Email Verify Alternatives
Customer Email Verification for WooCommerce
emails-verification-for-woocommerce
Enhance WooCommerce security and credibility with Email Verification best plugin. Ensure genuine customer interactions, eliminate spam, and elevate em …
miniOrange OTP Login, Verification and SMS Notifications
miniorange-otp-verification
OTP Verification via Email/SMS/WhatsApp,SMS Notifications for WooCommerce,OTP Login with Phone,PasswordLess Login.Custom Gateway for OTP Verification
User Verification by PickPlugins
user-verification
Email verification for user registration to protect spam.
Customer Email Verification for WooCommerce
customer-email-verification-for-woocommerce
Secure WooCommerce registrations with OTP-based email verification, reducing spam and ensuring only valid email addresses are used.
Make Disable Admin Email Verification Prompt| Aims Infosoft
make-disable-admin-email-verification-prompt
Disable Admin Email Verification Prompt with checkbox option in Genearl in Settings.if you want to disable prompt then tick the chekckbox.
Email Verify Developer Profile
28 plugins · 120K total installs
How We Detect Email Verify
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/email-verify/assets/css/admin.css/wp-content/plugins/email-verify/assets/js/admin.js