Emails Blacklist for Everest Forms Security & Risk Analysis

wordpress.org/plugins/emails-blacklist-everest-forms

An add-on plugin for Everest Forms that allows the Blacklisting of specific field's value and emails and email domains by form.

20 active installs v1.0.4 PHP + WP 4.9+ Updated Dec 9, 2025
everesteverest-formeverest-formsformforms
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Emails Blacklist for Everest Forms Safe to Use in 2026?

Generally Safe

Score 100/100

Emails Blacklist for Everest Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The plugin "emails-blacklist-everest-forms" v1.0.4 exhibits a significant security concern due to its unprotected AJAX handlers. While the code analysis indicates no dangerous functions, all SQL queries use prepared statements, and most output is properly escaped, the presence of six AJAX handlers entirely lacking authentication checks presents a critical attack vector. This means any user, regardless of their WordPress role, could potentially trigger these handlers, leading to unintended actions or data manipulation.

The absence of nonce checks and capability checks further exacerbates this risk, as it leaves these entry points open to unauthorized access and exploitation. The fact that there are no known CVEs and no recorded vulnerabilities in its history is a positive sign, suggesting a potentially well-maintained plugin in terms of external threat intelligence. However, this historical absence of vulnerabilities does not negate the immediate and evident weaknesses identified in the static analysis.

In conclusion, while the plugin demonstrates good practices in its handling of SQL queries and output escaping, the unprotected AJAX handlers are a major security flaw. This oversight creates a substantial risk that outweighs the positive aspects. It is strongly recommended that these AJAX handlers be secured with appropriate authentication and authorization mechanisms before the plugin is used in a production environment.

Key Concerns

  • AJAX handlers without auth checks
  • No nonce checks
  • No capability checks
  • High number of unprotected entry points
Vulnerabilities
None known

Emails Blacklist for Everest Forms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Emails Blacklist for Everest Forms Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
9 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

90% escaped10 total outputs
Attack Surface
6 unprotected

Emails Blacklist for Everest Forms Attack Surface

Entry Points6
Unprotected6

AJAX Handlers 6

authwp_ajax_select_formemails-blacklist-everest-forms.php:144
noprivwp_ajax_select_formemails-blacklist-everest-forms.php:146
authwp_ajax_blacklist_formemails-blacklist-everest-forms.php:148
noprivwp_ajax_blacklist_formemails-blacklist-everest-forms.php:150
authwp_ajax_deleteemails-blacklist-everest-forms.php:153
noprivwp_ajax_deleteemails-blacklist-everest-forms.php:155
WordPress Hooks 4
actionadmin_noticesemails-blacklist-everest-forms.php:74
actionadmin_enqueue_scriptsemails-blacklist-everest-forms.php:140
actionadmin_menuemails-blacklist-everest-forms.php:142
filtereverest_forms_entry_saveemails-blacklist-everest-forms.php:158
Maintenance & Trust

Emails Blacklist for Everest Forms Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.0
Last updatedDec 9, 2025
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Emails Blacklist for Everest Forms Developer Profile

CoderPress

7 plugins · 4K total installs

86
trust score
Avg Security Score
97/100
Avg Patch Time
33 days
View full developer profile
Detection Fingerprints

How We Detect Emails Blacklist for Everest Forms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/emails-blacklist-everest-forms/assets/css/admin.css/wp-content/plugins/emails-blacklist-everest-forms/assets/js/admin.js
Script Paths
/wp-content/plugins/emails-blacklist-everest-forms/assets/js/admin.js
Version Parameters
emails-blacklist-everest-forms/assets/css/admin.css?ver=emails-blacklist-everest-forms/assets/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
blacklisting-formefeb-admin-wrap
Data Attributes
data-efeb-form-id
JS Globals
efeb_ajax_object
FAQ

Frequently Asked Questions about Emails Blacklist for Everest Forms