
Emails Blacklist for Everest Forms Security & Risk Analysis
wordpress.org/plugins/emails-blacklist-everest-formsAn add-on plugin for Everest Forms that allows the Blacklisting of specific field's value and emails and email domains by form.
Is Emails Blacklist for Everest Forms Safe to Use in 2026?
Generally Safe
Score 100/100Emails Blacklist for Everest Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "emails-blacklist-everest-forms" v1.0.4 exhibits a significant security concern due to its unprotected AJAX handlers. While the code analysis indicates no dangerous functions, all SQL queries use prepared statements, and most output is properly escaped, the presence of six AJAX handlers entirely lacking authentication checks presents a critical attack vector. This means any user, regardless of their WordPress role, could potentially trigger these handlers, leading to unintended actions or data manipulation.
The absence of nonce checks and capability checks further exacerbates this risk, as it leaves these entry points open to unauthorized access and exploitation. The fact that there are no known CVEs and no recorded vulnerabilities in its history is a positive sign, suggesting a potentially well-maintained plugin in terms of external threat intelligence. However, this historical absence of vulnerabilities does not negate the immediate and evident weaknesses identified in the static analysis.
In conclusion, while the plugin demonstrates good practices in its handling of SQL queries and output escaping, the unprotected AJAX handlers are a major security flaw. This oversight creates a substantial risk that outweighs the positive aspects. It is strongly recommended that these AJAX handlers be secured with appropriate authentication and authorization mechanisms before the plugin is used in a production environment.
Key Concerns
- AJAX handlers without auth checks
- No nonce checks
- No capability checks
- High number of unprotected entry points
Emails Blacklist for Everest Forms Security Vulnerabilities
Emails Blacklist for Everest Forms Code Analysis
Output Escaping
Emails Blacklist for Everest Forms Attack Surface
AJAX Handlers 6
WordPress Hooks 4
Maintenance & Trust
Emails Blacklist for Everest Forms Maintenance & Trust
Maintenance Signals
Community Trust
Emails Blacklist for Everest Forms Alternatives
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More
wpforms-lite
The best WordPress contact form plugin. Drag & Drop form builder to create beautiful contact forms, payment forms, & other custom forms.
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder
fluentform
Get a fast contact form plugin. Create advanced forms using drag and drop form builder with all smart features.
Forminator Forms – Contact Form, Payment Form & Custom Form Builder
forminator
Best WordPress form builder plugin. Create contact forms, payment forms & order forms with 1000+ integrations.
Ninja Forms – The Contact Form Builder That Grows With You
ninja-forms
The 100% beginner friendly WordPress form builder. Drag & drop form fields to build beautiful, professional contact forms in minutes.
SureForms – Contact Form, Payment Form & Other Custom Form Builder
sureforms
The most beginner-friendly, AI Form Builder for WordPress to create contact forms, payment forms & other custom forms with advanced features, with …
Emails Blacklist for Everest Forms Developer Profile
7 plugins · 4K total installs
How We Detect Emails Blacklist for Everest Forms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/emails-blacklist-everest-forms/assets/css/admin.css/wp-content/plugins/emails-blacklist-everest-forms/assets/js/admin.js/wp-content/plugins/emails-blacklist-everest-forms/assets/js/admin.jsemails-blacklist-everest-forms/assets/css/admin.css?ver=emails-blacklist-everest-forms/assets/js/admin.js?ver=HTML / DOM Fingerprints
blacklisting-formefeb-admin-wrapdata-efeb-form-idefeb_ajax_object