EVA – Email Validator Security & Risk Analysis

wordpress.org/plugins/eva-email-validator

Keep your WordPress platforms free from fake or disposable email accounts.

0 active installs v1.1 PHP 7.0+ WP 5.2+ Updated Jun 8, 2019
apiemailemail-validatoremail-verifiervalidation
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is EVA – Email Validator Safe to Use in 2026?

Generally Safe

Score 85/100

EVA – Email Validator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The "eva-email-validator" v1.1 plugin exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of identified dangerous functions, raw SQL queries, file operations, and critical taint flows suggests a well-written codebase with security in mind. Furthermore, 100% of SQL queries use prepared statements, and all identified output is properly escaped, which are excellent security practices that mitigate common vulnerabilities.

However, there are a few areas that, while not indicating immediate critical risks, warrant attention. The presence of an external HTTP request, although only one, could potentially be a vector for information leakage or even man-in-the-middle attacks if not handled with appropriate validation and TLS. The single nonce check and capability check, while present, highlight that these security mechanisms are implemented, but their limited scope might leave other potential entry points less protected if they were to emerge. The plugin's vulnerability history being entirely clear is a significant positive, indicating a history of responsible development and a lack of previously exploited weaknesses.

In conclusion, "eva-email-validator" v1.1 appears to be a secure plugin with robust coding practices. The limited attack surface and lack of critical vulnerabilities are commendable. The single external HTTP request is the most notable area for potential improvement, and ensuring comprehensive use of nonces and capability checks for all potential interactions would further enhance its security. Overall, the plugin presents a low-risk profile.

Key Concerns

  • External HTTP request present
  • Single nonce check implemented
  • Single capability check implemented
Vulnerabilities
None known

EVA – Email Validator Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

EVA – Email Validator Release Timeline

v1.1Current
v1.0
Code Analysis
Analyzed Mar 17, 2026

EVA – Email Validator Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
14 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

100% escaped14 total outputs
Attack Surface

EVA – Email Validator Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionafter_setup_themeplugin.php:19
actionadmin_noticessrc\Controller\Dashboard.php:34
actionadmin_menusrc\Controller\Dashboard.php:38
actionadmin_initsrc\Controller\Dashboard.php:39
actionpre_comment_on_postsrc\EVA\for_comments.php:29
actioncomment_postsrc\EVA\for_comments.php:30
filteris_emailsrc\EVA\for_comments.php:37
actionregistration_errorssrc\EVA\for_register.php:24
filteris_emailsrc\EVA\is_email.php:24
Maintenance & Trust

EVA – Email Validator Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedJun 8, 2019
PHP min version7.0
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

EVA – Email Validator Developer Profile

Squarebit

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect EVA – Email Validator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Script Paths
/wp-content/plugins/eva-email-validator/assets/js/frontend.js/wp-content/plugins/eva-email-validator/assets/js/backend.js
Version Parameters
eva-email-validator/assets/js/frontend.js?ver=eva-email-validator/assets/js/backend.js?ver=

HTML / DOM Fingerprints

JS Globals
window.eva_validator_settings
REST Endpoints
/wp-json/eva-email-validator/
FAQ

Frequently Asked Questions about EVA – Email Validator