
EVA – Email Validator Security & Risk Analysis
wordpress.org/plugins/eva-email-validatorKeep your WordPress platforms free from fake or disposable email accounts.
Is EVA – Email Validator Safe to Use in 2026?
Generally Safe
Score 85/100EVA – Email Validator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "eva-email-validator" v1.1 plugin exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of identified dangerous functions, raw SQL queries, file operations, and critical taint flows suggests a well-written codebase with security in mind. Furthermore, 100% of SQL queries use prepared statements, and all identified output is properly escaped, which are excellent security practices that mitigate common vulnerabilities.
However, there are a few areas that, while not indicating immediate critical risks, warrant attention. The presence of an external HTTP request, although only one, could potentially be a vector for information leakage or even man-in-the-middle attacks if not handled with appropriate validation and TLS. The single nonce check and capability check, while present, highlight that these security mechanisms are implemented, but their limited scope might leave other potential entry points less protected if they were to emerge. The plugin's vulnerability history being entirely clear is a significant positive, indicating a history of responsible development and a lack of previously exploited weaknesses.
In conclusion, "eva-email-validator" v1.1 appears to be a secure plugin with robust coding practices. The limited attack surface and lack of critical vulnerabilities are commendable. The single external HTTP request is the most notable area for potential improvement, and ensuring comprehensive use of nonces and capability checks for all potential interactions would further enhance its security. Overall, the plugin presents a low-risk profile.
Key Concerns
- External HTTP request present
- Single nonce check implemented
- Single capability check implemented
EVA – Email Validator Security Vulnerabilities
EVA – Email Validator Release Timeline
EVA – Email Validator Code Analysis
Output Escaping
EVA – Email Validator Attack Surface
WordPress Hooks 9
Maintenance & Trust
EVA – Email Validator Maintenance & Trust
Maintenance Signals
Community Trust
EVA – Email Validator Alternatives
Reoon Email Verifier
reoon-email-verifier
Safeguard your online forms against invalid, temporary, disposable, and harmful email addresses with real-time verification.
EmailVerify.io
emailverify
Safeguard your online forms against invalid, temporary, disposable, and harmful email addresses with real-time verification.
ZeroBounce Email Verification & Validation
zerobounce
ZeroBounce validates emails on your WordPress site in real-time, blocking invalid and risky emails to improve deliverability and reduce bounce rates.
Antideo Email Validator
antideo-email-validator
Form email validation, Email Blacklist, Domain Blacklist, Form email check, Real time email validator Requires at least: 4.7 Tested up to: 6.9.
Clearout Email Validator – Real-Time Email Verification on WordPress Forms
clearout-email-validator
Block invalid emails like temporary, disposable, etc. with our real-time email verification. Verify email address during form-fill and stop form spam.
EVA – Email Validator Developer Profile
1 plugin · 0 total installs
How We Detect EVA – Email Validator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/eva-email-validator/assets/js/frontend.js/wp-content/plugins/eva-email-validator/assets/js/backend.jseva-email-validator/assets/js/frontend.js?ver=eva-email-validator/assets/js/backend.js?ver=HTML / DOM Fingerprints
window.eva_validator_settings/wp-json/eva-email-validator/