Exact Match Disallowed Comment & Contact Forms Security & Risk Analysis

wordpress.org/plugins/exact-match-disallowed-comment-contact-forms

Change the default WordPress comment blocklist functionality to exact match and save entries marked as spam for review.

100 active installs v1.3.1 PHP 7.0+ WP + Updated Nov 17, 2025
anti-spamblacklistcontact-form-7formidablegravity-forms
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Exact Match Disallowed Comment & Contact Forms Safe to Use in 2026?

Generally Safe

Score 100/100

Exact Match Disallowed Comment & Contact Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The "exact-match-disallowed-comment-contact-forms" plugin version 1.3.1 exhibits a generally strong security posture based on the static analysis. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, which significantly limits the potential attack surface. Furthermore, the absence of dangerous functions and critical or high-severity taint flows is highly encouraging. The plugin also demonstrates good practices in its limited use of SQL queries, with 50% employing prepared statements, and it includes nonce checks, indicating an awareness of common web vulnerabilities.

However, a few areas warrant attention. The 50% of SQL queries not using prepared statements represent a potential risk of SQL injection, although the limited number of queries mitigates this somewhat. The plugin also performs file operations without explicit detail on how these are handled, which could be a vector if not properly secured. The complete lack of capability checks is a concern; while the attack surface is currently small, this omission could become problematic if new features are added that interact with sensitive data or functionality without proper access controls.

The plugin's vulnerability history is excellent, with zero recorded CVEs of any severity. This suggests a history of well-written and secure code or consistent patching. In conclusion, the plugin is currently in a good security state, primarily due to its minimal attack surface and lack of critical code issues. The main areas for improvement involve ensuring all SQL queries are prepared and implementing capability checks for any sensitive operations.

Key Concerns

  • SQL queries not using prepared statements
  • File operations without detail on security
  • No capability checks implemented
Vulnerabilities
None known

Exact Match Disallowed Comment & Contact Forms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Exact Match Disallowed Comment & Contact Forms Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
1 prepared
Unescaped Output
2
2 escaped
Nonce Checks
1
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

SQL Query Safety

50% prepared2 total queries

Output Escaping

50% escaped4 total outputs
Attack Surface

Exact Match Disallowed Comment & Contact Forms Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actioninitblocklist-manager.php:41
actionadmin_menublocklist-manager.php:51
filterpre_comment_approvedblocklist-manager.php:54
filterfrm_validate_entryblocklist-manager.php:57
filterfrm_check_blacklistblocklist-manager.php:59
filterwpcf7_submission_is_blacklistedblocklist-manager.php:62
filtergform_entry_is_spamblocklist-manager.php:65
actionwp_print_scriptsinc\class-table-entries.php:16
Maintenance & Trust

Exact Match Disallowed Comment & Contact Forms Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 17, 2025
PHP min version7.0
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

Exact Match Disallowed Comment & Contact Forms Developer Profile

Ryan Howard

7 plugins · 30K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Exact Match Disallowed Comment & Contact Forms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/exact-match-disallowed-comment-contact-forms/assets/css/backend.css/wp-content/plugins/exact-match-disallowed-comment-contact-forms/assets/js/backend.js
Version Parameters
exact-match-disallowed-comment-contact-forms/assets/css/backend.css?ver=exact-match-disallowed-comment-contact-forms/assets/js/backend.js?ver=

HTML / DOM Fingerprints

CSS Classes
blocklist-entries-php
FAQ

Frequently Asked Questions about Exact Match Disallowed Comment & Contact Forms