
Exact Match Disallowed Comment & Contact Forms Security & Risk Analysis
wordpress.org/plugins/exact-match-disallowed-comment-contact-formsChange the default WordPress comment blocklist functionality to exact match and save entries marked as spam for review.
Is Exact Match Disallowed Comment & Contact Forms Safe to Use in 2026?
Generally Safe
Score 100/100Exact Match Disallowed Comment & Contact Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "exact-match-disallowed-comment-contact-forms" plugin version 1.3.1 exhibits a generally strong security posture based on the static analysis. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, which significantly limits the potential attack surface. Furthermore, the absence of dangerous functions and critical or high-severity taint flows is highly encouraging. The plugin also demonstrates good practices in its limited use of SQL queries, with 50% employing prepared statements, and it includes nonce checks, indicating an awareness of common web vulnerabilities.
However, a few areas warrant attention. The 50% of SQL queries not using prepared statements represent a potential risk of SQL injection, although the limited number of queries mitigates this somewhat. The plugin also performs file operations without explicit detail on how these are handled, which could be a vector if not properly secured. The complete lack of capability checks is a concern; while the attack surface is currently small, this omission could become problematic if new features are added that interact with sensitive data or functionality without proper access controls.
The plugin's vulnerability history is excellent, with zero recorded CVEs of any severity. This suggests a history of well-written and secure code or consistent patching. In conclusion, the plugin is currently in a good security state, primarily due to its minimal attack surface and lack of critical code issues. The main areas for improvement involve ensuring all SQL queries are prepared and implementing capability checks for any sensitive operations.
Key Concerns
- SQL queries not using prepared statements
- File operations without detail on security
- No capability checks implemented
Exact Match Disallowed Comment & Contact Forms Security Vulnerabilities
Exact Match Disallowed Comment & Contact Forms Code Analysis
SQL Query Safety
Output Escaping
Exact Match Disallowed Comment & Contact Forms Attack Surface
WordPress Hooks 8
Maintenance & Trust
Exact Match Disallowed Comment & Contact Forms Maintenance & Trust
Maintenance Signals
Community Trust
Exact Match Disallowed Comment & Contact Forms Alternatives
WP Contact Slider – Contact Form Slider Widget
wp-contact-slider
Helps you to show slide out contact form to display CF7, Gravity forms, Ninja Forms, WP Forms, display random text/HTML and support some other forms.
Gravity Forms Zero Spam
gravity-forms-zero-spam
Enhance your Gravity Forms to include anti-spam measures originally based on the work of David Walsh's "Zero Spam" technique.
Maspik – Ultimate Spam Protection
contact-forms-anti-spam
No more fake leads or unwanted submissions — Maspik blocks spam instantly across all forms without using CAPTCHA.
Gravity Forms Email Blacklist
gravity-forms-email-blacklist
Add-on for Gravity Forms to create a Blacklisting of specific emails or domains for the Email input field to throw a validation error or mark as spam.
Spam Protect for Contact Form 7
wp-contact-form-7-spam-blocker
Spam Protect for Contact-Form7 protects from spam and bots. Customize defense strategies and monitor blocked attempts. Protect your time effectively!
Exact Match Disallowed Comment & Contact Forms Developer Profile
7 plugins · 30K total installs
How We Detect Exact Match Disallowed Comment & Contact Forms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/exact-match-disallowed-comment-contact-forms/assets/css/backend.css/wp-content/plugins/exact-match-disallowed-comment-contact-forms/assets/js/backend.jsexact-match-disallowed-comment-contact-forms/assets/css/backend.css?ver=exact-match-disallowed-comment-contact-forms/assets/js/backend.js?ver=HTML / DOM Fingerprints
blocklist-entries-php