
FilterBounce Email Verifier Security & Risk Analysis
wordpress.org/plugins/filter-bounce-email-verifierVerifies email addresses in real-time during form submissions to prevent invalid, disposable, temporary, catch-all, free or spamtrap email addresses.
Is FilterBounce Email Verifier Safe to Use in 2026?
Generally Safe
Score 92/100FilterBounce Email Verifier has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "filter-bounce-email-verifier" v1.0.2 plugin presents a mixed security posture. On the positive side, its code analysis shows no critical issues like dangerous functions, raw SQL queries, or file operations. The plugin also demonstrates strong output escaping practices, with almost all outputs being properly sanitized. Furthermore, the lack of any recorded vulnerabilities in its history suggests a generally stable and secure development process. However, there are significant security concerns primarily related to its attack surface.
The plugin exposes three AJAX handlers, and alarmingly, all three lack authentication checks. This is a major security weakness, as it means any unauthenticated user could potentially interact with these handlers, leading to unintended actions or information disclosure. The absence of nonce checks on these AJAX handlers exacerbates this risk, as it prevents WordPress from verifying the legitimacy of the requests. The plugin also makes an external HTTP request, which, while not inherently bad, can be a vector for vulnerabilities if not handled securely. The absence of any taint analysis flows is positive, indicating no immediate critical vulnerabilities were found there.
In conclusion, while the plugin exhibits good practices in terms of SQL query handling, output escaping, and a clean vulnerability history, the unprotected AJAX endpoints are a substantial security risk that requires immediate attention. The plugin's strengths lie in its internal code safety, but its external interface is poorly secured. Addressing the unauthenticated AJAX handlers is paramount to improving its overall security.
Key Concerns
- 3 AJAX handlers without auth checks
- No nonce checks on AJAX handlers
- External HTTP request
FilterBounce Email Verifier Security Vulnerabilities
FilterBounce Email Verifier Code Analysis
Output Escaping
FilterBounce Email Verifier Attack Surface
AJAX Handlers 3
WordPress Hooks 22
Maintenance & Trust
FilterBounce Email Verifier Maintenance & Trust
Maintenance Signals
Community Trust
FilterBounce Email Verifier Alternatives
Reoon Email Verifier
reoon-email-verifier
Safeguard your online forms against invalid, temporary, disposable, and harmful email addresses with real-time verification.
ZeroBounce Email Verification & Validation
zerobounce
ZeroBounce validates emails on your WordPress site in real-time, blocking invalid and risky emails to improve deliverability and reduce bounce rates.
Clearout Email Validator – Real-Time Email Verification on WordPress Forms
clearout-email-validator
Block invalid emails like temporary, disposable, etc. with our real-time email verification. Verify email address during form-fill and stop form spam.
Emailable – Premium Email Verification & Validation
emailable
Verify emails in real-time with Emailable.
TrueMail Email Validator
truemail-email-validator
TrueMail plugin can be seamlessly integrated with all forms to verify the user email address in real-time before submission.
FilterBounce Email Verifier Developer Profile
1 plugin · 0 total installs
How We Detect FilterBounce Email Verifier
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/filter-bounce-email-verifier/admin/css/filter-bounce-admin.css/wp-content/plugins/filter-bounce-email-verifier/admin/js/filter-bounce-admin.js/wp-content/plugins/filter-bounce-email-verifier/admin/js/filter-bounce-admin.jsfilter-bounce-email-verifier/admin/css/filter-bounce-admin.css?ver=filter-bounce-email-verifier/admin/js/filter-bounce-admin.js?ver=HTML / DOM Fingerprints
data-filterbounce-api-keyfilterbounce_obj