FilterBounce Email Verifier Security & Risk Analysis

wordpress.org/plugins/filter-bounce-email-verifier

Verifies email addresses in real-time during form submissions to prevent invalid, disposable, temporary, catch-all, free or spamtrap email addresses.

0 active installs v1.0.2 PHP 7.4+ WP 5.0+ Updated Aug 3, 2024
block-spamemail-verificationemail-verifierform-email-verificationtemporary-email-blocker
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is FilterBounce Email Verifier Safe to Use in 2026?

Generally Safe

Score 92/100

FilterBounce Email Verifier has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "filter-bounce-email-verifier" v1.0.2 plugin presents a mixed security posture. On the positive side, its code analysis shows no critical issues like dangerous functions, raw SQL queries, or file operations. The plugin also demonstrates strong output escaping practices, with almost all outputs being properly sanitized. Furthermore, the lack of any recorded vulnerabilities in its history suggests a generally stable and secure development process. However, there are significant security concerns primarily related to its attack surface.

The plugin exposes three AJAX handlers, and alarmingly, all three lack authentication checks. This is a major security weakness, as it means any unauthenticated user could potentially interact with these handlers, leading to unintended actions or information disclosure. The absence of nonce checks on these AJAX handlers exacerbates this risk, as it prevents WordPress from verifying the legitimacy of the requests. The plugin also makes an external HTTP request, which, while not inherently bad, can be a vector for vulnerabilities if not handled securely. The absence of any taint analysis flows is positive, indicating no immediate critical vulnerabilities were found there.

In conclusion, while the plugin exhibits good practices in terms of SQL query handling, output escaping, and a clean vulnerability history, the unprotected AJAX endpoints are a substantial security risk that requires immediate attention. The plugin's strengths lie in its internal code safety, but its external interface is poorly secured. Addressing the unauthenticated AJAX handlers is paramount to improving its overall security.

Key Concerns

  • 3 AJAX handlers without auth checks
  • No nonce checks on AJAX handlers
  • External HTTP request
Vulnerabilities
None known

FilterBounce Email Verifier Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

FilterBounce Email Verifier Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
33 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

97% escaped34 total outputs
Attack Surface
3 unprotected

FilterBounce Email Verifier Attack Surface

Entry Points3
Unprotected3

AJAX Handlers 3

authwp_ajax_validate_filterbounce_apiadmin\class-filter-bounce-admin.php:10
authwp_ajax_validate_filterbounce_emailadmin\class-filter-bounce-admin.php:11
authwp_ajax_filterbounce_remove_api_keyadmin\class-filter-bounce-admin.php:12
WordPress Hooks 22
actionplugins_loadedincludes\class-filter-bounce.php:49
actionadmin_enqueue_scriptsincludes\class-filter-bounce.php:55
actionadmin_enqueue_scriptsincludes\class-filter-bounce.php:56
actionadmin_menuincludes\class-filter-bounce.php:57
actionadmin_initincludes\class-filter-bounce.php:58
actionwp_enqueue_scriptsincludes\class-filter-bounce.php:64
actionwp_enqueue_scriptsincludes\class-filter-bounce.php:65
actioninitincludes\class-filter-bounce.php:66
filtergform_validationpublic\class-filter-bounce-public.php:21
filterfrm_validate_field_entrypublic\class-filter-bounce-public.php:25
filterwpcf7_validate_email*public\class-filter-bounce-public.php:29
filterregistration_errorspublic\class-filter-bounce-public.php:33
actionwoocommerce_checkout_processpublic\class-filter-bounce-public.php:37
filterninja_forms_submit_datapublic\class-filter-bounce-public.php:41
actionelementor_pro/forms/validationpublic\class-filter-bounce-public.php:45
actionwpforms_process_validate_emailpublic\class-filter-bounce-public.php:49
filterfluentform/validate_input_item_input_emailpublic\class-filter-bounce-public.php:53
filterforminator_custom_form_submit_errorspublic\class-filter-bounce-public.php:57
filterhappyforms_validate_part_submissionpublic\class-filter-bounce-public.php:61
actionmailmint_before_form_submitpublic\class-filter-bounce-public.php:65
filtercntctfrm_check_formpublic\class-filter-bounce-public.php:69
filterpreprocess_commentpublic\class-filter-bounce-public.php:73
Maintenance & Trust

FilterBounce Email Verifier Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedAug 3, 2024
PHP min version7.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

FilterBounce Email Verifier Developer Profile

Fresent

1 plugin · 0 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect FilterBounce Email Verifier

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/filter-bounce-email-verifier/admin/css/filter-bounce-admin.css/wp-content/plugins/filter-bounce-email-verifier/admin/js/filter-bounce-admin.js
Script Paths
/wp-content/plugins/filter-bounce-email-verifier/admin/js/filter-bounce-admin.js
Version Parameters
filter-bounce-email-verifier/admin/css/filter-bounce-admin.css?ver=filter-bounce-email-verifier/admin/js/filter-bounce-admin.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-filterbounce-api-key
JS Globals
filterbounce_obj
FAQ

Frequently Asked Questions about FilterBounce Email Verifier