MailboxValidator Email Validator Security & Risk Analysis

wordpress.org/plugins/mailboxvalidator-email-validator

Email verification for WordPress forms. Block disposable, block spam, block invalid email, block free email and role-based email.

20 active installs v1.7.1 PHP + WP + Updated Dec 11, 2025
email-checkeremail-filteremail-validationemail-verifyform-validation
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is MailboxValidator Email Validator Safe to Use in 2026?

Generally Safe

Score 100/100

MailboxValidator Email Validator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The "mailboxvalidator-email-validator" plugin v1.7.1 exhibits a concerning security posture, primarily due to its unprotected AJAX handler. This single unprotected entry point represents a significant risk, as it can be directly accessed by unauthenticated users. The taint analysis further highlights this concern, revealing three critical flows with unsanitized paths, strongly suggesting that user-supplied data could be manipulated to execute unintended actions or access sensitive information. While the plugin's vulnerability history is clean, with no known CVEs, this lack of past issues does not negate the present risks identified in the code analysis. The low percentage of prepared statements in SQL queries and a moderate rate of proper output escaping also indicate areas where good security practices are not consistently applied.

In conclusion, the plugin's strength lies in its lack of historical vulnerabilities. However, this is overshadowed by significant weaknesses. The unprotected AJAX handler and critical taint flows create direct avenues for potential exploitation. The general lack of robust security checks, such as nonce and capability checks, and less-than-ideal SQL and output escaping practices, contribute to an overall elevated risk profile. Users of this plugin should be aware of these potential vulnerabilities and consider mitigation strategies if they cannot be addressed by the developer.

Key Concerns

  • Unprotected AJAX handler
  • Critical taint flow with unsanitized path
  • Critical taint flow with unsanitized path
  • Critical taint flow with unsanitized path
  • SQL queries not using prepared statements
  • Output escaping not properly implemented
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

MailboxValidator Email Validator Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

MailboxValidator Email Validator Code Analysis

Dangerous Functions
0
Raw SQL Queries
15
1 prepared
Unescaped Output
22
14 escaped
Nonce Checks
0
Capability Checks
0
File Operations
4
External Requests
1
Bundled Libraries
0

SQL Query Safety

6% prepared16 total queries

Output Escaping

39% escaped36 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

3 flows3 with unsanitized paths
mbv_wpcf7_custom_email_validator_filter (mailboxvalidator-email-validator.php:1146)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

MailboxValidator Email Validator Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_mailboxvalidator_email_validator_submit_feedbackmailboxvalidator-email-validator.php:25
WordPress Hooks 18
actionadmin_noticesmailboxvalidator-email-validator.php:24
actionadmin_footer_textmailboxvalidator-email-validator.php:26
actionadmin_enqueue_scriptsmailboxvalidator-email-validator.php:28
filterregistration_errorsmailboxvalidator-email-validator.php:30
filterwpcf7_validate_emailmailboxvalidator-email-validator.php:33
filterwpcf7_validate_email*mailboxvalidator-email-validator.php:34
actionfrm_validate_entrymailboxvalidator-email-validator.php:36
filtercaldera_forms_validate_field_emailmailboxvalidator-email-validator.php:38
filterwppb_check_form_field_default-e-mailmailboxvalidator-email-validator.php:40
filtercntctfrm_check_formmailboxvalidator-email-validator.php:42
actionwoocommerce_after_checkout_validationmailboxvalidator-email-validator.php:44
filteris_emailmailboxvalidator-email-validator.php:46
actionadmin_menumailboxvalidator-email-validator.php:59
actionadmin_initmailboxvalidator-email-validator.php:61
actionwp_enqueue_scriptmailboxvalidator-email-validator.php:79
actionpre_comment_on_postmailboxvalidator-email-validator.php:1483
actioncomment_postmailboxvalidator-email-validator.php:1484
filteris_emailmailboxvalidator-email-validator.php:1491
Maintenance & Trust

MailboxValidator Email Validator Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 11, 2025
PHP min version
Downloads10K

Community Trust

Rating20/100
Number of ratings1
Active installs20
Developer Profile

MailboxValidator Email Validator Developer Profile

MailboxValidator

2 plugins · 520 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect MailboxValidator Email Validator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mailboxvalidator-email-validator/assets/js/mbv.js/wp-content/plugins/mailboxvalidator-email-validator/assets/js/jquery.tagsinput.min.js
Script Paths
/wp-content/plugins/mailboxvalidator-email-validator/assets/js/mbv.js/wp-content/plugins/mailboxvalidator-email-validator/assets/js/jquery.tagsinput.min.js
Version Parameters
mailboxvalidator-email-validator/assets/js/mbv.js?ver=mailboxvalidator-email-validator/assets/js/jquery.tagsinput.min.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-tab
JS Globals
mbv_data
FAQ

Frequently Asked Questions about MailboxValidator Email Validator