
RA – Registration Mail Address Domain Limiter Security & Risk Analysis
wordpress.org/plugins/ra-registration-mail-address-domain-limiterThe domain which can be used for user's registration can be restricted.
Is RA – Registration Mail Address Domain Limiter Safe to Use in 2026?
Generally Safe
Score 85/100RA – Registration Mail Address Domain Limiter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "ra-registration-mail-address-domain-limiter" v1.2.8 exhibits a mixed security posture. On the positive side, the plugin has no known CVEs, no outdated bundled libraries, and no direct SQL queries that aren't prepared. Furthermore, the attack surface appears to be very small with zero exposed entry points like AJAX handlers, REST API routes, or shortcodes, and no external HTTP requests or file operations. This indicates a generally cautious approach to exposing functionality.
However, there are significant concerns within the static analysis. The presence of the `unserialize` function is a critical risk, as it can lead to Remote Code Execution if an attacker can control the serialized data being processed. Compounding this, a notable percentage of output is not properly escaped. While the taint analysis shows no current flows with unsanitized paths, the `unserialize` function itself is a latent vulnerability waiting for an injection vector. The low number of capability checks and nonce checks also suggests potential weaknesses in authorization and request verification, especially if the plugin's functionality is ever expanded or an unexpected entry point is discovered.
Given the lack of historical vulnerabilities, it's possible the plugin's limited functionality and careful implementation have so far prevented exploitation. However, the identified code signals, particularly `unserialize` and unescaped output, present serious inherent risks that significantly outweigh the benefits of its limited attack surface. The plugin should be reviewed and these specific vulnerabilities addressed.
Key Concerns
- Dangerous function 'unserialize' used
- Output not properly escaped
- Limited auth checks (capability/nonce)
RA – Registration Mail Address Domain Limiter Security Vulnerabilities
RA – Registration Mail Address Domain Limiter Code Analysis
Dangerous Functions Found
Output Escaping
RA – Registration Mail Address Domain Limiter Attack Surface
WordPress Hooks 6
Maintenance & Trust
RA – Registration Mail Address Domain Limiter Maintenance & Trust
Maintenance Signals
Community Trust
RA – Registration Mail Address Domain Limiter Alternatives
RA – Mod Multibyt Slug
ra-mod-multibyt-slug
When the multi-byte character is used in slug of new creation post, it changes so that post_type and post_ID may be used.
WP Mail SMTP by WPForms – The Most Popular SMTP and Email Log Plugin
wp-mail-smtp
Make email delivery easy for WordPress. Connect with SMTP, Gmail, Outlook, SendGrid, Mailgun, SES, Zoho, + more. Rated #1 WordPress SMTP Email plugin.
Hostinger Reach – AI-Powered Email Marketing for WordPress
hostinger-reach
Launch and grow your email marketing effortlessly with Hostinger Reach. Collect contacts, sync subscribers, and send emails – all in one, AI powered.
MC4WP: Mailchimp for WordPress
mailchimp-for-wp
The #1 Mailchimp plugin for WordPress. Allows you to add a multitude of newsletter sign-up methods to your site.
WP Multibyte Patch
wp-multibyte-patch
Multibyte functionality enhancement for the WordPress Japanese package.
RA – Registration Mail Address Domain Limiter Developer Profile
3 plugins · 90 total installs
How We Detect RA – Registration Mail Address Domain Limiter
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ra-registration-mail-address-domain-limiter/ra-mail-domain-limiter.cssra-registration-mail-address-domain-limiter/style.css?ver=ra-mail-domain-limiter.css?ver=HTML / DOM Fingerprints
id="rmadl_admin_css"