
Registration Email Blocker Security & Risk Analysis
wordpress.org/plugins/registration-email-blockerBlock unwanted email domains during user registration. Helps Russian site owners comply with Federal Law 406-FZ requirements for user registration.
Is Registration Email Blocker Safe to Use in 2026?
Generally Safe
Score 100/100Registration Email Blocker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "registration-email-blocker" v1.0.0 plugin exhibits a generally good security posture, with several key strengths. All identified entry points, including AJAX handlers, are protected by appropriate authorization checks (nonces and capability checks). The plugin demonstrates excellent SQL hygiene by exclusively using prepared statements and robust output escaping practices, with all 153 outputs properly escaped. The absence of any known vulnerabilities in its history further suggests a well-maintained and secure codebase.
However, the static analysis reveals one significant concern: a high-severity taint flow. This indicates a potential pathway where untrusted data could be processed without adequate sanitization, potentially leading to vulnerabilities if exploited. While the overall attack surface is small and lacks unauthenticated entry points, this high-severity taint flow is the primary risk to address. The presence of three flows with unsanitized paths, although not rated critical or high in severity, warrants investigation to ensure they don't pose a latent risk.
In conclusion, the plugin is strong in its fundamental security implementations like authentication, SQL, and output handling. The vulnerability history is a positive sign. The main weakness lies in the identified high-severity taint flow, which requires immediate attention. Addressing this specific risk would significantly bolster the plugin's security.
Key Concerns
- High severity taint flow detected
- Unsanitized path in taint analysis (3 flows)
Registration Email Blocker Security Vulnerabilities
Registration Email Blocker Release Timeline
Registration Email Blocker Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Registration Email Blocker Attack Surface
AJAX Handlers 3
WordPress Hooks 9
Maintenance & Trust
Registration Email Blocker Maintenance & Trust
Maintenance Signals
Community Trust
Registration Email Blocker Alternatives
DM Confirm Email
dm-confirm-email
Protect your wordpress site with spam registration. DM Confirm Email requires new users to confirm their email addresses.
MailCheck.ai
validator-pizza
Prevent disposable email addresses from registering or commenting on your site with MailCheck.ai.
Page Authority – Allowed Domains
page-authority-allowed-domains
Restrict WordPress user accounts to administrator-approved email domains.
Doltics Radar
doltics-radar
Protects selected WordPress email, comment, and registration flows with a spam protection API.
Activity Log – Monitor & Record User Changes
aryo-activity-log
This top rated Activity Log plugin helps you monitor & log all changes and actions on your WordPress site, so you can remain secure and organized.
Registration Email Blocker Developer Profile
1 plugin · 90 total installs
How We Detect Registration Email Blocker
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/registration-email-blocker/css/admin-style.css/wp-content/plugins/registration-email-blocker/js/admin-script.js/wp-content/plugins/registration-email-blocker/js/admin-script.jsregistration-email-blocker/css/admin-style.css?ver=registration-email-blocker/js/admin-script.js?ver=HTML / DOM Fingerprints
regiembl-admin-wrapper<!-- Защита от прямого доступа --><!-- Константы плагина --><!-- Основной класс плагина Registration Email Blocker --><!-- Единственный экземпляр класса -->+27 moredata-regiembl-actionregiembl_admin_script