[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fbO48C03RCFxXWe0Pw6TR1ebLrfuexqqcPDtsFMr142o":3,"$f_w_7VBYMrPj5NlM7aCuwlk4ivVOGwjiHGVh3SqqwJ0Y":311,"$f2In_9K9h95Cj9pTq7HN72Rwgs654IparhcQe8wA4hWU":315},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":13,"last_updated":14,"tested_up_to":15,"requires_at_least":16,"requires_php":17,"tags":18,"homepage":24,"download_link":25,"security_score":26,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28,"discovery_status":29,"vulnerabilities":30,"developer":31,"crawl_stats":27,"alternatives":37,"analysis":136,"fingerprints":263},"registration-email-blocker","Registration Email Blocker","1.0.0","Patsikov Artem","https:\u002F\u002Fprofiles.wordpress.org\u002Faltcreative\u002F","\u003Cp>Registration Email Blocker is a WordPress plugin that restricts which email domains can be used for user registration on your website. The plugin was developed to help Russian website owners partially comply with Federal Law No. 406-FZ regarding user authorization requirements.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>How this plugin helps with compliance:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Federal Law 406-FZ requires Russian websites to use specific authorization methods (phone numbers, ESIA, or Russian-controlled systems). While the law does not directly address email-based registration, using foreign email services (gmail.com, yahoo.com, etc.) during registration may contradict the spirit of the law.\u003C\u002Fp>\n\u003Cp>This plugin helps in the following ways:\u003Cbr \u002F>\n* Prevents registration with foreign email domains (blacklist mode)\u003Cbr \u002F>\n* Allows registration only with approved domains (whitelist mode)\u003Cbr \u002F>\n* Identifies existing users with non-compliant email addresses\u003Cbr \u002F>\n* Sends notifications to users requesting email change\u003Cbr \u002F>\n* Provides audit logs of all registration attempts\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Important Legal Notice:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>This plugin is a technical tool and does not guarantee full compliance with Federal Law 406-FZ. The plugin addresses only the email domain aspect of user registration. Website owners remain responsible for ensuring full legal compliance. We recommend consulting with a lawyer regarding applicable legislation.\u003C\u002Fp>\n\u003Cp>The plugin helps eliminate one potential compliance issue but does not replace proper legal authorization systems required by law.\u003C\u002Fp>\n\u003Ch4>Key Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Two Operation Modes\u003C\u002Fstrong>: Blacklist (block specific domains) or Whitelist (allow only specific domains)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Flexible Enforcement\u003C\u002Fstrong>: Hard blocking or warning mode\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Existing User Management\u003C\u002Fstrong>: Automatically identifies users with non-compliant email addresses\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Bulk Email Notifications\u003C\u002Fstrong>: Send email change requests to affected users\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Detailed Logging\u003C\u002Fstrong>: Complete history of registration attempts with IP addresses and timestamps\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WooCommerce Integration\u003C\u002Fstrong>: Controls email domains during registration and checkout\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Domain Statistics\u003C\u002Fstrong>: Analyzes email domains used across all site users\u003C\u002Fli>\n\u003Cli>\u003Cstrong>CSV Export\u003C\u002Fstrong>: Export list of users with non-compliant emails\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Pre-configured Domain Lists\u003C\u002Fstrong>: Ready-to-use lists of popular foreign and Russian email services\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Administrator Exclusion\u003C\u002Fstrong>: Option to exempt administrators from domain checks\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Who Needs This Plugin\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Russian website owners required to comply with Federal Law 406-FZ\u003C\u002Fli>\n\u003Cli>Administrators who need to control user registration\u003C\u002Fli>\n\u003Cli>WooCommerce stores operating in Russia with customer email requirements\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Technical Details\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Works with standard WordPress registration\u003C\u002Fli>\n\u003Cli>Full WooCommerce compatibility\u003C\u002Fli>\n\u003Cli>Multisite compatible\u003C\u002Fli>\n\u003Cli>Translation ready\u003C\u002Fli>\n\u003Cli>GDPR considerations included\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Legal Compliance Notice\u003C\u002Fh3>\n\u003Cp>\u003Cstrong>Federal Law 406-FZ Compliance:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Federal Law No. 406-FZ (adopted July 26, 2023) establishes requirements for user authorization on Russian websites. The law requires authorization through:\u003Cbr \u002F>\n1. Mobile phone numbers\u003Cbr \u002F>\n2. ESIA (Unified Identification and Authentication System)\u003Cbr \u002F>\n3. Biometric identification system\u003Cbr \u002F>\n4. Russian-controlled information systems\u003C\u002Fp>\n\u003Cp>This plugin addresses the email domain aspect of user registration by preventing the use of foreign email services and encouraging the use of Russian email providers. However, \u003Cstrong>email-based registration is not explicitly addressed in the law\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>What This Plugin Does:\u003C\u002Fstrong>\u003Cbr \u002F>\n* Prevents registration with foreign email domains (gmail.com, yahoo.com, etc.)\u003Cbr \u002F>\n* Allows only approved Russian email domains (mail.ru, yandex.ru, etc.)\u003Cbr \u002F>\n* Identifies and notifies existing users with non-compliant emails\u003Cbr \u002F>\n* Provides audit logs for compliance verification\u003C\u002Fp>\n\u003Cp>\u003Cstrong>What This Plugin Does NOT Do:\u003C\u002Fstrong>\u003Cbr \u002F>\n* Does not implement phone number authorization\u003Cbr \u002F>\n* Does not integrate with ESIA\u003Cbr \u002F>\n* Does not provide biometric identification\u003Cbr \u002F>\n* Does not guarantee full legal compliance with Federal Law 406-FZ\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Responsibility:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Website owners are solely responsible for ensuring full compliance with Federal Law 406-FZ and all applicable legislation. This plugin is a technical tool that may assist with partial compliance but should not be considered a complete legal solution. We strongly recommend consulting with a lawyer regarding your specific compliance requirements.\u003C\u002Fp>\n\u003Ch3>Support Development\u003C\u002Fh3>\n\u003Cp>This plugin is completely free and will always remain free. If you find it useful, consider supporting its continued development and maintenance.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Your donation helps with:\u003C\u002Fstrong>\u003Cbr \u002F>\n* Adding new features based on user requests\u003Cbr \u002F>\n* Maintaining compatibility with new WordPress versions\u003Cbr \u002F>\n* Providing technical support\u003Cbr \u002F>\n* Creating documentation and tutorials\u003Cbr \u002F>\n* Ensuring compliance with changing legislation\u003C\u002Fp>\n\u003Cp>Even a small contribution helps the development team continue improving this plugin and creating other useful tools for the WordPress community.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Support via:\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Fyookassa.ru\u002Fmy\u002Fi\u002FaVPRSGFZeJmV\u002Fl\" rel=\"nofollow ugc\">YooKassa\u003C\u002Fa> (any amount)\u003C\u002Fp>\n\u003Cp>All donations are received through registered business entity (IP), ensuring full transparency and legal compliance with Russian tax requirements.\u003C\u002Fp>\n\u003Ch3>Additional Information\u003C\u002Fh3>\n\u003Cp>\u003Cstrong>Developer:\u003C\u002Fstrong> Altcreative Web Studio\u003Cbr \u002F>\n\u003Cstrong>Website:\u003C\u002Fstrong> https:\u002F\u002Faltcreative.ru\u003Cbr \u002F>\n\u003Cstrong>Support:\u003C\u002Fstrong> main@mail-altcreative.ru\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Recommendations:\u003C\u002Fstrong>\u003Cbr \u002F>\n* Install an SMTP plugin for reliable email delivery\u003Cbr \u002F>\n* Regularly check the “Problem Users” tab\u003Cbr \u002F>\n* Maintain backups before making bulk changes\u003Cbr \u002F>\n* Test settings in staging environment before deploying to production\u003Cbr \u002F>\n* Consult with a lawyer regarding full compliance with Federal Law 406-FZ\u003C\u002Fp>\n\u003Cp>\u003Cstrong>System Requirements:\u003C\u002Fstrong>\u003Cbr \u002F>\n* WordPress 6.0 or higher\u003Cbr \u002F>\n* PHP 8.0 or higher\u003Cbr \u002F>\n* MySQL 5.7 or higher (or MariaDB 10.2+)\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Compatibility:\u003C\u002Fstrong>\u003Cbr \u002F>\n* WordPress 6.0 – 6.7+\u003Cbr \u002F>\n* WooCommerce 7.0+\u003Cbr \u002F>\n* Multisite: Yes\u003Cbr \u002F>\n* Translation: Ready\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Privacy:\u003C\u002Fstrong>\u003Cbr \u002F>\n* The plugin stores registration attempt logs including email addresses and IP addresses\u003Cbr \u002F>\n* All data is stored locally in your WordPress database\u003Cbr \u002F>\n* No data is sent to external services\u003Cbr \u002F>\n* Logs can be cleared at any time by administrator\u003C\u002Fp>\n\u003Ch3>License\u003C\u002Fh3>\n\u003Cp>This plugin is licensed under GPL v2 or later.\u003C\u002Fp>\n\u003Cp>Copyright (C) 2026 Altcreative\u003C\u002Fp>\n\u003Cp>This program is free software: you can redistribute it and\u002For modify it under the terms of the GNU General Public License as published by the Free Software Foundation, either version 2 of the License, or (at your option) any later version.\u003C\u002Fp>\n\u003Cp>This program is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details.\u003C\u002Fp>\n","Block unwanted email domains during user registration. Helps Russian site owners comply with Federal Law 406-FZ requirements for user registration.",90,443,0,"2026-01-24T20:48:00.000Z","6.9.5","6.0","8.0",[19,20,21,22,23],"compliance","email","registration","russia","security","","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fregistration-email-blocker.1.0.0.zip",100,null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":32,"display_name":7,"profile_url":8,"plugin_count":33,"total_installs":11,"avg_security_score":26,"avg_patch_time_days":34,"trust_score":35,"computed_at":36},"altcreative",1,30,94,"2026-08-24T10:25:57.307Z",[38,58,81,98,112],{"slug":39,"name":40,"version":41,"author":42,"author_profile":43,"description":44,"short_description":45,"active_installs":26,"downloaded":46,"rating":47,"num_ratings":48,"last_updated":49,"tested_up_to":50,"requires_at_least":51,"requires_php":24,"tags":52,"homepage":55,"download_link":56,"security_score":57,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28},"dm-confirm-email","DM Confirm Email","1.4","Michael","https:\u002F\u002Fprofiles.wordpress.org\u002Fdonmhico\u002F","\u003Cp>Having so many spam registrations? Tired of getting fake users with fake emails? Good news! DM Confirm Email will solve your problems.\u003Cbr \u002F>\nDM Confirm Email will send a confirmation email and the only time it will actually “create” the account for the user if the email address is confirmed.\u003C\u002Fp>\n\u003Cp>Also allows you to send a welcome message to newly confirmed and created users which is great to give your new users initial instructions or other information that can be helpful to new users.\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"http:\u002F\u002Fdonmhi.co\u002Fprojects\u002Fdm-confirm-email\" rel=\"nofollow ugc\">DM Confirm Email\u003C\u002Fa> integrates seamlessly with wordpress registration system and uses all native registration hooks which allows all your current customization and plugins to the registration work.\u003C\u002Fp>\n\u003Ch4>Additional Resources\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Ca href=\"http:\u002F\u002Fdonmhi.co\u002Fprojects\u002Fdm-confirm-email\u002F#demo\" rel=\"nofollow ugc\">See DM Confirm Email in action\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Fview\u002Fplugin-reviews\u002Fdm-confirm-email\" rel=\"ugc\">Review the plugin and let me know what you think!\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Fplugin\u002Fdm-confirm-email\" rel=\"ugc\">Have a question? Or found a bug?\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"http:\u002F\u002Fdonmhi.co\u002Fprojects\u002Fdm-confirm-email\" rel=\"nofollow ugc\">For suggestions and ideas for future release. Comment here\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Ftwitter.com\u002Fdonmhico\" rel=\"nofollow ugc\">Follow me @donMhico\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Reduce unwanted and spam registration.\u003C\u002Fli>\n\u003Cli>Verifies and confirms email addresses of user registrations.\u003C\u002Fli>\n\u003Cli>Customize the confirmation email that will be sent.\u003C\u002Fli>\n\u003Cli>Allows html email content.\u003C\u002Fli>\n\u003Cli>Resend confirmation email feature\u003C\u002Fli>\n\u003Cli>Define the number of days before the confirmation keys will be expired.\u003C\u002Fli>\n\u003Cli>Customize all warning and successful messages in the wordpress side.\u003C\u002Fli>\n\u003Cli>Ability to send welcome message to new users.\u003C\u002Fli>\n\u003Cli>Prevents waste of resources and web space by only creating user account to confirmed emails.\u003C\u002Fli>\n\u003Cli>Uses all the native registration hooks for more advanced customization.\u003C\u002Fli>\n\u003Cli>Seamless integration\u003C\u002Fli>\n\u003Cli>NEW! Ability to edit the email message containing the password of the new account that will be sent to the user.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Future\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Display all pending registrations that need confirmation on the Dashboard.\u003C\u002Fli>\n\u003C\u002Ful>\n","Protect your wordpress site with spam registration. DM Confirm Email requires new users to confirm their email addresses.",22080,82,7,"2014-03-11T14:27:00.000Z","3.7.41","3.6",[53,20,21,23,54],"confirm","spam","http:\u002F\u002Fdonmhi.co\u002Fprojects\u002Fdm-confirm-email\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fdm-confirm-email.1.4.zip",85,{"slug":59,"name":60,"version":61,"author":62,"author_profile":63,"description":64,"short_description":65,"active_installs":66,"downloaded":67,"rating":26,"num_ratings":68,"last_updated":69,"tested_up_to":70,"requires_at_least":71,"requires_php":72,"tags":73,"homepage":78,"download_link":79,"security_score":80,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28},"validator-pizza","MailCheck.ai","1.3.0","tompec","https:\u002F\u002Fprofiles.wordpress.org\u002Ftompec\u002F","\u003Cp>\u003Cstrong>MailCheck.ai is now UserCheck.com\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Please install the \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fusercheck\u002F\" rel=\"ugc\">new version\u003C\u002Fa> of this plugin.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>MailCheck.ai is a powerful WordPress plugin that prevents disposable or throwaway email addresses from registering or commenting on your site. This helps to protect your site from spam and maintain the quality of your user base.\u003C\u002Fp>\n\u003Ch4>Key Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Automatically checks email addresses against a constantly updated database of disposable email domains\u003C\u002Fli>\n\u003Cli>Works out of the box with no configuration required\u003C\u002Fli>\n\u003Cli>No API key needed\u003C\u002Fli>\n\u003Cli>Caches results for improved performance\u003C\u002Fli>\n\u003Cli>Seamlessly integrates with WordPress registration and comment forms\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>The plugin uses the API provided by \u003Ca href=\"https:\u002F\u002Fwww.mailcheck.ai\" rel=\"nofollow ugc\">MailCheck.ai\u003C\u002Fa>, which is constantly updated to include the latest disposable email domains. This ensures your site stays protected against new disposable email providers.\u003C\u002Fp>\n\u003Cp>MailCheck.ai is free to use and starts working immediately after installation. No registration or configuration is required.\u003C\u002Fp>\n","Prevent disposable email addresses from registering or commenting on your site with MailCheck.ai.",50,5150,4,"2024-08-27T03:13:00.000Z","6.6.5","5.2","7.2",[74,75,23,76,77],"disposable-email","email-validation","spam-prevention","user-registration","https:\u002F\u002Fwww.mailcheck.ai","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fvalidator-pizza.1.3.0.zip",92,{"slug":82,"name":83,"version":84,"author":85,"author_profile":86,"description":87,"short_description":88,"active_installs":34,"downloaded":89,"rating":13,"num_ratings":13,"last_updated":90,"tested_up_to":91,"requires_at_least":16,"requires_php":92,"tags":93,"homepage":96,"download_link":97,"security_score":26,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28},"page-authority-allowed-domains","Page Authority – Allowed Domains","2.0.2","Talisa @ Page Authority","https:\u002F\u002Fprofiles.wordpress.org\u002Ftwestford\u002F","\u003Cp>Restrict WordPress user accounts to administrator-approved email domains.\u003C\u002Fp>\n\u003Cp>Page Authority – Allowed Domains gives administrators a simple way to control which email domains are permitted when WordPress user accounts are created. When the allowlist is set, any attempt to create a user with an email outside the approved domains is blocked across the standard registration form, the REST API, and WooCommerce registration.\u003C\u002Fp>\n\u003Cp>It is designed for sites where only users from specific organizations, companies, clients, or teams should be added as WordPress users. Typical use cases include internal company portals where only staff email addresses should ever become accounts, agency-managed client sites that should reject public signups, membership or B2B sites that vet users by their email domain, and multisite networks that need consistent domain rules across sites.\u003C\u002Fp>\n\u003Cp>Existing users are never modified automatically. Instead, the Existing User Audit highlights accounts whose email domains are not on the allowlist so an administrator can review and act on them individually, including removing an account and reassigning its content.\u003C\u002Fp>\n\u003Cp>Features include:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Admin-managed allowed domain list\u003C\u002Fli>\n\u003Cli>Standard WordPress registration enforcement\u003C\u002Fli>\n\u003Cli>REST API user creation\u002Fupdate enforcement\u003C\u002Fli>\n\u003Cli>WooCommerce registration enforcement\u003C\u002Fli>\n\u003Cli>Existing User Audit tools\u003C\u002Fli>\n\u003Cli>Optional login enforcement\u003C\u002Fli>\n\u003Cli>Per-user unauthorized account removal with content reassignment\u003C\u002Fli>\n\u003Cli>Multisite-aware protections\u003C\u002Fli>\n\u003Cli>Lightweight architecture with no custom database tables\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Security Notes\u003C\u002Fh3>\n\u003Cp>The plugin includes:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Capability checks\u003C\u002Fli>\n\u003Cli>Nonce verification (verified before any state-changing logic runs)\u003C\u002Fli>\n\u003Cli>Sanitization and escaping\u003C\u002Fli>\n\u003Cli>Live revalidation before destructive actions\u003C\u002Fli>\n\u003Cli>Current-admin protection\u003C\u002Fli>\n\u003Cli>Multisite Super Admin protection\u003C\u002Fli>\n\u003Cli>Explicit content reassignment or delete confirmation before user removal\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Recommended operational practices:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Review the Existing User Audit before enabling login blocking\u003C\u002Fli>\n\u003Cli>Test custom registration and SSO flows before production rollout\u003C\u002Fli>\n\u003Cli>Maintain regular database backups before deleting users\u003C\u002Fli>\n\u003Cli>Restrict plugin management access to trusted administrators only\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Uninstall\u003C\u002Fh3>\n\u003Cp>Deleting the plugin removes its current options:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ccode>pageauth_allowed_domains\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>\u003Ccode>pageauth_audit_log\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>\u003Ccode>pageauth_block_unauthorized_logins\u003C\u002Fcode>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>It also cleans up internal flags, transients, user meta, and any leftover keys from prior plugin versions that used the \u003Ccode>paad_\u003C\u002Fcode> or \u003Ccode>aed_\u003C\u002Fcode> prefixes. On multisite, the matching network options are removed as well.\u003C\u002Fp>\n","Restrict WordPress user accounts to administrator-approved email domains.",279,"2026-06-28T19:23:00.000Z","7.0.2","7.4",[94,20,21,23,95],"domains","users","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fpage-authority-allowed-domains\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fpage-authority-allowed-domains.2.0.2.zip",{"slug":99,"name":100,"version":6,"author":101,"author_profile":102,"description":103,"short_description":104,"active_installs":13,"downloaded":105,"rating":13,"num_ratings":13,"last_updated":106,"tested_up_to":91,"requires_at_least":107,"requires_php":92,"tags":108,"homepage":110,"download_link":111,"security_score":26,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28},"doltics-radar","Doltics Radar","doltics","https:\u002F\u002Fprofiles.wordpress.org\u002Fdoltics\u002F","\u003Cp>Doltics Radar checks enabled WordPress flows before they complete. Admins can enable protection for outbound email, submitted comments, and account registrations under Settings > Doltics Radar.\u003C\u002Fp>\n\u003Cp>Email protection uses WordPress core mail hooks when available. Doltics Radar also includes a Mailgun compatibility adapter for Mailgun versions that replace \u003Ccode>wp_mail()\u003C\u002Fcode> without calling \u003Ccode>pre_wp_mail\u003C\u002Fcode>.\u003C\u002Fp>\n\u003Ch3>API Contract\u003C\u002Fh3>\n\u003Cp>The plugin sends a JSON \u003Ccode>POST\u003C\u002Fcode> request to the URL \u003Ccode>https:\u002F\u002Fradar.doltics.com\u002Fscore\u003C\u002Fcode> :\u003C\u002Fp>\n\u003Cpre>\u003Ccode>{\n  \"text\": \"The sample text\",\n  \"locale\": \"en\"\n}\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>The API should return JSON using one of these response shapes:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>{\n  \"score\": 0.95,\n  \"classification\": \"spam\",\n  \"signals\": {\n    \"token_count\": 10,\n    \"unknown_word_ratio\": 0.1,\n    \"spam_keyword_score\": 0.61,\n    \"uppercase_ratio\": 0.34,\n    \"exclamation_density\": 0.3,\n    \"url_count\": 1\n  }\n}\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>Numeric scores are compared against the configured threshold.\u003C\u002Fp>\n","Protects selected WordPress email, comment, and registration flows with a spam protection API.",105,"2026-06-03T09:23:00.000Z","5.7",[109,20,21,23,54],"comments","https:\u002F\u002Fdoltics.com\u002Fproducts\u002Fradar\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fdoltics-radar.1.0.0.zip",{"slug":113,"name":114,"version":115,"author":116,"author_profile":117,"description":118,"short_description":119,"active_installs":120,"downloaded":121,"rating":122,"num_ratings":123,"last_updated":124,"tested_up_to":91,"requires_at_least":16,"requires_php":125,"tags":126,"homepage":131,"download_link":132,"security_score":133,"vuln_count":134,"unpatched_count":13,"last_vuln_date":135,"fetched_at":28},"aryo-activity-log","Activity Log – Monitor & Record User Changes","2.11.2","Elementor","https:\u002F\u002Fprofiles.wordpress.org\u002Felemntor\u002F","\u003Cp>\u003Cstrong>AN EASY TO USE & FULLY SUPPORTED WORDPRESS ACTIVITY LOG PLUGIN\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Want to monitor and track your WordPress website activity? Find out exactly who does what on your WordPress website with this plugin. Activity Log is like an airplane’s black box that logs every action in the WordPress admin, and lets you see exactly what users are doing on your WordPress website.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>If someone is trying to hack your site\u003C\u002Fli>\n\u003Cli>When a post was published, and who published it\u003C\u002Fli>\n\u003Cli>If a plugin\u002Ftheme was activated\u002Fdeactivated\u003C\u002Fli>\n\u003Cli>Suspicious admin activity\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>It’s so essential; you’ll wonder how you ever managed your website without it. The plugin is also lightning fast and works behind the scenes, so it doesn\\’t affect site and admin performance. For optimal performance, we built the plugin so that it runs on a separate table in the database.\u003C\u002Fp>\n\u003Cp>If you have more than a handful of users, keeping track of who did what is virtually impossible. This plugin solves that issue by tracking what actions were initiated by which users, and displaying it in an easy-to-use and easy-to-filter view on the dashboard of your WordPress site.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>New! Introducing Email Logging\u003C\u002Fstrong> – Capture all emails sent from your WordPress site for streamlined debugging and compliance. Gain better visibility into email communication, aiding both troubleshooting and record-keeping. This is particularly beneficial for WooCommerce stores, allowing you to easily track sent emails alongside other critical site events.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Export to CSV\u003C\u002Fstrong> – Export your Activity Log data records to CSV. Developers can easily add support for custom data formats with our new dedicated Export API.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Data Privacy and GDPR Compliance\u003C\u002Fstrong> – We provide the tools to help you adhere to GDPR compliance standards, including Export\u002FErasure of data via the WordPress Privacy Tools.\u003C\u002Fp>\n\u003Ch3>With the Activity Log you can record:\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>WordPress\u003C\u002Fstrong> – Core updates\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Posts\u003C\u002Fstrong> – Created, updated, deleted\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Pages\u003C\u002Fstrong> – Created, updated, deleted\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Custom Post Type\u003C\u002Fstrong> – Created, updated, deleted\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Tags\u003C\u002Fstrong> – Created, updated, deleted\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Categories\u003C\u002Fstrong> – Created, updated, deleted\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Taxonomies\u003C\u002Fstrong> – Created, updated, deleted\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Menus\u003C\u002Fstrong> – Created, updated, deleted\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Media\u003C\u002Fstrong> – Created, updated, deleted\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Comments\u003C\u002Fstrong> – Created, approved, unapproved, trashed, untrashed, spammed, unspammed, deleted\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Users\u003C\u002Fstrong> – Login, logout, login failed, update profile, registered, deleted\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Plugins\u003C\u002Fstrong> – Installed, updated, activated, deactivated, changed\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Themes\u003C\u002Fstrong> – Installed, updated, deleted, activated, changed (Editor and Customizer)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Widgets\u003C\u002Fstrong> – Added to sidebar, deleted from sidebar, order widgets\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Setting\u003C\u002Fstrong> – General, writing, reading, discussion, media, permalinks\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Options\u003C\u002Fstrong> – Extended custom settings for 3rd party plugins\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Export\u003C\u002Fstrong> – Exported activity log file\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WooCommerce\u003C\u002Fstrong> – Track products, orders, customers, and more\u003C\u002Fli>\n\u003Cli>\u003Cstrong>bbPress\u003C\u002Fstrong> – Forums, topics, replies, taxonomies, and other actions\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Emails sent from WordPress site\u003C\u002Fstrong> – Sending successful, sending failed\u003C\u002Fli>\n\u003Cli>There’s more, of course, but you get the point…\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>For each event recorded by the activity log, the following details are also logged:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Date and time of occurrence\u003C\u002Fli>\n\u003Cli>User and user role responsible for the change\u003C\u002Fli>\n\u003Cli>Source IP address from which the change originated\u003C\u002Fli>\n\u003Cli>Affected object where the change occurred\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>The plugin doesn\\’t require any kind of setup; it works right out of the box (just another reason people love it)!\u003C\u002Fp>\n\u003Ch3>Data Storage and Performance Optimization\u003C\u002Fh3>\n\u003Cp>In order to ensure optimal performance of your website, all events and logs data are stored in a dedicated custom table within your WordPress database. This approach significantly reduces the impact on your website’s performance, ensuring seamless operation even during peak traffic periods.\u003C\u002Fp>\n\u003Ch3>Uninstall Clean-up\u003C\u002Fh3>\n\u003Cp>We understand the importance of maintaining a clean and efficient database environment. That’s why our plugin features an uninstall hook that seamlessly removes all traces of its presence from your website when uninstalling. This meticulous clean-up process ensures that your database remains lean and clutter-free even after our plugin has been removed.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>With our optimized data storage, thorough logging, and meticulous clean-up process, you can trust that our plugin will enhance the functionality and security of your WordPress site without compromising its performance.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Ch3>What users have to say\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cem>“Its tools, particularly for data privacy and GDPR compliance, make it indispensable for websites operating within European Union boundaries or dealing with EU citizens’ data”\u003C\u002Fem> – \u003Ca href=\"https:\u002F\u002Fblog.hubspot.com\u002Fwebsite\u002F8-best-plugins-tracking-user-activity-wordpress\" rel=\"nofollow ugc\">HubSpot.com\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Cem>“If you’re after a competent WP security audit log plugin with all the basic features you need, Activity Log is it!”\u003C\u002Fem> – \u003Ca href=\"https:\u002F\u002Fwpastra.com\u002Fplugins\u002Fwordpress-activity-log-plugins\u002F\" rel=\"nofollow ugc\">WPAstra.com\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Cem>“Activity Log features a remarkably straightforward dashboard interface, providing administrators with an at-a-glance understanding of site interactions”\u003C\u002Fem> – \u003Ca href=\"https:\u002F\u002Fwww.malcare.com\u002Fblog\u002Fwordpress-activity-log\u002F\" rel=\"nofollow ugc\">Malcare.com\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Cem>“Best 10 Free WordPress Plugins of the Month: Keeping tabs on what your users do with their access to the Dashboard”\u003C\u002Fem> – \u003Ca href=\"https:\u002F\u002Fmanagewp.com\u002Fbest-free-wordpress-plugins-july-2014\" rel=\"nofollow ugc\">ManageWP.com\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Cem>“Thanks to this step, we’ve discovered that our site was undergoing a brute force attack”\u003C\u002Fem> – \u003Ca href=\"https:\u002F\u002Fartdriver.com\u002Fblog\u002Fwordpress-site-hacked-solution-time\" rel=\"nofollow ugc\">Artdriver.com\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Cem>“Optimized code – The plugin itself is blazing fast and leaves almost no footprint on the server”\u003C\u002Fem> – \u003Ca href=\"https:\u002F\u002Fwww.freshtechtips.com\u002F2014\u002F01\u002Fbest-audit-trail-plugins-for-wordpress.html\" rel=\"nofollow ugc\">FreshTechTips.com\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Cem>“Activity Log lets you track a huge range of activities. Overall, very easy to use and setup”\u003C\u002Fem> – \u003Ca href=\"https:\u002F\u002Fwww.elegantthemes.com\u002Fblog\u002Ftips-tricks\u002F5-best-ways-to-monitor-wordpress-activity-via-the-dashboard\" rel=\"nofollow ugc\">ElegantThemes.com\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Contributions:\u003C\u002Fh3>\n\u003Cp>\u003Cstrong>Would you like to contribute to this plugin?\u003C\u002Fstrong> You’re more than welcome to submit your pull requests on the \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fpojome\u002Factivity-log\" rel=\"nofollow ugc\">GitHub repo\u003C\u002Fa>. And, if you have any notes about the code, please open a ticket on the issue tracker.\u003C\u002Fp>\n","This top rated Activity Log plugin helps you monitor & log all changes and actions on your WordPress site, so you can remain secure and organized.",200000,4041821,86,74,"2026-06-07T11:49:00.000Z","7.0",[127,128,129,23,130],"activity-log","audit-log","email-log","user-log","https:\u002F\u002Factivitylog.io\u002F?utm_source=wp-plugins&utm_campaign=plugin-uri&utm_medium=wp-dash","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Faryo-activity-log.2.11.2.zip",93,9,"2024-11-20 17:10:23",{"attackSurface":137,"codeSignals":195,"taintFlows":205,"riskAssessment":254,"analyzedAt":262},{"hooks":138,"ajaxHandlers":177,"restRoutes":191,"shortcodes":192,"cronEvents":193,"entryPointCount":194,"unprotectedCount":13},[139,145,149,154,160,164,167,171,175],{"type":140,"name":141,"callback":142,"file":143,"line":144},"action","admin_menu","add_admin_menu","includes\u002Fadmin-page.php",28,{"type":140,"name":146,"callback":147,"file":143,"line":148},"admin_init","register_settings",29,{"type":140,"name":150,"callback":151,"file":152,"line":153},"plugins_loaded","load_textdomain","registration-email-blocker.php",81,{"type":155,"name":156,"callback":157,"priority":158,"file":152,"line":159},"filter","registration_errors","validate_registration_email",10,84,{"type":155,"name":161,"callback":162,"priority":158,"file":152,"line":163},"woocommerce_registration_errors","validate_woocommerce_email",87,{"type":140,"name":165,"callback":166,"priority":158,"file":152,"line":11},"woocommerce_after_checkout_validation","validate_woocommerce_checkout_email",{"type":140,"name":168,"callback":169,"file":152,"line":170},"admin_enqueue_scripts","enqueue_admin_assets",96,{"type":140,"name":172,"callback":173,"file":152,"line":174},"login_form","display_registration_warnings",99,{"type":140,"name":176,"callback":173,"file":152,"line":26},"register_form",[178,183,187],{"action":179,"nopriv":180,"callback":181,"hasNonce":182,"hasCapCheck":182,"file":143,"line":34},"REGIEMBL_send_notifications",false,"ajax_send_notifications",true,{"action":184,"nopriv":180,"callback":185,"hasNonce":182,"hasCapCheck":182,"file":143,"line":186},"REGIEMBL_export_users","ajax_export_users",31,{"action":188,"nopriv":180,"callback":189,"hasNonce":182,"hasCapCheck":182,"file":143,"line":190},"REGIEMBL_clear_logs","ajax_clear_logs",32,[],[],[],3,{"dangerousFunctions":196,"sqlUsage":197,"outputEscaping":200,"fileOperations":33,"externalRequests":13,"nonceChecks":194,"capabilityChecks":203,"bundledLibraries":204},[],{"prepared":198,"raw":13,"locations":199},16,[],{"escaped":201,"rawEcho":13,"locations":202},153,[],5,[],[206,224,237,245],{"entryPoint":207,"graph":208,"unsanitizedCount":33,"severity":223},"display_registration_warnings (registration-email-blocker.php:106)",{"nodes":209,"edges":221},[210,215],{"id":211,"type":212,"label":213,"file":152,"line":214},"n0","source","$_GET",113,{"id":216,"type":217,"label":218,"file":152,"line":219,"wp_function":220},"n1","sink","echo() [XSS]",114,"echo",[222],{"from":211,"to":216,"sanitized":180},"medium",{"entryPoint":225,"graph":226,"unsanitizedCount":13,"severity":236},"\u003Cadmin-page> (includes\u002Fadmin-page.php:0)",{"nodes":227,"edges":234},[228,230],{"id":211,"type":212,"label":213,"file":143,"line":229},488,{"id":216,"type":217,"label":231,"file":143,"line":232,"wp_function":233},"get_results() [SQLi]",496,"get_results",[235],{"from":211,"to":216,"sanitized":182},"low",{"entryPoint":238,"graph":239,"unsanitizedCount":33,"severity":236},"\u003Cregistration-email-blocker> (registration-email-blocker.php:0)",{"nodes":240,"edges":243},[241,242],{"id":211,"type":212,"label":213,"file":152,"line":214},{"id":216,"type":217,"label":218,"file":152,"line":219,"wp_function":220},[244],{"from":211,"to":216,"sanitized":180},{"entryPoint":246,"graph":247,"unsanitizedCount":33,"severity":253},"render_logs_tab (includes\u002Fadmin-page.php:482)",{"nodes":248,"edges":251},[249,250],{"id":211,"type":212,"label":213,"file":143,"line":229},{"id":216,"type":217,"label":231,"file":143,"line":232,"wp_function":233},[252],{"from":211,"to":216,"sanitized":180},"high",{"summary":255,"deductions":256},"The \"registration-email-blocker\" v1.0.0 plugin exhibits a generally good security posture, with several key strengths. All identified entry points, including AJAX handlers, are protected by appropriate authorization checks (nonces and capability checks). The plugin demonstrates excellent SQL hygiene by exclusively using prepared statements and robust output escaping practices, with all 153 outputs properly escaped. The absence of any known vulnerabilities in its history further suggests a well-maintained and secure codebase.\n\nHowever, the static analysis reveals one significant concern: a high-severity taint flow. This indicates a potential pathway where untrusted data could be processed without adequate sanitization, potentially leading to vulnerabilities if exploited. While the overall attack surface is small and lacks unauthenticated entry points, this high-severity taint flow is the primary risk to address. The presence of three flows with unsanitized paths, although not rated critical or high in severity, warrants investigation to ensure they don't pose a latent risk.\n\nIn conclusion, the plugin is strong in its fundamental security implementations like authentication, SQL, and output handling. The vulnerability history is a positive sign. The main weakness lies in the identified high-severity taint flow, which requires immediate attention. Addressing this specific risk would significantly bolster the plugin's security.",[257,260],{"reason":258,"points":259},"High severity taint flow detected",15,{"reason":261,"points":194},"Unsanitized path in taint analysis (3 flows)","2026-04-16T11:21:23.730Z",{"wat":264,"direct":273},{"assetPaths":265,"generatorPatterns":268,"scriptPaths":269,"versionParams":270},[266,267],"\u002Fwp-content\u002Fplugins\u002Fregistration-email-blocker\u002Fcss\u002Fadmin-style.css","\u002Fwp-content\u002Fplugins\u002Fregistration-email-blocker\u002Fjs\u002Fadmin-script.js",[],[267],[271,272],"registration-email-blocker\u002Fcss\u002Fadmin-style.css?ver=","registration-email-blocker\u002Fjs\u002Fadmin-script.js?ver=",{"cssClasses":274,"htmlComments":276,"htmlAttributes":305,"restEndpoints":307,"jsGlobals":308,"shortcodeOutput":310},[275],"regiembl-admin-wrapper",[277,278,279,280,281,282,283,284,285,286,287,288,289,290,291,292,293,294,295,296,296,288,297,298,299,300,289,301,302,303,304],"\u003C!-- Защита от прямого доступа -->","\u003C!-- Константы плагина -->","\u003C!-- Основной класс плагина Registration Email Blocker -->","\u003C!-- Единственный экземпляр класса -->","\u003C!-- Получить экземпляр класса (Singleton) -->","\u003C!-- Конструктор -->","\u003C!-- Загрузка зависимостей -->","\u003C!-- Подключаем валидатор -->","\u003C!-- Подключаем админ-панель -->","\u003C!-- Подключаем обработчик email -->","\u003C!-- Инициализация хуков -->","\u003C!-- Активация плагина -->","\u003C!-- Деактивация плагина -->","\u003C!-- Загрузка текстового домена для переводов -->","\u003C!-- Хук для проверки email при регистрации (стандартная регистрация WordPress) -->","\u003C!-- Хук для WooCommerce регистрации -->","\u003C!-- Хук для WooCommerce checkout -->","\u003C!-- Добавление ссылки настроек на странице плагинов -->","\u003C!-- Подключение стилей и скриптов для админки -->","\u003C!-- Отображение предупреждений на странице регистрации -->","\u003C!-- Создаем таблицу для логов -->","\u003C!-- Устанавливаем настройки по умолчанию -->","\u003C!-- Сохраняем настройки только если их еще нет -->","\u003C!-- Сохраняем версию плагина -->","\u003C!-- Очищаем scheduled events если будут -->","\u003C!-- Загрузка переводов -->","\u003C!-- Валидация email при стандартной регистрации WordPress -->","\u003C!-- Валидация email при регистрации WooCommerce -->",[306],"data-regiembl-action",[],[309],"regiembl_admin_script",[],{"error":182,"url":312,"statusCode":313,"statusMessage":314,"message":314},"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fregistration-email-blocker\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":33,"versions":316},[317],{"version":6,"download_url":25,"svn_tag_url":318,"released_at":27,"has_diff":180,"diff_files_changed":319,"diff_lines":27,"trac_diff_url":27,"vulnerabilities":320,"is_current":182},"https:\u002F\u002Fplugins.svn.wordpress.org\u002Fregistration-email-blocker\u002Ftags\u002F1.0.0\u002F",[],[]]