Reoon Email Verifier Security & Risk Analysis

wordpress.org/plugins/reoon-email-verifier

Safeguard your online forms against invalid, temporary, disposable, and harmful email addresses with real-time verification.

600 active installs v2.1.1 PHP 7.4+ WP 4.7+ Updated Jan 18, 2026
block-spam-registrationemail-validatoremail-verifierform-email-validationtemporary-email-blocker
99
A · Safe
CVEs total1
Unpatched0
Last CVEOct 9, 2025
Safety Verdict

Is Reoon Email Verifier Safe to Use in 2026?

Generally Safe

Score 99/100

Reoon Email Verifier has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Oct 9, 2025Updated 4mo ago
Risk Assessment

The reoon-email-verifier v2.1.1 plugin presents a mixed security posture. On the positive side, it demonstrates good practices in handling SQL queries with 100% prepared statements and a high percentage of properly escaped outputs. The absence of dangerous functions and file operations further contributes to a relatively contained code base. However, significant concerns arise from the attack surface. With three AJAX handlers identified, all of which lack authentication checks, there is a substantial risk of unauthorized actions being performed. The taint analysis, while limited in scope (two flows analyzed), identified two flows with unsanitized paths, though these did not escalate to critical or high severity in this assessment. The vulnerability history shows one known CVE, which has since been patched, and a past common vulnerability type of "Missing Authorization," aligning with the current findings of unprotected AJAX handlers. This suggests a historical pattern that needs continued vigilance. Overall, while the plugin shows strengths in its data handling and output sanitization, the lack of authorization on its AJAX endpoints represents a critical weakness that could be exploited.

Key Concerns

  • Unprotected AJAX handlers
  • Taint flows with unsanitized paths
  • Lack of nonce checks on AJAX
  • Low number of capability checks
Vulnerabilities
1 published

Reoon Email Verifier Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-62938medium · 4.3Missing Authorization

Reoon Email Verifier <= 2.0.1 - Missing Authorization

Oct 9, 2025 Patched in 2.1.1 (64d)
Version History

Reoon Email Verifier Release Timeline

v2.1.1Current
v2.0.11 CVE
v1.3.21 CVE
v1.3.11 CVE
v1.2.61 CVE
v1.2.51 CVE
Code Analysis
Analyzed Mar 16, 2026

Reoon Email Verifier Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
10
84 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

89% escaped94 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
validate_reoon_api (includes\ajax-class.php:116)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
3 unprotected

Reoon Email Verifier Attack Surface

Entry Points3
Unprotected3

AJAX Handlers 3

authwp_ajax_validate_reoon_apiincludes\ajax-class.php:18
authwp_ajax_validate_reoon_emailincludes\ajax-class.php:19
authwp_ajax_reoon_remove_api_keyincludes\ajax-class.php:20
WordPress Hooks 27
actionadmin_menureoon-email-verifier.php:91
actionadmin_initreoon-email-verifier.php:92
actionadmin_enqueue_scriptsreoon-email-verifier.php:93
actionplugins_loadedreoon-email-verifier.php:95
filterplugin_action_links_reoon-email-verifier/reoon-email-verifier.phpreoon-email-verifier.php:99
filtergform_validationreoon-email-verifier.php:166
filterfrm_validate_field_entryreoon-email-verifier.php:171
filterwpcf7_validate_emailreoon-email-verifier.php:176
filterwpcf7_validate_email*reoon-email-verifier.php:177
filterregistration_errorsreoon-email-verifier.php:181
actionwoocommerce_checkout_processreoon-email-verifier.php:185
filterninja_forms_submit_datareoon-email-verifier.php:190
actionelementor_pro/forms/validation/emailreoon-email-verifier.php:195
actionwpforms_process_validate_emailreoon-email-verifier.php:200
filterfluentform/validate_input_item_input_emailreoon-email-verifier.php:205
filterforminator_custom_form_submit_errorsreoon-email-verifier.php:210
filterhappyforms_validate_part_submissionreoon-email-verifier.php:215
filtercntctfrm_check_formreoon-email-verifier.php:220
filterpreprocess_commentreoon-email-verifier.php:225
actionmailmint_before_form_submitreoon-email-verifier.php:230
filtereverest_forms_visible_fieldsreoon-email-verifier.php:235
filtersurecart/checkout/validatereoon-email-verifier.php:240
filterwsf_action_email_email_validatereoon-email-verifier.php:254
actionjet-form-builder/form-handler/before-sendreoon-email-verifier.php:271
actionmetform_before_store_form_datareoon-email-verifier.php:276
filterbuddyforms_form_custom_validationreoon-email-verifier.php:281
filterbitform_filter_form_validationreoon-email-verifier.php:286
Maintenance & Trust

Reoon Email Verifier Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 18, 2026
PHP min version7.4
Downloads6K

Community Trust

Rating100/100
Number of ratings3
Active installs600
Developer Profile

Reoon Email Verifier Developer Profile

Reoon Technology

1 plugin · 600 total installs

87
trust score
Avg Security Score
99/100
Avg Patch Time
64 days
View full developer profile
Detection Fingerprints

How We Detect Reoon Email Verifier

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/reoon-email-verifier/assets/css/admin.css/wp-content/plugins/reoon-email-verifier/assets/js/admin.js/wp-content/plugins/reoon-email-verifier/assets/js/frontend.js
Script Paths
/wp-content/plugins/reoon-email-verifier/assets/js/admin.js/wp-content/plugins/reoon-email-verifier/assets/js/frontend.js
Version Parameters
reoon-email-verifier/assets/css/admin.css?ver=reoon-email-verifier/assets/js/admin.js?ver=reoon-email-verifier/assets/js/frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
reoonev-validation-error
Data Attributes
data-reoonev-options
JS Globals
REOONEV
FAQ

Frequently Asked Questions about Reoon Email Verifier