Truelist Email Validator Security & Risk Analysis

wordpress.org/plugins/truelist-email-validator

Validate email addresses in real-time on WordPress forms using the Truelist API. Block invalid, disposable, and role-based emails.

0 active installs v1.0.0 PHP 8.0+ WP 5.9+ Updated Apr 10, 2026
contact-formdisposable-emailemail-validationemail-verificationspam-protection
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Truelist Email Validator Safe to Use in 2026?

Generally Safe

Score 100/100

Truelist Email Validator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "truelist-email-validator" plugin v1.0.0 exhibits a strong security posture based on the provided static analysis. The absence of critical findings in taint analysis, along with 100% of SQL queries using prepared statements and all output being properly escaped, indicates good development practices for handling sensitive data and preventing common injection vulnerabilities. The plugin also correctly implements nonce and capability checks for its AJAX entry points, and there are no REST API routes or shortcodes to further expand the attack surface without proper authorization.

The vulnerability history shows a complete lack of known CVEs, which is a very positive indicator of the plugin's security track record. This suggests that the developers are either maintaining a very secure codebase or have not yet been the target of widespread vulnerability discovery. The limited external HTTP requests and the absence of file operations further minimize potential attack vectors.

Overall, this plugin appears to be well-secured. Its strengths lie in robust data handling, secure entry point management, and a clean vulnerability history. While the attack surface is small and protected, the potential for future vulnerabilities cannot be entirely dismissed, but based on current data, the risk is exceptionally low.

Vulnerabilities
None known

Truelist Email Validator Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Truelist Email Validator Release Timeline

v1.0.0Current
Code Analysis
Analyzed Apr 16, 2026

Truelist Email Validator Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
0
37 escaped
Nonce Checks
2
Capability Checks
1
File Operations
0
External Requests
2
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

100% escaped37 total outputs
Attack Surface

Truelist Email Validator Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 3

authwp_ajax_truelist_validateincludes/class-truelist-ajax.php:20
noprivwp_ajax_truelist_validateincludes/class-truelist-ajax.php:21
authwp_ajax_truelist_test_api_keyincludes/class-truelist-settings.php:12
WordPress Hooks 12
actionwp_enqueue_scriptsincludes/class-truelist-ajax.php:22
actionadmin_menuincludes/class-truelist-settings.php:10
actionadmin_initincludes/class-truelist-settings.php:11
actionadmin_enqueue_scriptsincludes/class-truelist-settings.php:13
filterwpcf7_validate_emailincludes/integrations/class-truelist-cf7.php:17
filterwpcf7_validate_email*includes/integrations/class-truelist-cf7.php:18
filtergform_validationincludes/integrations/class-truelist-gravity.php:15
filterregistration_errorsincludes/integrations/class-truelist-native.php:16
filterpreprocess_commentincludes/integrations/class-truelist-native.php:20
actioninitincludes/integrations/class-truelist-universal.php:29
actionwpforms_process_validate_emailincludes/integrations/class-truelist-wpforms.php:15
actionplugins_loadedtruelist-email-validator.php:28
Maintenance & Trust

Truelist Email Validator Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedApr 10, 2026
PHP min version8.0
Downloads43

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Truelist Email Validator Developer Profile

ayushtruelist

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Truelist Email Validator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/truelist-email-validator/assets/js/truelist-validate.js
Script Paths
/wp-content/plugins/truelist-email-validator/assets/js/truelist-validate.js
Version Parameters
truelist-email-validator/assets/js/truelist-validate.js?ver=1.0.0

HTML / DOM Fingerprints

JS Globals
truelistValidate
FAQ

Frequently Asked Questions about Truelist Email Validator