turboSMTP Email Validator Security & Risk Analysis

wordpress.org/plugins/turbosmtp-email-validator

Email validation tool in WordPress forms registrations using turboSMTP API

10 active installs v1.9.1 PHP 7.0+ WP 6.0+ Updated Dec 2, 2025
email-testeremail-validationemail-validator
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is turboSMTP Email Validator Safe to Use in 2026?

Generally Safe

Score 100/100

turboSMTP Email Validator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The "turbosmtp-email-validator" v1.9.1 plugin presents a mixed security posture. On the positive side, the plugin has no recorded vulnerability history, suggesting a relatively stable and secure past. The code analysis also indicates a responsible approach to database interactions, with a high percentage of SQL queries using prepared statements and a reasonable rate of output escaping.

However, significant security concerns arise from the attack surface. The plugin exposes two AJAX handlers, both of which lack authentication checks. This is a critical oversight, as it allows any unauthenticated user to potentially trigger these handlers, leading to unauthorized actions or information disclosure depending on their functionality. While taint analysis did not reveal critical or high severity unsanitized paths, the lack of authentication on AJAX endpoints is a more immediate and direct risk that bypasses typical WordPress security measures.

In conclusion, while the plugin demonstrates good practices in areas like SQL query sanitization and has a clean vulnerability record, the absence of authentication checks on its AJAX endpoints is a serious weakness that significantly elevates the risk profile. This plugin requires immediate attention to secure these entry points.

Key Concerns

  • Unprotected AJAX handlers
  • Lack of capability checks on AJAX
  • External HTTP requests
  • Output escaping rate below 100%
Vulnerabilities
None known

turboSMTP Email Validator Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

turboSMTP Email Validator Code Analysis

Dangerous Functions
0
Raw SQL Queries
3
11 prepared
Unescaped Output
17
41 escaped
Nonce Checks
3
Capability Checks
0
File Operations
0
External Requests
3
Bundled Libraries
0

SQL Query Safety

79% prepared14 total queries

Output Escaping

71% escaped58 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

7 flows1 with unsanitized paths
ajax_get_email_details (admin\class-turbosmtp-email-validator-admin.php:103)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

turboSMTP Email Validator Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_turbosmtp-email-validator-disconnectincludes\class-turbosmtp-email-validator.php:155
authwp_ajax_turbosmtp-email-validator_get_email_detailsincludes\class-turbosmtp-email-validator.php:156
WordPress Hooks 24
actionadmin_enqueue_scriptsincludes\class-turbosmtp-email-validator.php:150
actionadmin_enqueue_scriptsincludes\class-turbosmtp-email-validator.php:151
actionadmin_menuincludes\class-turbosmtp-email-validator.php:152
actionadmin_initincludes\class-turbosmtp-email-validator.php:153
actionadmin_post_turbosmtp-email-validator-loginincludes\class-turbosmtp-email-validator.php:154
actionupdate_option_turbosmtp_email_validator_error_messageincludes\class-turbosmtp-email-validator.php:158
actionturbosmtp_email_validator_validated_emailincludes\class-turbosmtp-email-validator.php:161
actionwp_enqueue_scriptsincludes\class-turbosmtp-email-validator.php:219
actionwp_enqueue_scriptsincludes\class-turbosmtp-email-validator.php:220
filterturbosmtp_email_validator_checkemailincludes\class-turbosmtp-email-validator.php:225
filterregistration_errorsincludes\class-turbosmtp-email-validator.php:232
filterwpmu_validate_user_signupincludes\class-turbosmtp-email-validator.php:233
actionwoocommerce_register_postincludes\class-turbosmtp-email-validator.php:239
filterwoocommerce_after_checkout_validationincludes\class-turbosmtp-email-validator.php:240
actionpre_comment_on_postincludes\class-turbosmtp-email-validator.php:246
actioncomment_postincludes\class-turbosmtp-email-validator.php:247
filtermc4wp_form_messagesincludes\class-turbosmtp-email-validator.php:253
filtermc4wp_form_errorsincludes\class-turbosmtp-email-validator.php:254
filtergform_field_validationincludes\class-turbosmtp-email-validator.php:260
filterwpcf7_validate_emailincludes\class-turbosmtp-email-validator.php:266
filterwpcf7_validate_email*includes\class-turbosmtp-email-validator.php:267
filterwpforms_process_after_filterincludes\class-turbosmtp-email-validator.php:272
filterelementor_pro/forms/validation/emailincludes\class-turbosmtp-email-validator.php:276
filteris_emailpublic\class-turbosmtp-email-validator-public.php:78
Maintenance & Trust

turboSMTP Email Validator Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 2, 2025
PHP min version7.0
Downloads849

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

turboSMTP Email Validator Developer Profile

turboSMTP

3 plugins · 510 total installs

100
trust score
Avg Security Score
100/100
Avg Patch Time
6 days
View full developer profile
Detection Fingerprints

How We Detect turboSMTP Email Validator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/turbosmtp-email-validator/css/turbosmtp-email-validator-admin.css/wp-content/plugins/turbosmtp-email-validator/js/turbosmtp-email-validator-admin.js
Script Paths
js/turbosmtp-email-validator-admin.js
Version Parameters
turbosmtp-email-validator/css/turbosmtp-email-validator-admin.css?ver=turbosmtp-email-validator/js/turbosmtp-email-validator-admin.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-turbosmtp-email-validator
JS Globals
turbosmtpEmailValidator
FAQ

Frequently Asked Questions about turboSMTP Email Validator