
UserCheck Security & Risk Analysis
wordpress.org/plugins/usercheckProtect your WordPress site from disposable email addresses using the UserCheck API.
Is UserCheck Safe to Use in 2026?
Generally Safe
Score 92/100UserCheck has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'usercheck' plugin version 0.1.1 presents a generally positive security posture based on the static analysis. The complete absence of an attack surface, including AJAX handlers, REST API routes, shortcodes, and cron events, is a significant strength, indicating no readily exposed entry points for attackers. Furthermore, the code demonstrates good practices with 100% of SQL queries utilizing prepared statements and a high percentage of output being properly escaped. The presence of a nonce check further enhances security against common web attacks. The plugin's vulnerability history is also a strong indicator of its current security, with zero recorded CVEs and no common vulnerability types. This suggests a lack of known exploitable flaws. However, the plugin's overall security can be considered incomplete due to the lack of capability checks and the presence of external HTTP requests without clear indication of their security implications. While no specific critical or high-severity issues were identified in the taint analysis, the potential for issues arising from unauthenticated external requests or improper capability checks cannot be fully dismissed without further investigation. The plugin's strengths lie in its minimal attack surface and adherence to core WordPress security practices like prepared statements and output escaping. Its weakness lies in the potential for privilege escalation or information disclosure through the undocumented external HTTP requests or the complete absence of capability checks.
Key Concerns
- No capability checks found
- External HTTP requests present without clear auth
UserCheck Security Vulnerabilities
UserCheck Code Analysis
Output Escaping
UserCheck Attack Surface
WordPress Hooks 5
Maintenance & Trust
UserCheck Maintenance & Trust
Maintenance Signals
Community Trust
UserCheck Alternatives
Antideo Email Validator
antideo-email-validator
Form email validation, Email Blacklist, Domain Blacklist, Form email check, Real time email validator Requires at least: 4.7 Tested up to: 6.9.
DeBounce Email Validator
debounce-io-email-validator
Real-time email validation for WordPress forms. Block invalid, disposable, and risky emails to keep your database clean and improve deliverability.
QuickEmailVerification
quickemailverification
The QuickEmailVerification email verification plugin to avoid fake, bad and nonexistent emails.
Byteplant Email Validator
email-validator-by-byteplant
With the Byteplant Email Validator plugin you can easily verify with a real-time live check if an email address really exists and is valid (https://ww …
Mailgun Email Validator
mailgun-email-validator
Kick spam with a highly advanced email validation in comment forms, user registration and contact forms using Mailgun's Email validation service.
UserCheck Developer Profile
1 plugin · 100 total installs
How We Detect UserCheck
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
usercheck-api-key-description