
Email Domain Blacklist for WooCommerce and EDD Security & Risk Analysis
wordpress.org/plugins/woo-email-domain-blacklistA lightweight plugin to block any email domain from WooCommerce and Easy Digital Download checkout page
Is Email Domain Blacklist for WooCommerce and EDD Safe to Use in 2026?
Generally Safe
Score 100/100Email Domain Blacklist for WooCommerce and EDD has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "woo-email-domain-blacklist" v2.0.1 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices regarding SQL queries, utilizing prepared statements exclusively, and shows no known CVEs or historical vulnerabilities. The attack surface is also commendably small, with no unprotected entry points. However, significant concerns arise from the code analysis. The presence of the `create_function` dangerous function is a major red flag, as it can lead to remote code execution if not handled with extreme caution and sanitization, though no specific flows were identified in the taint analysis. Furthermore, a low percentage of output escaping (36%) is a considerable risk, potentially exposing the site to cross-site scripting (XSS) vulnerabilities. The absence of nonce checks and capability checks on potential entry points (though currently zero unprotected ones exist) leaves room for future vulnerabilities if new entry points are introduced without proper authentication and authorization mechanisms.
Key Concerns
- Dangerous function 'create_function' used
- Low output escaping percentage (36%)
- No nonce checks implemented
- No capability checks implemented
Email Domain Blacklist for WooCommerce and EDD Security Vulnerabilities
Email Domain Blacklist for WooCommerce and EDD Code Analysis
Dangerous Functions Found
Output Escaping
Email Domain Blacklist for WooCommerce and EDD Attack Surface
WordPress Hooks 9
Scheduled Events 1
Maintenance & Trust
Email Domain Blacklist for WooCommerce and EDD Maintenance & Trust
Maintenance Signals
Community Trust
Email Domain Blacklist for WooCommerce and EDD Alternatives
Email and Domain Blocker for WooCommerce
email-and-domain-blocker
Block emails or domains from WooCommerce signups. Supports wildcards, logging, CSV export, and test email checker.
Block Emails for WooCommerce Checkout
wc-block-emails
A WooCommerce plugin to block specific email addresses during checkout.
Advanced Email Domain Restriction
advanced-email-domain-restriction
Restrict user registrations to specific domains, TLDs, or email addresses. Includes CSV import/export and WooCommerce support.
Spam Defender – Email Blocker
spam-defender-email-blocker
Block specific email addresses from using your WordPress site. Stop fake orders, spam registrations, and unwanted comments.
MailPoet – Newsletters, Email Marketing, and Automation
mailpoet
Send beautiful newsletters from WordPress. Collect subscribers with signup forms, automate your emails for WooCommerce, blog post notifications & more
Email Domain Blacklist for WooCommerce and EDD Developer Profile
3 plugins · 4K total installs
How We Detect Email Domain Blacklist for WooCommerce and EDD
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/woo-email-domain-blacklist/admin/js/email-blacklist-admin.jswoo-email-domain-blacklist/admin/css/email-blacklist-admin.css?ver=woo-email-domain-blacklist/admin/js/email-blacklist-admin.js?ver=HTML / DOM Fingerprints
email-blacklist-noticeFOA_Email_Domain_Blacklist_Admin_vars