
Advanced Google reCAPTCHA Security & Risk Analysis
wordpress.org/plugins/advanced-google-recaptchaCaptcha protection against spam comments & brute force login attacks using Google reCAPTCHA.
Is Advanced Google reCAPTCHA Safe to Use in 2026?
Generally Safe
Score 98/100Advanced Google reCAPTCHA has a strong security track record. Known vulnerabilities have been patched promptly.
The "advanced-google-recaptcha" v1.31 plugin exhibits a mixed security posture. On the positive side, its code analysis reveals robust practices in handling SQL queries and output escaping, with 100% of both utilizing prepared statements and proper escaping respectively. There are no identified file operations or external HTTP requests, and no bundled libraries appear to be flagged as dangerous. However, significant concerns arise from its attack surface and vulnerability history. The presence of one unprotected AJAX handler represents a direct entry point for potential malicious activity. Furthermore, the plugin has a history of three medium-severity vulnerabilities, including SQL Injection, Guessable CAPTCHA, and Generation of Predictable Numbers or Identifiers. While currently unpatched CVEs are zero, the recurring nature of these vulnerability types suggests potential underlying weaknesses that might resurface in future versions if not adequately addressed. The taint analysis, while not indicating critical or high severity flows, did identify two flows with unsanitized paths, which is a cause for concern.
Key Concerns
- Unprotected AJAX handler
- Multiple medium severity CVEs in history
- Taint analysis shows unsanitized paths
- Missing nonce checks on AJAX
Advanced Google reCAPTCHA Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Advanced Google reCAPTCHA <= 1.29 - Authenticated (Subscriber+) Limited SQL Injection via 'sSearch' Parameter
Advanced Google reCaptcha <= 1.27 - Built-in Math CAPTCHA Bypass
Advanced Google reCAPTCHA <= 1.25 - Brute Force Protection IP Unblock
Advanced Google reCAPTCHA Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Advanced Google reCAPTCHA Attack Surface
AJAX Handlers 1
WordPress Hooks 54
Maintenance & Trust
Advanced Google reCAPTCHA Maintenance & Trust
Maintenance Signals
Community Trust
Advanced Google reCAPTCHA Alternatives
reCaptcha for WooCommerce
advanced-google-recaptcha-for-woocommerce
Enable Google reCaptcha for WooCommerce Checkout, Login, Registration, and Reset Password Forms to protect your store against spam.
Addonify – reCaptcha For EDD
addonify-recaptcha-for-edd
Addonify reCAPTCHA for EDD is a simple plugin that adds Google reCaptcha in Easy Digital Downloads login and registration forms.
Checkout Captcha for WooCommerce
jkm-checkout-captcha-for-woo
Adds reCAPTCHA verification to WooCommerce checkout, login, registration, and password reset forms to prevent spam and bot transactions.
CF7 Google Captcha Load After Page
cf7-google-captcha-load-after-page
This plugins use for your website speed improvement and decrease your page request. When you have used contact form 7 and insert you Google Captcha( v …
Power Captcha reCAPTCHA
power-captcha-recaptcha
Protect WordPress/WooCommerce/Contact Form 7 forms from spam, brute-force attacks, fake comments, accounts, or registrations with Google reCAPTCHA.
Advanced Google reCAPTCHA Developer Profile
28 plugins · 3.5M total installs
How We Detect Advanced Google reCAPTCHA
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/advanced-google-recaptcha/wf-flyout/css/wf-flyout.css/wp-content/plugins/advanced-google-recaptcha/wf-flyout/js/wf-flyout.js/wp-content/plugins/advanced-google-recaptcha/assets/css/admin-style.css/wp-content/plugins/advanced-google-recaptcha/assets/js/admin-script.js/wp-content/plugins/advanced-google-recaptcha/assets/js/frontend-script.js/wp-content/plugins/advanced-google-recaptcha/wf-flyout/js/wf-flyout.js/wp-content/plugins/advanced-google-recaptcha/assets/js/admin-script.js/wp-content/plugins/advanced-google-recaptcha/assets/js/frontend-script.jsadvanced-google-recaptcha/wf-flyout/css/wf-flyout.css?ver=advanced-google-recaptcha/wf-flyout/js/wf-flyout.js?ver=advanced-google-recaptcha/assets/css/admin-style.css?ver=advanced-google-recaptcha/assets/js/admin-script.js?ver=advanced-google-recaptcha/assets/js/frontend-script.js?ver=HTML / DOM Fingerprints
wpcaptcha-login-formwpcaptcha-register-formwpcaptcha-comment-formwpcaptcha-lostpassword-formwpcaptcha-resetpass-formwpcaptcha-checkout-formwf-flyout-container<!-- Added by Advanced Google reCAPTCHA plugin --><!-- Added by WebFactory Ltd -->data-wpcaptcha-sitekeydata-wpcaptcha-themedata-wpcaptcha-sizewpcaptcha_vars/wp-json/wpcaptcha/v1/get_settings