
CAPTCHA 4WP – Antispam CAPTCHA solution for WordPress Security & Risk Analysis
wordpress.org/plugins/advanced-nocaptcha-recaptchaUse CAPTCHA to stop spam and allow customers & users to interact with your website easily. Block fake accounts and orders. Avoid false positives.
Is CAPTCHA 4WP – Antispam CAPTCHA solution for WordPress Safe to Use in 2026?
Generally Safe
Score 99/100CAPTCHA 4WP – Antispam CAPTCHA solution for WordPress has a strong security track record. Known vulnerabilities have been patched promptly.
The "advanced-nocaptcha-recaptcha" plugin v7.6.0 exhibits a generally good security posture, with a high percentage of SQL queries using prepared statements and a strong adherence to output escaping and nonce checks. The plugin also shows good practice by not bundling external libraries, which often become outdated and introduce vulnerabilities. However, a significant concern arises from the presence of an unprotected AJAX handler, creating a potential entry point for unauthorized actions. While the taint analysis reports no immediate critical or high severity issues, this uncovered AJAX handler warrants attention. The plugin's vulnerability history, particularly a past high-severity Cross-Site Request Forgery (CSRF) vulnerability, indicates a potential for similar issues if not diligently managed. Despite the current lack of unpatched CVEs and zero taint flows, the single unprotected AJAX handler is a clear risk that slightly degrades its otherwise strong security standing.
Key Concerns
- Unprotected AJAX handler found
- One past high severity CVE
CAPTCHA 4WP – Antispam CAPTCHA solution for WordPress Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
CAPTCHA 4WP <= 7.0.6.1 - Cross-Site Request Forgery to Local File Inclusion
CAPTCHA 4WP – Antispam CAPTCHA solution for WordPress Code Analysis
SQL Query Safety
Output Escaping
CAPTCHA 4WP – Antispam CAPTCHA solution for WordPress Attack Surface
AJAX Handlers 9
WordPress Hooks 53
Maintenance & Trust
CAPTCHA 4WP – Antispam CAPTCHA solution for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
CAPTCHA 4WP – Antispam CAPTCHA solution for WordPress Alternatives
Contact Form 7 Captcha
contact-form-7-simple-recaptcha
Protect your Contact Form 7 forms with Google reCAPTCHA V2, Google reCAPTCHA V3, hCAPTCHA, or Cloudflare Turnstile.
reCAPTCHA in WP comments form
recaptcha-in-wp-comments-form
reCAPTCHA in WP comments form is an ANTISPAM tool that adds a Google reCAPTCHA to the comments form and protects your site from the spam robots threat …
DoLogin Security
dologin
Easy Login. 2FA login. Passwordless login. Cloudflare Turnstile reCAPTCHA. GeoLocation (Continent/Country/City)/IP range to limit login attempts.
G-Forms hCaptcha
gf-hcaptcha
A new way to monetize your site traffic with the hCaptcha addon for Gravity Forms.
Ultimate WP Captcha
ultimate-wp-captcha
Enables Google reCAPTCHA and hCaptcha for the WordPress website forms.
CAPTCHA 4WP – Antispam CAPTCHA solution for WordPress Developer Profile
9 plugins · 238K total installs
How We Detect CAPTCHA 4WP – Antispam CAPTCHA solution for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/advanced-nocaptcha-recaptcha/js/admin/c4wp-admin-settings.js/wp-content/plugins/advanced-nocaptcha-recaptcha/js/frontend/c4wp-frontend.js/wp-content/plugins/advanced-nocaptcha-recaptcha/css/c4wp-admin.css/wp-content/plugins/advanced-nocaptcha-recaptcha/css/c4wp-frontend.csshttps://www.google.com/recaptcha/api.js?render=https://www.google.com/recaptcha/api.js?onload=onloadCallback&render=advanced-nocaptcha-recaptcha/js/admin/c4wp-admin-settings.js?ver=advanced-nocaptcha-recaptcha/js/frontend/c4wp-frontend.js?ver=advanced-nocaptcha-recaptcha/css/c4wp-admin.css?ver=advanced-nocaptcha-recaptcha/css/c4wp-frontend.css?ver=HTML / DOM Fingerprints
c4wp-fieldc4wp-labelc4wp-input-wrapc4wp-captcha-settings-wrapc4wp-recaptcha-block<!-- @dev:start --><!-- @dev:end --><!-- @free:start --><!-- @free:end -->+2 moredata-site-keyC4WP/wp-json/c4wp/v1/settings