[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fUVbBuAtJK-waXxFKgO9izDuYikgelFPJLfqISHFD2yk":3,"$fNtyRvYJ380pl_1ESlA3mytG8ncnUNdhB9Kye2DK1sR0":262,"$fCDdVuJRLxlHWHZylWSNfbEN-S7VCMMeoC5vw-hhfyOA":267},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":13,"last_updated":14,"tested_up_to":15,"requires_at_least":16,"requires_php":17,"tags":18,"homepage":24,"download_link":25,"security_score":26,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28,"discovery_status":29,"vulnerabilities":30,"developer":31,"crawl_stats":27,"alternatives":37,"analysis":146,"fingerprints":239},"anti-ddosbot-recaptcha-protection","Anti DDOS\u002FBOT reCAPTCHA Protection","1.1.2","Pantelis Kaplanoglou","https:\u002F\u002Fprofiles.wordpress.org\u002Fwebtouchgr\u002F","\u003Cp>Stop bad traffic before it reaches your content. This plugin requires visitors to complete a one-time reCAPTCHA verification, effectively blocking automated bots and reducing the impact of DDOS attacks.\u003C\u002Fp>\n\u003Ch4>Key Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>One-Click Protection\u003C\u002Fstrong> – Enable protection with a single click after reCAPTCHA verification\u003C\u002Fli>\n\u003Cli>\u003Cstrong>URL Targeting\u003C\u002Fstrong> – Protect specific pages or your entire website\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Logged-in Users Bypass\u003C\u002Fstrong> – Admins and editors never see the captcha\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Emergency Override\u003C\u002Fstrong> – Enable via wp-config.php if you lose admin access\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Fully Translated\u003C\u002Fstrong> – Available in 132 languages with professional human-quality translations\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Lightweight\u003C\u002Fstrong> – Minimal impact on your site’s performance\u003C\u002Fli>\n\u003C\u002Ful>\n","Stop bad bots and limit DDOS attacks with Google reCAPTCHA. One-time human verification keeps automated traffic away. Translated in 132 languages.",10,1700,0,"2026-06-30T12:32:00.000Z","7.0.2","5.0","7.4",[19,20,21,22,23],"bot","ddos","protection","recaptcha","security","http:\u002F\u002Fwordpress.org\u002Fplugins\u002Fanti-ddosbot-recaptcha-protection","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fanti-ddosbot-recaptcha-protection.1.1.2.zip",100,null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":32,"display_name":7,"profile_url":8,"plugin_count":33,"total_installs":11,"avg_security_score":26,"avg_patch_time_days":34,"trust_score":35,"computed_at":36},"webtouchgr",1,30,94,"2026-08-29T05:44:12.861Z",[38,58,81,103,125],{"slug":39,"name":40,"version":41,"author":42,"author_profile":43,"description":44,"short_description":45,"active_installs":46,"downloaded":47,"rating":26,"num_ratings":33,"last_updated":48,"tested_up_to":15,"requires_at_least":49,"requires_php":50,"tags":51,"homepage":56,"download_link":57,"security_score":26,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28},"anti-browser-ddos-protection","Anti Browser DDoS Protection","2.28","sourcecode347","https:\u002F\u002Fprofiles.wordpress.org\u002Fsourcecode347\u002F","\u003Cp>The \u003Cstrong>Anti Browser DDoS Protection\u003C\u002Fstrong> plugin provides robust protection against denial-of-service (DoS) attacks on your WordPress site. It implements IP-based rate limiting, with configurable settings for subscribers, non-logged-in users, and verified bots, while excluding administrators and other non-subscriber roles. It features advanced bot detection to identify and limit suspicious bots, immediate blocking of malicious bots by User Agent, and supports Cloudflare for accurate client IP detection. Static assets (e.g., CSS, JS, images) are excluded to maintain site performance. An intuitive admin panel allows you to configure rate limits, bot exclusions, trusted bot IP ranges (with automatic duplicate removal), blocked bots by User Agent, log expiration settings, and view logs for blocked IPs, banned IPs, and high traffic bots with auto-refresh every 30 seconds, all with User Agent details and timestamps. You can export \u003Cstrong>Excluded Bots\u003C\u002Fstrong>, \u003Cstrong>Bot IP Ranges\u003C\u002Fstrong>, and \u003Cstrong>Blocked Bots\u003C\u002Fstrong> lists to .txt files and import new entries to append to existing lists without duplicates. Daily bar charts for Blocked IPs, Banned IPs, and High Traffic Bots are displayed above the logs for quick visual insights.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Key Features:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Rate limiting based on IP for subscribers and non-logged-in users, with configurable maximum requests and time window.\u003C\u002Fli>\n\u003Cli>Excludes non-subscriber logged-in users (e.g., administrators, editors) from rate limiting.\u003C\u002Fli>\n\u003Cli>Advanced bot detection to identify suspicious bots (bots using trusted User Agents but from unverified IPs).\u003C\u002Fli>\n\u003Cli>Suspicious bots are subject to the same rate limiting as regular users and logged with User Agent in the Blocked IPs Log.\u003C\u002Fli>\n\u003Cli>Immediate blocking of malicious bots by User Agent (e.g., MJ12bot, SemrushBot, DotBot by default) with customizable settings and logging.\u003C\u002Fli>\n\u003Cli>Configurable rate limiting for verified excluded bots (default: 100 requests per minute), with logging for bots exceeding this limit.\u003C\u002Fli>\n\u003Cli>High Traffic Excluded Bots Log to track verified bots with excessive requests, including IP, User Agent, and timestamp.\u003C\u002Fli>\n\u003Cli>Admin panel to configure maximum requests, time window, excluded bots, trusted bot IP ranges, blocked bots (User Agents), blocks before ban, ban duration, high traffic bot limits, and log expiration (days).\u003C\u002Fli>\n\u003Cli>Export \u003Cstrong>Excluded Bots\u003C\u002Fstrong>, \u003Cstrong>Bot IP Ranges\u003C\u002Fstrong>, and \u003Cstrong>Blocked Bots\u003C\u002Fstrong> lists to .txt files for backup or transfer.\u003C\u002Fli>\n\u003Cli>Import .txt files for \u003Cstrong>Excluded Bots\u003C\u002Fstrong>, \u003Cstrong>Bot IP Ranges\u003C\u002Fstrong>, and \u003Cstrong>Blocked Bots\u003C\u002Fstrong> to append new entries to existing lists, with automatic duplicate removal.\u003C\u002Fli>\n\u003Cli>Automatic removal of duplicate IP ranges in the \u003Cstrong>Bot IP Ranges\u003C\u002Fstrong> field on save, keeping the first occurrence.\u003C\u002Fli>\n\u003Cli>Support for Cloudflare real IP detection using \u003Ccode>CF-Connecting-IP\u003C\u002Fcode> and \u003Ccode>X-Forwarded-For\u003C\u002Fcode> headers.\u003C\u002Fli>\n\u003Cli>Excludes static assets (CSS, JS, images, fonts, etc.) from rate limiting to optimize performance.\u003C\u002Fli>\n\u003Cli>Logs blocked IPs, banned IPs, and high traffic bots with IP, User Agent, and timestamps using the WordPress timezone, viewable in the admin panel with options to clear logs and auto-refresh every 30 seconds.\u003C\u002Fli>\n\u003Cli>Daily bar charts for Blocked IPs, Banned IPs, and High Traffic Bots displayed above the logs in the admin panel for visual statistics.\u003C\u002Fli>\n\u003Cli>Automatic log expiration (Blocked IPs, Banned IPs, High Traffic Bots) after a configurable number of days (default: 5 days), with hourly cleanup via WordPress Scheduler.\u003C\u002Fli>\n\u003Cli>All error messages and logs prefixed with “Anti Browser DDoS Protection: ” for clarity.\u003C\u002Fli>\n\u003Cli>Donate link in the admin panel to support the project.\u003C\u002Fli>\n\u003Cli>Automatic cleanup of transients, blocked IPs, banned IPs, high traffic bots, blocked bots, bot IP ranges, and log expiration settings on plugin deactivation to prevent database bloat.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Ideal for WordPress sites seeking enhanced security against automated attacks, with seamless integration for Cloudflare users, advanced bot management, efficient log management, visual charts for statistics, and easy export\u002Fimport for bot lists.\u003C\u002Fp>\n\u003Ch3>Plugin Assets img\u002F\u003C\u002Fh3>\n\u003Ch3>Icon Image\u003C\u002Fh3>\n\u003Cp>Normal: icon-128×128.png\u003Cbr \u002F>\nHigh-DPI (Retina): icon-256×256.png\u003C\u002Fp>\n\u003Ch3>Bugs\u003C\u002Fh3>\n\u003Cp>Caching plugins such as WP Super Cache, W3 Total Cache, and others may bypass the DDoS protection provided by Anti Browser DDoS Protection, serving cached pages without triggering the plugin’s checks for blocked bots, rate limiting, or banned IPs.\u003Cbr \u002F>\n– \u003Cstrong>Solution\u003C\u002Fstrong>: Disable all WordPress caching plugins to ensure full DDoS protection. Instead, enable Browser Caching using a service like Cloudflare to improve performance without compromising security.\u003Cbr \u002F>\n   Enable standard type Caching and Configure Cloudflare Browser Cache TTL (e.g., 8 days) via \u003Cstrong>Caching > Configuration\u003C\u002Fstrong> in the Cloudflare dashboard.- \u003Cstrong>Cloudflare Compatibility\u003C\u002Fstrong>: Ensure Cloudflare is configured to pass \u003Ccode>CF-Connecting-IP\u003C\u002Fcode> headers for accurate IP detection. Check your Cloudflare dashboard if logged IPs are incorrect.\u003Cbr \u002F>\n– \u003Cstrong>Bot IP Ranges\u003C\u002Fstrong>: Update the \u003Cstrong>Bot IP Ranges\u003C\u002Fstrong> field every 6 months (next update: March 2026) using official sources (e.g., Google, Bing, Yandex documentation). Duplicate ranges are automatically removed on save. Export to .txt for backup or import from .txt to append new ranges.\u003Cbr \u002F>\n– \u003Cstrong>Blocked Bots\u003C\u002Fstrong>: Add malicious bots to the \u003Cstrong>Blocked Bots (User Agents)\u003C\u002Fstrong> field (e.g., MJ12bot, SemrushBot, DotBot) to block them immediately. Blocked bots are logged with their IP and User Agent. Export to .txt for backup or import from .txt to append new entries.\u003Cbr \u002F>\n– \u003Cstrong>Excluded Bots\u003C\u002Fstrong>: Add trusted bots (e.g., Googlebot, Bingbot) to the \u003Cstrong>Excluded Bots\u003C\u002Fstrong> field to exempt them from regular rate limiting (if from verified IPs). Export to .txt for backup or import from .txt to append new entries.\u003Cbr \u002F>\n– \u003Cstrong>High Traffic Bots\u003C\u002Fstrong>: Verified bots exceeding the configured limit (default: 100 requests per minute) are logged for monitoring but not blocked. Check the High Traffic Excluded Bots Log regularly.\u003Cbr \u002F>\n– \u003Cstrong>Log Expiration\u003C\u002Fstrong>: Set the \u003Cstrong>Log Expires (Days)\u003C\u002Fstrong> setting to control how long logs are retained (default: 5 days). Cleanup runs hourly via WordPress Scheduler. Logs older than the specified days are automatically deleted.\u003Cbr \u002F>\n– \u003Cstrong>Timezone\u003C\u002Fstrong>: Set the WordPress timezone correctly (e.g., \u003Ccode>Europe\u002FAthens\u003C\u002Fcode> for Greece) in Settings > General > Timezone to ensure accurate timestamp display in logs and charts.\u003Cbr \u002F>\n– \u003Cstrong>Performance\u003C\u002Fstrong>: For high-traffic sites, clear the Blocked IPs Log, Banned IPs Log, and High Traffic Excluded Bots Log regularly, or set a lower \u003Cstrong>Log Expires (Days)\u003C\u002Fstrong> value to prevent database growth.\u003Cbr \u002F>\n– \u003Cstrong>Customization\u003C\u002Fstrong>: Contact the author for additional features like custom error pages, email notifications for high traffic bots, or advanced logging.\u003Cbr \u002F>\n– \u003Cstrong>Support the Project\u003C\u002Fstrong>: If you find this plugin useful, consider supporting its development via the \u003Ca href=\"https:\u002F\u002Fbuy.stripe.com\u002FbIY5o70SSfam8Qo7ss\" rel=\"nofollow ugc\">donation link\u003C\u002Fa> in the admin panel or plugin page.\u003C\u002Fp>\n","Protects WordPress from DDoS with rate limiting, bot detection, blocking, Cloudflare support, logs, charts, and bot list export\u002Fimport.",70,1020,"2026-06-22T07:51:00.000Z","6.0","8.5",[52,53,54,55,23],"bot-blocking","ddos-protection","ip-blocking","rate-limiting","","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fanti-browser-ddos-protection.2.28.zip",{"slug":59,"name":60,"version":61,"author":62,"author_profile":63,"description":64,"short_description":65,"active_installs":66,"downloaded":67,"rating":68,"num_ratings":69,"last_updated":70,"tested_up_to":15,"requires_at_least":71,"requires_php":17,"tags":72,"homepage":76,"download_link":77,"security_score":78,"vuln_count":79,"unpatched_count":13,"last_vuln_date":80,"fetched_at":28},"login-recaptcha","Login No Captcha reCAPTCHA","1.8.1","Robert Peake","https:\u002F\u002Fprofiles.wordpress.org\u002Frobertpeake\u002F","\u003Cp>Adds a Google No Captcha ReCaptcha checkbox to your WordPress and Woocommerce login, forgot password, and user registration pages. Denies access to automated scripts while making it easy on humans to log in by checking a box. As Google says, it is “Tough on bots, easy on humans.”\u003C\u002Fp>\n","Adds a Google No Captcha ReCaptcha checkbox to your Wordpress and Woocommerce login, forgot password, and user registration pages.",60000,1419501,90,63,"2026-05-26T15:16:00.000Z","4.6",[73,74,75,22,23],"bots","google","nocaptcha","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Flogin-recaptcha\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Flogin-recaptcha.1.8.1.zip",96,2,"2026-05-27 14:54:36",{"slug":82,"name":83,"version":84,"author":85,"author_profile":86,"description":87,"short_description":88,"active_installs":89,"downloaded":90,"rating":91,"num_ratings":92,"last_updated":93,"tested_up_to":94,"requires_at_least":95,"requires_php":96,"tags":97,"homepage":100,"download_link":101,"security_score":26,"vuln_count":33,"unpatched_count":13,"last_vuln_date":102,"fetched_at":28},"no-bot-registration","No-Bot Registration","2.5.1","Arnan","https:\u002F\u002Fprofiles.wordpress.org\u002Fadegans\u002F","\u003Cp>Tired of spam bots in your WordPress and ClassicPress website? Do you want to get rid of false registrations and other spammy nonsense? Don’t wan’t to use a clumsy and user-unfriendly Captcha? Don’t want to use a Captcha from Google or other big-tech company period?\u003C\u002Fp>\n\u003Cp>Meet \u003Cstrong>No-Bot Registration\u003C\u002Fstrong>, easy to use, superior protection without making it hard for your visitors. Easily blacklist (partial) email addresses and domains so they can no longer register an account.\u003C\u002Fp>\n\u003Cp>Create one or more questions and a set of possible answers for them and visitors have to answer your question when they register.\u003Cbr \u002F>\nIf they answer wrong, they get denied their account.\u003C\u002Fp>\n\u003Cp>Questions can be as simple as “1 + 1”, with possible answers being 1, one or uno. That way you can plan for eventualities and how people interpret your question.\u003C\u002Fp>\n\u003Ch4>Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Protect registration forms\u003C\u002Fli>\n\u003Cli>Protect the WooCommerce checkout form if you let people register from there\u003C\u002Fli>\n\u003Cli>Protect your blog comment form\u003C\u002Fli>\n\u003Cli>Prevents comment spam, trackback spam and other nuisances with ease\u003C\u002Fli>\n\u003Cli>Set up multiple security questions to further confuse bots\u003C\u002Fli>\n\u003Cli>Blacklist any email, domain or tld you don’t like\u003C\u002Fli>\n\u003Cli>Configurable notification messages for users failing the security tests\u003C\u002Fli>\n\u003C\u002Ful>\n","Prevent bots from creating accounts by blacklisting domains and usernames and present people with a human friendly security question.",2000,37337,88,28,"2025-12-28T03:50:00.000Z","6.9.5","5.8","8.0",[98,19,99,21,23],"antispam","crawler","https:\u002F\u002Fajdg.solutions\u002Fproduct\u002Fno-bot-registration\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fno-bot-registration.2.5.1.zip","2024-04-09 00:00:00",{"slug":104,"name":105,"version":106,"author":107,"author_profile":108,"description":109,"short_description":110,"active_installs":111,"downloaded":112,"rating":113,"num_ratings":114,"last_updated":115,"tested_up_to":116,"requires_at_least":49,"requires_php":56,"tags":117,"homepage":56,"download_link":121,"security_score":122,"vuln_count":33,"unpatched_count":13,"last_vuln_date":123,"fetched_at":124},"cartpauj-register-captcha","Cartpauj Register Captcha","2.0.1","cartpauj","https:\u002F\u002Fprofiles.wordpress.org\u002Fcartpauj\u002F","\u003Cp>Cartpauj Register Captcha does one simple task. It prevents SPAM signups through WordPress’s default registration form. There are no settings to configure. Just activate and watch those SPAM sign-ups fade away! Requires openssl PHP library.\u003C\u002Fp>\n\u003Ch4>Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Adds CAPTCHA to the WordPress register sign-up form.\u003C\u002Fli>\n\u003Cli>NO settings or configurations to deal with.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Note\u003C\u002Fh3>\n\u003Cp>Built with a modified version of Phoca Captcha PHP library\u003Cbr \u002F>\nIcon by \u003Ca href=\"http:\u002F\u002Fwww.flaticon.com\u002Fauthors\u002Ffreepik\" rel=\"nofollow ugc\">Freepik\u003C\u002Fa>\u003C\u002Fp>\n","Cartpauj Register Captcha does one simple task. It prevents SPAM signups through WordPress' default registration form.",1000,38973,84,24,"2025-05-20T23:09:00.000Z","6.8.5",[118,119,21,22,120],"captcha","login-security","turnstile","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fcartpauj-register-captcha.2.0.1.zip",92,"2023-08-21 00:00:00","2026-04-06T09:54:40.288Z",{"slug":126,"name":127,"version":106,"author":128,"author_profile":129,"description":130,"short_description":131,"active_installs":132,"downloaded":133,"rating":35,"num_ratings":134,"last_updated":135,"tested_up_to":136,"requires_at_least":137,"requires_php":138,"tags":139,"homepage":141,"download_link":142,"security_score":143,"vuln_count":79,"unpatched_count":33,"last_vuln_date":144,"fetched_at":145},"blue-captcha","Blue Captcha","jotis","https:\u002F\u002Fprofiles.wordpress.org\u002Fjotis\u002F","\u003Cp>Blue Captcha is a powerful and highly customized WordPress plugin that effectively protects your WP blogs from spammers and unwanted persons. It is easily installed and provides high protection against spammers, bots or unwanted persons.\u003C\u002Fp>\n\u003Ch4>Do you like Blue Captcha? Then Support it!\u003C\u002Fh4>\n\u003Cp>If you like Blue Captcha, then you can help it grow by \u003Ca href=\"http:\u002F\u002Fmybluestuff.blogspot.gr\u002Fp\u002Fdonate_21.html\" rel=\"nofollow ugc\">\u003Cstrong>donating one dollar\u003C\u002Fstrong>\u003C\u002Fa>. Any donation will be highly appreciated and will help in further development of this plugin.\u003C\u002Fp>\n\u003Cp>Features:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>It can be applied to any of the following : login form, registration form, commentary form or password recovery form\u003C\u002Fli>\n\u003Cli>It’s highly customized\u003C\u002Fli>\n\u003Cli>It has 7 predefined CAPTCHA difficulty levels to choose from – of course, you can adjust your CAPTCHA settings and create a custom level\u003C\u002Fli>\n\u003Cli>The possible CAPTCHA customizations are more than enough\u003C\u002Fli>\n\u003Cli>It can apply the same or totally different CAPTCHA settings on login form, registration form, commentary form and password recovery form\u003C\u002Fli>\n\u003Cli>It can display CAPTCHA to only non-registered users or registered users\u003C\u002Fli>\n\u003Cli>It can preview CAPTCHA image before applying it\u003C\u002Fli>\n\u003Cli>It supports 5 different fonts and 30 different background images\u003C\u002Fli>\n\u003Cli>It supports single or double CAPTCHA layer\u003C\u002Fli>\n\u003Cli>It can display up to 20(!) characters on Captcha Images\u003C\u002Fli>\n\u003Cli>It is capable of adding extra drawing (lines, circles, grid, transparent lines) on CAPTCHA image\u003C\u002Fli>\n\u003Cli>It is capable of keeping log file which registers all activities concerning user logins, user registrations, user comments and password recovery\u003C\u002Fli>\n\u003Cli>It has “Hall of Shame” (HoS)\u003C\u002Fli>\n\u003Cli>It provides blocking options as well\u003C\u002Fli>\n\u003Cli>It can export the entire log file or HoS into CSV file (Excel)\u003C\u002Fli>\n\u003Cli>With the help of log file and HoS, it’s easy to track down the IP address of spammers or unwanted persons and ban them for ever\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>You can visit \u003Ca href=\"http:\u002F\u002Fmybluestuff.blogspot.com\u002Fp\u002Fblue-captcha.html\" rel=\"nofollow ugc\">Blue Captcha Page\u003C\u002Fa> for more information.\u003C\u002Fp>\n\u003Ch4>Blue Captcha Translation\u003C\u002Fh4>\n\u003Cp>Blue Captcha is now available in Greek, Spanish, Russian, Italian, Brazilian-Portuguese, Serbo-Croatian & Slovenian.\u003C\u002Fp>\n\u003Cp>I would be very grateful if someone is willing to translate Blue Captcha to another language.\u003Cbr \u002F>\nFor those interested, the template translation file (“blue-captcha.pot”) is located on “languages” folder of blue-captcha plugin.\u003C\u002Fp>\n\u003Ch3>Contribution\u003C\u002Fh3>\n\u003Cp>Special Thanks To The Following Contributors:\u003C\u002Fp>\n\u003Cp>Leon Roskar (http:\u002F\u002Fwww.qb.si) => Slovenian Translation\u003Cbr \u002F>\nBorisa Djuraskovic (http:\u002F\u002Fwww.webhostinghub.com) => Serbo-Croatian Translation\u003Cbr \u002F>\nJoão Victor T. Magalhães => Brazilian Portuguese Translation\u003Cbr \u002F>\nEricka Morales Hernández (http:\u002F\u002Ftodoriesgo.net) => Italian Translation\u003Cbr \u002F>\nAlex Balashov => Russian Translation\u003Cbr \u002F>\nAndrew Kurtis (http:\u002F\u002Fwww.webhostinghub.com) => Spanish Translation\u003Cbr \u002F>\nChristos Bakopoulos => Arabic Translation\u003C\u002Fp>\n","Blue Captcha is a powerful and highly customized WordPress plugin that effectively protects your WP blogs from spammers and unwanted persons.",500,37339,15,"2026-02-08T17:30:00.000Z","6.9.4","4.9","7.0",[118,21,22,140,23],"safety","http:\u002F\u002Fwordpress.org\u002Fextend\u002Fplugins\u002Fblue-captcha\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fblue-captcha.2.0.1.zip",76,"2026-06-23 16:41:19","2026-04-16T10:56:18.058Z",{"attackSurface":147,"codeSignals":159,"taintFlows":170,"riskAssessment":228,"analyzedAt":238},{"hooks":148,"ajaxHandlers":155,"restRoutes":156,"shortcodes":157,"cronEvents":158,"entryPointCount":13,"unprotectedCount":13},[149],{"type":150,"name":151,"callback":152,"file":153,"line":154},"action","admin_menu","anti_ddos_bot_recaptcha_admin_menu","anti-ddos-bot-recaptcha-protection.php",29,[],[],[],[],{"dangerousFunctions":160,"sqlUsage":161,"outputEscaping":163,"fileOperations":13,"externalRequests":79,"nonceChecks":13,"capabilityChecks":13,"bundledLibraries":169},[],{"prepared":13,"raw":13,"locations":162},[],{"escaped":164,"rawEcho":33,"locations":165},22,[166],{"file":153,"line":167,"context":168},232,"raw output",[],[171,190,209,218],{"entryPoint":172,"graph":173,"unsanitizedCount":33,"severity":189},"adbr_checkRecaptchaKey (anti-ddos-bot-recaptcha-protection.php:31)",{"nodes":174,"edges":186},[175,180],{"id":176,"type":177,"label":178,"file":153,"line":179},"n0","source","$_POST",33,{"id":181,"type":182,"label":183,"file":153,"line":184,"wp_function":185},"n1","sink","wp_remote_get() [SSRF]",37,"wp_remote_get",[187],{"from":176,"to":181,"sanitized":188},false,"medium",{"entryPoint":191,"graph":192,"unsanitizedCount":208,"severity":189},"\u003Canti-ddos-bot-recaptcha-protection> (anti-ddos-bot-recaptcha-protection.php:0)",{"nodes":193,"edges":205},[194,196,197,200],{"id":176,"type":177,"label":195,"file":153,"line":179},"$_POST (x2)",{"id":181,"type":182,"label":183,"file":153,"line":184,"wp_function":185},{"id":198,"type":177,"label":195,"file":153,"line":199},"n2",50,{"id":201,"type":182,"label":202,"file":153,"line":203,"wp_function":204},"n3","update_option() [Settings Manipulation]",51,"update_option",[206,207],{"from":176,"to":181,"sanitized":188},{"from":198,"to":201,"sanitized":188},4,{"entryPoint":210,"graph":211,"unsanitizedCount":33,"severity":217},"adbr_updateOption (anti-ddos-bot-recaptcha-protection.php:48)",{"nodes":212,"edges":215},[213,214],{"id":176,"type":177,"label":178,"file":153,"line":199},{"id":181,"type":182,"label":202,"file":153,"line":203,"wp_function":204},[216],{"from":176,"to":181,"sanitized":188},"low",{"entryPoint":219,"graph":220,"unsanitizedCount":33,"severity":217},"adbr_updateUrlOption (anti-ddos-bot-recaptcha-protection.php:55)",{"nodes":221,"edges":226},[222,224],{"id":176,"type":177,"label":178,"file":153,"line":223},57,{"id":181,"type":182,"label":202,"file":153,"line":225,"wp_function":204},61,[227],{"from":176,"to":181,"sanitized":188},{"summary":229,"deductions":230},"The plugin \"anti-ddosbot-recaptcha-protection\" v1.0.0 exhibits a generally strong security posture based on the provided static analysis.  There are no identified direct attack surface entry points like AJAX handlers, REST API routes, or shortcodes that are unprotected. The code also shows excellent adherence to secure coding practices with no dangerous functions, all SQL queries using prepared statements, and a very high percentage of properly escaped output.  Furthermore, there are no recorded vulnerabilities, CVEs, or common vulnerability types in its history, suggesting a history of secure development and maintenance.\n\nHowever, a few areas warrant attention.  The presence of 4 total taint flows with unsanitized paths, even without critical or high severity, indicates potential for unexpected behavior or subtle vulnerabilities if data is not handled with extreme care, especially given the lack of explicit capability checks.  The plugin also makes 2 external HTTP requests, which could be a vector for request forgery or data leakage if not implemented securely.  While the absence of nonce checks might be acceptable if there are no direct AJAX endpoints, it's a general good practice to consider, especially if functionality could be triggered indirectly. The lack of capability checks is a more significant concern in the absence of other access control mechanisms.",[231,234,236],{"reason":232,"points":233},"Taint flows with unsanitized paths",8,{"reason":235,"points":208},"External HTTP requests",{"reason":237,"points":11},"No capability checks","2026-03-16T23:41:37.797Z",{"wat":240,"direct":245},{"assetPaths":241,"generatorPatterns":242,"scriptPaths":243,"versionParams":244},[],[],[],[],{"cssClasses":246,"htmlComments":248,"htmlAttributes":249,"restEndpoints":259,"jsGlobals":260,"shortcodeOutput":261},[247],"wrap",[],[250,251,252,253,254,255,256,257,258],"name=\"sitekey\"","name=\"secretkey\"","name=\"ddosrecaptchamsg1\"","name=\"ddosrecaptchamsg2\"","name=\"ddosrecaptchamsg3\"","name=\"ddosrecaptchabutton\"","name=\"ddosrecaptchalockurl1\"","name=\"ddosrecaptchalockurl2\"","name=\"ddosrecaptchalockurl3\"",[],[],[],{"error":263,"url":264,"statusCode":265,"statusMessage":266,"message":266},true,"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fanti-ddosbot-recaptcha-protection\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":268,"versions":269},3,[270,275,282],{"version":6,"download_url":25,"svn_tag_url":271,"released_at":27,"has_diff":188,"diff_files_changed":272,"diff_lines":27,"trac_diff_url":273,"vulnerabilities":274,"is_current":263},"https:\u002F\u002Fplugins.svn.wordpress.org\u002Fanti-ddosbot-recaptcha-protection\u002Ftags\u002F1.1.2\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fanti-ddosbot-recaptcha-protection%2Ftags%2F1.1.0&new_path=%2Fanti-ddosbot-recaptcha-protection%2Ftags%2F1.1.2",[],{"version":276,"download_url":277,"svn_tag_url":278,"released_at":27,"has_diff":188,"diff_files_changed":279,"diff_lines":27,"trac_diff_url":280,"vulnerabilities":281,"is_current":188},"1.1.0","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fanti-ddosbot-recaptcha-protection.1.1.0.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fanti-ddosbot-recaptcha-protection\u002Ftags\u002F1.1.0\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fanti-ddosbot-recaptcha-protection%2Ftags%2F1.0.1&new_path=%2Fanti-ddosbot-recaptcha-protection%2Ftags%2F1.1.0",[],{"version":283,"download_url":284,"svn_tag_url":285,"released_at":27,"has_diff":188,"diff_files_changed":286,"diff_lines":27,"trac_diff_url":27,"vulnerabilities":287,"is_current":188},"1.0.1","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fanti-ddosbot-recaptcha-protection.1.0.1.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fanti-ddosbot-recaptcha-protection\u002Ftags\u002F1.0.1\u002F",[],[]]