
BT Captcha Security & Risk Analysis
wordpress.org/plugins/bt-captchaBT Captcha - simple, Bilingual, Flexible, Protect Your WP Blog Against Comment Spams
Is BT Captcha Safe to Use in 2026?
Generally Safe
Score 85/100BT Captcha has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "bt-captcha" v1.0 plugin exhibits a mixed security posture. On one hand, the absence of known vulnerabilities and CVEs in its history is a positive indicator, suggesting a well-maintained or less-targeted plugin. The static analysis also shows a lack of dangerous functions, SQL injection vulnerabilities, file operations, and external HTTP requests, which are all strong security practices. However, significant concerns arise from the output escaping. With 100% of outputs not properly escaped, this presents a high risk of cross-site scripting (XSS) vulnerabilities. Although the taint analysis did not flag critical or high severity issues, the presence of unsanitized flows indicates potential weaknesses that could be exploited if user input is not handled carefully. The complete lack of nonce checks and capability checks, combined with zero AJAX handlers and REST API routes, is unusual for a plugin that likely interacts with user input. While this reduces the attack surface, it also means there's no granular access control or protection against certain types of attacks if any entry points were to be discovered or introduced in future versions. The plugin's strengths lie in its clean history and avoidance of common dangerous code patterns, but the unescaped output is a glaring weakness that requires immediate attention.
Key Concerns
- All outputs are unescaped, leading to XSS risk
- No nonce checks implemented
- No capability checks implemented
- Taint analysis found unsanitized flows
BT Captcha Security Vulnerabilities
BT Captcha Release Timeline
BT Captcha Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
BT Captcha Attack Surface
WordPress Hooks 3
Maintenance & Trust
BT Captcha Maintenance & Trust
Maintenance Signals
Community Trust
BT Captcha Alternatives
AntiBot Captcha
antibot-captcha
AntiBot Captcha - simple good-looking, but well-protected plugin against spam robots for your blog comments
Advanced Invisible Anti-Spam
advanced-invisible-anti-spam
Block bots without annoying captchas. Cache friendly solution with rotating keys! Blocks comment, registration, and bbpress spam. Activate and done!
BotBlocker
botblocker
Kills spam-bots, leaves humans standing. No CAPTCHAS, no math questions, no passwords, just spam blocking that stops spam-bots dead in their tracks.
Spam Protection Without Captcha
spam-protection-without-captcha
Protect Login, Register, Lost & Reset Password, Comment, woocommerce, CF7, bbpress, BuddyPress forms.
Spam protection, Honeypot, Anti-Spam by CleanTalk
cleantalk-spam-protect
Blocks spam comments, fake users, contact form spam and more. No impact on SEO. Privacy focused. CAPTCHA free, premium Antispam plugin.
BT Captcha Developer Profile
1 plugin · 10 total installs
How We Detect BT Captcha
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bt-captcha/bt-captcha.jsHTML / DOM Fingerprints
textfieldid="bt-captcha"window.urlinput