Captisa Forms Shortcode Plugin Security & Risk Analysis

wordpress.org/plugins/captisa-forms-shortcode

Allows the use of a special short code [captisa] for embedding Captisa Forms.

10 active installs v1.1 PHP + WP 3.3+ Updated Aug 20, 2020
form-builderhtml-formslead-generationonline-formsweb-forms
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Captisa Forms Shortcode Plugin Safe to Use in 2026?

Generally Safe

Score 85/100

Captisa Forms Shortcode Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The static analysis of the "captisa-forms-shortcode" plugin version 1.1 indicates a generally good security posture. The plugin demonstrates adherence to secure coding practices by utilizing prepared statements for all SQL queries and ensuring proper output escaping. Notably, there are no identified dangerous functions, file operations, or external HTTP requests, further contributing to a low-risk profile. The attack surface is minimal and appears to be well-protected, with no unauthenticated entry points identified across AJAX handlers, REST API routes, or cron events.

The vulnerability history is also a strong positive signal, showing no recorded CVEs whatsoever. This lack of past vulnerabilities, combined with the clean static analysis results, suggests that the developers have a strong focus on security. There are no immediate or apparent risks stemming from code analysis or taint flows. The absence of bundled libraries also removes a potential vector for known vulnerabilities.

In conclusion, based on the provided data, "captisa-forms-shortcode" v1.1 appears to be a secure plugin with a minimal risk profile. The developers have implemented good security practices and there is no historical evidence of vulnerabilities. The limited attack surface and protected entry points are commendable. It's important to note that this assessment is based solely on the provided static analysis and vulnerability history, and a comprehensive security audit would involve dynamic analysis and review of the full codebase.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Captisa Forms Shortcode Plugin Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Captisa Forms Shortcode Plugin Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

Captisa Forms Shortcode Plugin Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Captisa Forms Shortcode Plugin Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[captisa] captisa.php:41
Maintenance & Trust

Captisa Forms Shortcode Plugin Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedAug 20, 2020
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Captisa Forms Shortcode Plugin Developer Profile

captisaforms

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Captisa Forms Shortcode Plugin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Script Paths
/wp-content/plugins/captisa-forms-shortcode/scripts/cora.embed.js/wp-content/plugins/captisa-forms-shortcode/p/widget/[id]

HTML / DOM Fingerprints

CSS Classes
captisa-formcaptisa-body
Data Attributes
id='captisaEmbed'
JS Globals
cora.widget.load
Shortcode Output
<section class='captisa-form'><div class='captisa-body'><script id='captisaEmbed' src='https://secure.captisa.com/scripts/cora.embed.js'></script><script type='text/javascript'>
FAQ

Frequently Asked Questions about Captisa Forms Shortcode Plugin