Contact Form 7 BWP reCAPTCHA Extension Security & Risk Analysis

wordpress.org/plugins/contact-form-7-bwp-recaptcha-extension

This plugin provides a new tag for the Contact Form 7 Plugin. It allows the usage of a reCAPTCHA field provided by the BWP reCAPTCHA Plugin.

500 active installs v0.8 PHP + WP 2.9+ Updated Jun 12, 2012
captchacontactcontact-formcontact-form-7recaptcha
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Contact Form 7 BWP reCAPTCHA Extension Safe to Use in 2026?

Generally Safe

Score 85/100

Contact Form 7 BWP reCAPTCHA Extension has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 13yr ago
Risk Assessment

The static analysis of 'contact-form-7-bwp-recaptcha-extension' v0.8 indicates a generally good security posture with no identified dangerous functions, SQL injection risks, or external HTTP requests. The absence of any recorded CVEs further suggests a history of stable security. However, a significant concern arises from the complete lack of output escaping across all identified outputs. This suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data, if not properly sanitized before being displayed, could be manipulated to execute malicious scripts within a user's browser.

Key Concerns

  • No output escaping found
Vulnerabilities
None known

Contact Form 7 BWP reCAPTCHA Extension Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Contact Form 7 BWP reCAPTCHA Extension Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
10
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped10 total outputs
Attack Surface

Contact Form 7 BWP reCAPTCHA Extension Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionadmin_initincludes\CF7bwpCAPT.class.php:39
actionadmin_menuincludes\CF7bwpCAPT.class.php:40
actionadmin_noticesincludes\CF7bwpCAPT.class.php:44
actionadmin_initincludes\CF7bwpCAPT.class.php:48
actionadmin_initincludes\CF7bwpCAPT.class.php:49
filterwpcf7_validate_recaptchaincludes\CF7bwpCAPT.class.php:54
filterwpcf7_ajax_json_echoincludes\CF7bwpCAPT.class.php:55
actionplugins_loadedincludes\CF7bwpCAPT.class.php:59
Maintenance & Trust

Contact Form 7 BWP reCAPTCHA Extension Maintenance & Trust

Maintenance Signals

WordPress version tested3.1.4
Last updatedJun 12, 2012
PHP min version
Downloads33K

Community Trust

Rating80/100
Number of ratings4
Active installs500
Developer Profile

Contact Form 7 BWP reCAPTCHA Extension Developer Profile

manfer

2 plugins · 510 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Contact Form 7 BWP reCAPTCHA Extension

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/contact-form-7-bwp-recaptcha-extension/includes/css/donate.css
Version Parameters
contact-form-7-bwp-recaptcha-extension/includes/css/donate.css?ver=

HTML / DOM Fingerprints

Data Attributes
name="cf7_bwp_capt[select_theme]"name="cf7_bwp_capt[select_language]"name="cf7_bwp_capt[own_theme]"name="cf7_bwp_capt[own_language]"id="cf7_bwp_capt_own_theme"id="cf7_bwp_capt_own_language"
Shortcode Output
[recaptcha]
FAQ

Frequently Asked Questions about Contact Form 7 BWP reCAPTCHA Extension