
Image CAPTCHA for Contact Form 7 and WPForms by HookAndHook (DSGVO/GDPR) Security & Risk Analysis
wordpress.org/plugins/contact-form-7-image-captchaAdds an Image CAPTCHA to Contact Form 7 and WPForms, GDPR ready, perfect WPForms or Contact Form 7 Spam Protection Image CAPTCHA, adds a honeypot
Is Image CAPTCHA for Contact Form 7 and WPForms by HookAndHook (DSGVO/GDPR) Safe to Use in 2026?
Generally Safe
Score 100/100Image CAPTCHA for Contact Form 7 and WPForms by HookAndHook (DSGVO/GDPR) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "contact-form-7-image-captcha" plugin v3.3.28 exhibits a mixed security posture. On the positive side, there are no known CVEs, indicating a historically stable record. The static analysis reveals a limited attack surface, with only one shortcode and no AJAX handlers or REST API routes exposed. Furthermore, the absence of dangerous functions, file operations, and external HTTP requests are good signs. However, several concerns arise from the code analysis. The low percentage of properly escaped output (17%) is a significant weakness, suggesting a high risk of cross-site scripting (XSS) vulnerabilities. The fact that none of the entry points have capability checks or nonce checks is also worrying, as it means any user could potentially interact with the shortcode in unintended ways. The SQL query usage is also concerning, with half of the queries not using prepared statements, which could lead to SQL injection vulnerabilities.
While the taint analysis reported no flows, this might be due to the limited scope or nature of the tested code paths. The lack of capability checks and nonce checks significantly weakens the overall security, even with a small attack surface. The poorly escaped output is a direct pathway for XSS attacks. The vulnerability history is a strong point, but it does not negate the identified weaknesses in the current version. In conclusion, while the plugin has a clean vulnerability record, the current version has significant security concerns related to output sanitization and lack of authorization checks, which require immediate attention.
Key Concerns
- Low percentage of properly escaped output
- No nonce checks on entry points
- No capability checks on entry points
- 50% of SQL queries not using prepared statements
Image CAPTCHA for Contact Form 7 and WPForms by HookAndHook (DSGVO/GDPR) Security Vulnerabilities
Image CAPTCHA for Contact Form 7 and WPForms by HookAndHook (DSGVO/GDPR) Code Analysis
SQL Query Safety
Output Escaping
Image CAPTCHA for Contact Form 7 and WPForms by HookAndHook (DSGVO/GDPR) Attack Surface
Shortcodes 1
WordPress Hooks 13
Maintenance & Trust
Image CAPTCHA for Contact Form 7 and WPForms by HookAndHook (DSGVO/GDPR) Maintenance & Trust
Maintenance Signals
Community Trust
Image CAPTCHA for Contact Form 7 and WPForms by HookAndHook (DSGVO/GDPR) Alternatives
MultiForm Anti-Spam Image CAPTCHA for Contact Form 7, WPForms and Formidable Forms by Plugin Brewery (DSGVO/GDPR)
multiform-anti-spam-image-captcha
Add a GDPR-ready image CAPTCHA and honeypot to Contact Form 7, WPForms, and Formidable Forms. Fight spam!
ReCaptcha v2 for Contact Form 7
wpcf7-recaptcha
Adds reCaptcha v2 from Contact Form 7 5.0.5 that was dropped on Contact Form 7 5.1
Contact Form 7 Captcha
contact-form-7-simple-recaptcha
Protect your Contact Form 7 forms with Google reCAPTCHA V2, Google reCAPTCHA V3, hCAPTCHA, or Cloudflare Turnstile.
SilentShield – Captcha & Anti-Spam for WordPress (CF7, WPForms, Elementor, WooCommerce)
captcha-for-contact-form-7
SilentShield – the invisible shield against spam. Spam is the weed of the internet. It clogs your forms, steals your time, and corrupts your data.
WP Advanced Math Captcha
wp-advanced-math-captcha
Protect your WordPress site with a powerful and user-friendly Math Captcha. Now with seamless WooCommerce, WPForms, and Formidable Forms integration!
Image CAPTCHA for Contact Form 7 and WPForms by HookAndHook (DSGVO/GDPR) Developer Profile
6 plugins · 121K total installs
How We Detect Image CAPTCHA for Contact Form 7 and WPForms by HookAndHook (DSGVO/GDPR)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/contact-form-7-image-captcha/assets/icon-cf7.svg/wp-content/plugins/contact-form-7-image-captcha/assets/example-cf7.png/wp-content/plugins/contact-form-7-image-captcha/assets/icon-wpf.svg/wp-content/plugins/contact-form-7-image-captcha/assets/star.svg/wp-content/plugins/contact-form-7-image-captcha/assets/icon-cf7ic.svg/wp-content/plugins/contact-form-7-image-captcha/assets/pro-language.png/wp-content/plugins/contact-form-7-image-captcha/assets/pro-new-colors.png/wp-content/plugins/contact-form-7-image-captcha/assets/pro-color.png+1 morecontact-form-7-image-captcha/css/cf7ic-style.css?ver=contact-form-7-image-captcha/css/fontawesome.css?ver=contact-form-7-image-captcha/css/cf7ic-admin-style.css?ver=HTML / DOM Fingerprints
cf7ic-main-headingcf7ic-main-wrappercf7ic-wrappercf7ic-form-iconscf7ic-highlightcf7ic-examplecf7ic-separatorcf7ic-pro-p+4 moreid="ai1ic-form"name="ai1ic-form"cf7ic_ajax_url[cf7ic][cf7ic "toggle"]