
Contact Form 7 Captcha Security & Risk Analysis
wordpress.org/plugins/contact-form-7-simple-recaptchaProtect your Contact Form 7 forms with Google reCAPTCHA V2, Google reCAPTCHA V3, hCAPTCHA, or Cloudflare Turnstile.
Is Contact Form 7 Captcha Safe to Use in 2026?
Generally Safe
Score 99/100Contact Form 7 Captcha has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin 'contact-form-7-simple-recaptcha' version 0.1.7 exhibits a generally good security posture based on the provided static analysis. It demonstrates a commitment to secure coding practices, with all SQL queries using prepared statements and a high percentage of output being properly escaped. The absence of direct file operations and dangerous functions further strengthens its security. Importantly, all identified entry points, including shortcodes, appear to be protected by appropriate checks, and there are no identified unsanitized taint flows of critical or high severity.
However, the plugin's vulnerability history raises some concerns. It has had two known CVEs in the past, with one high and one medium severity vulnerability previously discovered. While there are no currently unpatched vulnerabilities, the historical presence of Cross-Site Scripting (XSS) issues indicates potential weaknesses in input sanitization or output escaping in previous versions. The presence of external HTTP requests, while not inherently a vulnerability, represents a potential attack vector if the target endpoints are compromised or malicious. Overall, while the current version shows strong secure coding practices, the past vulnerability record warrants continued vigilance and regular security audits.
Key Concerns
- Past High/Medium severity vulnerabilities found
- Presence of external HTTP requests
Contact Form 7 Captcha Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Contact Form 7 Captcha <= 0.1.1 - Reflected Cross-Site Scripting
Contact Form 7 Captcha <= 0.0.8 - Cross-Site Request Forgery to Stored Cross-Site Scripting
Contact Form 7 Captcha Code Analysis
Output Escaping
Data Flow Analysis
Contact Form 7 Captcha Attack Surface
Shortcodes 5
WordPress Hooks 13
Maintenance & Trust
Contact Form 7 Captcha Maintenance & Trust
Maintenance Signals
Community Trust
Contact Form 7 Captcha Alternatives
CAPTCHA 4WP – Antispam CAPTCHA solution for WordPress
advanced-nocaptcha-recaptcha
Use CAPTCHA to stop spam and allow customers & users to interact with your website easily. Block fake accounts and orders. Avoid false positives.
Contact Form 7 Text CAPTCHA
text-captcha-contact-form-7
Secure your website Contact Form 7 forms from bots and hackers using plugin Contact Form 7 Text CAPTCHA. Just place shortcode [captchacf7* input-captc …
BotShield CAPTCHA for Contact Form 7
botshield-captcha
BotShield CAPTCHA for Contact Form 7 – Advanced Spam Protection with Turnstile, reCAPTCHA, Arithmetic, and Alphanumeric.
Text Captcha For Contact Form 7 [GWE]
text-captcha-for-contact-form-7
Adds a text captcha to Contact Form 7
ReCaptcha v2 for Contact Form 7
wpcf7-recaptcha
Adds reCaptcha v2 from Contact Form 7 5.0.5 that was dropped on Contact Form 7 5.1
Contact Form 7 Captcha Developer Profile
1 plugin · 100K total installs
How We Detect Contact Form 7 Captcha
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/contact-form-7-simple-recaptcha/assets/css/admin.csscontact-form-7-simple-recaptcha/assets/css/admin.css?ver=HTML / DOM Fingerprints
cf7sr-contentdata-sitekeydata-callbackdata-expired-callbackcf7srLoadHcaptchahcaptchaIdsgrecaptchacf7sr_recaptcha_v3_settingscf7sr_recaptcha_v3_readycf7sr_turnstile_load[cf7sr-recaptcha][cf7sr-hcaptcha][cf7sr-turnstile]