
DS CF7 Math Captcha Security & Risk Analysis
wordpress.org/plugins/ds-cf7-math-captcha"DS CF7 Math Captcha" is a math captcha with refresh captcha functionality to prevent unwanted spam for your contact form 7 plugin.
Is DS CF7 Math Captcha Safe to Use in 2026?
Generally Safe
Score 99/100DS CF7 Math Captcha has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin 'ds-cf7-math-captcha' v3.1.0 exhibits a mixed security posture. On the positive side, the code analysis reveals a strong adherence to secure coding practices. There are no dangerous functions, all SQL queries utilize prepared statements, and a very high percentage of outputs are properly escaped. Furthermore, the plugin demonstrates good use of nonces and capability checks within its code. The absence of critical or high-severity taint flows indicates that data is generally handled safely.
However, significant concerns arise from the attack surface. The plugin exposes two AJAX handlers, both of which lack authentication checks. This presents a direct pathway for unauthenticated users to interact with potentially sensitive functionalities, even if the code analysis itself did not reveal specific exploitable flaws in this version. The vulnerability history shows one known CVE, which was a medium severity Cross-Site Scripting (XSS) vulnerability, last patched in September 2024. While this specific vulnerability is patched, the presence of past vulnerabilities, even if not critical, suggests a need for ongoing vigilance and rigorous security auditing.
In conclusion, while the code itself is largely well-written and secure, the unprotected AJAX endpoints are a notable weakness. Coupled with a history of past vulnerabilities, this warrants caution. The plugin's strengths lie in its diligent use of prepared statements and output escaping. The primary area for improvement is securing all entry points, especially AJAX handlers, to mitigate potential risks.
Key Concerns
- AJAX handlers without auth checks
- Medium severity vulnerability in history
DS CF7 Math Captcha Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Contact Form 7 Math Captcha <= 3.0.0 - Reflected Cross-Site Scripting
DS CF7 Math Captcha Code Analysis
Output Escaping
Data Flow Analysis
DS CF7 Math Captcha Attack Surface
AJAX Handlers 2
WordPress Hooks 10
Maintenance & Trust
DS CF7 Math Captcha Maintenance & Trust
Maintenance Signals
Community Trust
DS CF7 Math Captcha Alternatives
Contact Form 7 Spam Killer
cf7-advance-security
"Contact Form 7 Spam Killer" is a advance spam blocker that will help to prevent unwanted spam for your Contact Form 7 plugin.
ReCaptcha v2 for Contact Form 7
wpcf7-recaptcha
Adds reCaptcha v2 from Contact Form 7 5.0.5 that was dropped on Contact Form 7 5.1
Contact Form 7 Captcha
contact-form-7-simple-recaptcha
Protect your Contact Form 7 forms with Google reCAPTCHA V2, Google reCAPTCHA V3, hCAPTCHA, or Cloudflare Turnstile.
Invisible reCaptcha for WordPress
invisible-recaptcha
Invisible reCaptcha for WordPress plugin helps you to protect your sites against bad spam bots using the new Invisible reCaptcha by Google.
Image CAPTCHA for Contact Form 7 and WPForms by HookAndHook (DSGVO/GDPR)
contact-form-7-image-captcha
Adds an Image CAPTCHA to Contact Form 7 and WPForms, GDPR ready, perfect WPForms or Contact Form 7 Spam Protection Image CAPTCHA, adds a honeypot
DS CF7 Math Captcha Developer Profile
1 plugin · 30K total installs
How We Detect DS CF7 Math Captcha
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ds-cf7-math-captcha/assets/css/admin-style.css/wp-content/plugins/ds-cf7-math-captcha/assets/js/script-min.jsds-cf7-math-captcha/assets/js/script-min.js?ver=HTML / DOM Fingerprints
notice-warningajax_object[dscf7captcha]