Eazy CF Captcha Security & Risk Analysis

wordpress.org/plugins/eazy-cf-catpcha

Eazy C(omment)F(orm) Captcha adds a mathematic exercise to the comment form, contact form 7 & elementor, preventing bots to spam your comments and …

500 active installs v1.2.6 PHP 7.4+ WP 2.9.0+ Updated Apr 4, 2024
captchacf7comment-formcontact-form-7elementor
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Eazy CF Captcha Safe to Use in 2026?

Generally Safe

Score 85/100

Eazy CF Captcha has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The eazy-cf-catpcha plugin, version 1.2.6, exhibits a generally good security posture based on the provided static analysis and vulnerability history. The absence of any known CVEs, unpatched vulnerabilities, or recorded common vulnerability types is a significant strength, suggesting a history of relatively secure development or prompt patching.

However, the static analysis reveals some areas for improvement. While there are no identified dangerous functions, SQL queries are properly prepared, and file operations or external HTTP requests are absent, there are concerns regarding output escaping. With 66% of outputs properly escaped, approximately one-third of the outputs are not, creating a potential risk for cross-site scripting (XSS) vulnerabilities, especially if user-supplied data is involved in these unescaped outputs. Furthermore, the lack of capability checks on entry points, though the attack surface is currently zero, implies that if new entry points were introduced without proper authorization checks, they could be exploitable. The presence of a single nonce check is positive, but its scope is not detailed.

Key Concerns

  • Outputs are not fully escaped
  • No capability checks on entry points
Vulnerabilities
None known

Eazy CF Captcha Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Eazy CF Captcha Release Timeline

v1.2.5
v1.2.4
v1.2.3
v1.2.2
v1.2.1
v1.2.0
v1.1.2
v1.1.1
v1.1.0
v1.0.4
v1.0.3
v1.0.2
v1.0.1
v1.0.0
Code Analysis
Analyzed Mar 16, 2026

Eazy CF Captcha Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
16
31 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

66% escaped47 total outputs
Attack Surface

Eazy CF Captcha Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 17
actionadmin_menuincludes\Admin\EazyCFCaptchaAdmin.php:17
actionwpcf7_admin_initincludes\Admin\EazyCFCaptchaAdmin.php:20
actionplugins_loadedincludes\EazyCFCaptchaPlugin.php:64
filteroption_eazycfc_label_textincludes\EazyCFCaptchaPlugin.php:65
actionplugins_loadedincludes\EazyCFCaptchaPlugin.php:129
actionelementor_pro/forms/register_actionincludes\Elementor\EazyCFElementor.php:14
actionelementor_pro/forms/fields/registerincludes\Elementor\EazyCFElementor.php:16
actionelementor_pro/forms/render/itemincludes\Elementor\Fields\EazyCFCaptcha.php:35
filterelementor_pro/forms/field_typesincludes\Elementor\Fields\EazyCFCaptcha.php:38
actionelementor/preview/enqueue_scriptsincludes\Elementor\Fields\EazyCFCaptcha.php:40
actionelementor/element/form/section_form_fields/before_section_endincludes\Elementor\Fields\EazyCFCaptcha.php:42
actionwp_enqueue_scriptsincludes\PluginPublic\EazyCFCPublicBase.php:39
filtercomment_form_after_fieldsincludes\PluginPublic\EazyCFCPublicCommentForm.php:20
actionpre_comment_on_postincludes\PluginPublic\EazyCFCPublicCommentForm.php:21
actionwpcf7_initincludes\PluginPublic\EazyCFCPublicContactForm7.php:20
filterwpcf7_validate_eazy_cf_captchaincludes\PluginPublic\EazyCFCPublicContactForm7.php:21
filterwpcf7_validate_eazy_cf_captcha*includes\PluginPublic\EazyCFCPublicContactForm7.php:22
Maintenance & Trust

Eazy CF Captcha Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedApr 4, 2024
PHP min version7.4
Downloads17K

Community Trust

Rating80/100
Number of ratings4
Active installs500
Developer Profile

Eazy CF Captcha Developer Profile

Tamás

3 plugins · 2K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Eazy CF Captcha

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/eazy-cf-catpcha/assets/js/admin.elementor.js
Script Paths
/wp-content/plugins/eazy-cf-catpcha/assets/js/admin.elementor.js
Version Parameters
eazycfcaptcha-elementor

HTML / DOM Fingerprints

CSS Classes
eazycfc-captcha-containerelementor-field-type-eazycfcaptcha
Data Attributes
data-eazycfc-option-remove-honeypotdata-eazycfc-option-easydata-eazycfc-option-show-logged-in
JS Globals
eazycfcaptcha
FAQ

Frequently Asked Questions about Eazy CF Captcha