
Anti-spam, Spam protection, ReCaptcha for all forms and GDPR-compliant Security & Risk Analysis
wordpress.org/plugins/gdpr-compliant-recaptcha-for-all-formsAnti-spam - CAPTCHA that protects all forms against spam and brute-force. Invisible and GDPR-compliant.
Is Anti-spam, Spam protection, ReCaptcha for all forms and GDPR-compliant Safe to Use in 2026?
Generally Safe
Score 99/100Anti-spam, Spam protection, ReCaptcha for all forms and GDPR-compliant has a strong security track record. Known vulnerabilities have been patched promptly.
The "gdpr-compliant-recaptcha-for-all-forms" plugin v4.1.2 exhibits a mixed security posture. On the positive side, it makes good use of prepared statements for SQL queries and has a history of addressing vulnerabilities promptly. However, there are significant concerns, particularly regarding its attack surface. A substantial number of AJAX handlers (half of the total) lack proper authentication checks, creating potential entry points for unauthorized actions. The taint analysis further amplifies these concerns, revealing a high number of flows with unsanitized paths, four of which are rated as high severity. This suggests a strong possibility of vulnerabilities like cross-site scripting or insecure direct object references within these unsanitized flows, especially when combined with the unprotected AJAX endpoints.
The vulnerability history shows one past medium severity CVE, which was a Cross-Site Request Forgery. While there are no currently unpatched vulnerabilities, the past occurrence of CSRF, coupled with the unprotected AJAX handlers, warrants attention as it indicates a potential for similar issues if not mitigated. The plugin demonstrates a weakness in output escaping, with over a third of outputs not being properly escaped, which could lead to cross-site scripting vulnerabilities. The presence of file operations and external HTTP requests, while not inherently dangerous, require careful scrutiny in the context of the identified taint issues.
In conclusion, while the plugin demonstrates some good security practices like prepared statement usage and a proactive approach to patching past vulnerabilities, the significant number of unprotected AJAX handlers and high-severity taint flows with unsanitized paths represent critical areas of concern. The less-than-ideal output escaping further adds to the risk profile. Addressing these specific weaknesses is crucial to improving the plugin's overall security.
Key Concerns
- Unprotected AJAX handlers
- High severity taint flows with unsanitized paths
- Unescaped output
- One past medium severity CVE
Anti-spam, Spam protection, ReCaptcha for all forms and GDPR-compliant Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Anti-spam, Spam protection, ReCaptcha for all forms and GDPR-compliant <= 4.1.1 - Cross-Site Request Forgery
Anti-spam, Spam protection, ReCaptcha for all forms and GDPR-compliant Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Anti-spam, Spam protection, ReCaptcha for all forms and GDPR-compliant Attack Surface
AJAX Handlers 12
WordPress Hooks 28
Scheduled Events 1
Maintenance & Trust
Anti-spam, Spam protection, ReCaptcha for all forms and GDPR-compliant Maintenance & Trust
Maintenance Signals
Community Trust
Anti-spam, Spam protection, ReCaptcha for all forms and GDPR-compliant Alternatives
CAPTCHA 4WP – Antispam CAPTCHA solution for WordPress
advanced-nocaptcha-recaptcha
Use CAPTCHA to stop spam and allow customers & users to interact with your website easily. Block fake accounts and orders. Avoid false positives.
reCaptcha by BestWebSoft
google-captcha
Protect WordPress website forms from spam entries with Google reCAPTCHA.
reCAPTCHA in WP comments form
recaptcha-in-wp-comments-form
reCAPTCHA in WP comments form is an ANTISPAM tool that adds a Google reCAPTCHA to the comments form and protects your site from the spam robots threat …
Antispam Bee
antispam-bee
Sophisticated antispam plugin for effective daily comment and trackback spam-fighting. Built with data protection and privacy in mind.
CF7 Apps – Honeypot, Database, Redirection, Webhook, and Addons for Contact Form 7
contact-form-7-honeypot
Addons for Contact Form 7 — Honeypot, Database Entries, Redirection, Spam Protection, Webhooks, ACF integration for Contact Form 7, and more.
Anti-spam, Spam protection, ReCaptcha for all forms and GDPR-compliant Developer Profile
2 plugins · 4K total installs
How We Detect Anti-spam, Spam protection, ReCaptcha for all forms and GDPR-compliant
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gdpr-compliant-recaptcha-for-all-forms/css/style_warning_simulation.css/wp-content/plugins/gdpr-compliant-recaptcha-for-all-forms/scripts/recaptcha-gdpr-pro-state.js/wp-content/plugins/gdpr-compliant-recaptcha-for-all-forms/scripts/recaptcha-gdpr-pro-state.jsgdpr-compliant-recaptcha-for-all-forms/css/style_warning_simulation.css?ver=gdpr-compliant-recaptcha-for-all-forms/scripts/recaptcha-gdpr-pro-state.js?ver=HTML / DOM Fingerprints
<!-- in main plugin file -->