
WPBruiser {no- Captcha anti-Spam} Security & Risk Analysis
wordpress.org/plugins/goodbye-captchaAn extremely powerful antispam plugin that blocks spam-bots without annoying captcha images.
Is WPBruiser {no- Captcha anti-Spam} Safe to Use in 2026?
Generally Safe
Score 85/100WPBruiser {no- Captcha anti-Spam} has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'goodbye-captcha' plugin version 3.1.43 exhibits a mixed security posture. While it boasts a clean vulnerability history with no known CVEs and shows some good practices like using prepared statements for a majority of its SQL queries and implementing nonce and capability checks, there are significant concerns. The static analysis reveals a concerning attack surface with one AJAX handler lacking authentication checks, which presents a direct entry point for potential abuse. Furthermore, the taint analysis indicates all analyzed flows have unsanitized paths, though thankfully without critical or high severity issues in this instance. The moderate percentage of properly escaped output also suggests a potential for cross-site scripting vulnerabilities if user-supplied data is handled carelessly in the unescaped outputs.
Key Concerns
- Unprotected AJAX handler
- Unsanitized taint flows found
- Low percentage of output escaping
WPBruiser {no- Captcha anti-Spam} Security Vulnerabilities
WPBruiser {no- Captcha anti-Spam} Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WPBruiser {no- Captcha anti-Spam} Attack Surface
AJAX Handlers 1
WordPress Hooks 60
Maintenance & Trust
WPBruiser {no- Captcha anti-Spam} Maintenance & Trust
Maintenance Signals
Community Trust
WPBruiser {no- Captcha anti-Spam} Alternatives
reCaptcha by BestWebSoft
google-captcha
Protect WordPress website forms from spam entries with Google reCAPTCHA.
Anti-spam, Spam protection, ReCaptcha for all forms and GDPR-compliant
gdpr-compliant-recaptcha-for-all-forms
Anti-spam - CAPTCHA that protects all forms against spam and brute-force. Invisible and GDPR-compliant.
Human Presence – Stop Form Spam Without ReCaptcha
ellipsis-human-presence-technology
The #1 Plugin for Blocking Form Spam on WordPress
Akismet Anti-spam: Spam Protection
akismet
The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam solution for WordPress and WooCommerce.
Antispam Bee
antispam-bee
Sophisticated antispam plugin for effective daily comment and trackback spam-fighting. Built with data protection and privacy in mind.
WPBruiser {no- Captcha anti-Spam} Developer Profile
2 plugins · 100K total installs
How We Detect WPBruiser {no- Captcha anti-Spam}
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/goodbye-captcha/assets/admin/css/admin-style.css/wp-content/plugins/goodbye-captcha/assets/public/css/style.css/wp-content/plugins/goodbye-captcha/assets/public/css/gdbc-public-style.css/wp-content/plugins/goodbye-captcha/assets/public/scripts/gdbc-client.js/wp-content/plugins/goodbye-captcha/assets/public/scripts/gdbc-client-new.js.php/wp-content/plugins/goodbye-captcha/assets/public/scripts/gdbc-client.js/wp-content/plugins/goodbye-captcha/assets/public/scripts/gdbc-client-new.js.phpgoodbye-captcha/assets/public/css/style.css?ver=goodbye-captcha/assets/public/css/gdbc-public-style.css?ver=HTML / DOM Fingerprints
gdbc-settings-inputgdbc-section-titlegdbc-warning-messagegdbc-success-messagegdbc-error-messagegdbc-custom-field-wrapgdbc-ajax-loader<!-- Gdbc Brute Guardian is Active --><!-- Gdbc Brute Guardian settings -->data-gdbc-fielddata-gdbc-actiongdbc_client_ajaxgdbc_client_params/wp-json/goodbyecaptcha/v1/settings/wp-json/goodbyecaptcha/v1/nonce[wpbr]