
reCaptcha by BestWebSoft Security & Risk Analysis
wordpress.org/plugins/google-captchaProtect WordPress website forms from spam entries with Google reCAPTCHA.
Is reCaptcha by BestWebSoft Safe to Use in 2026?
Generally Safe
Score 98/100reCaptcha by BestWebSoft has a strong security track record. Known vulnerabilities have been patched promptly.
The "google-captcha" plugin, version 1.86, presents a mixed security posture. On the positive side, the static analysis shows a strong adherence to secure coding practices with a high percentage of properly escaped outputs, robust nonce and capability checks, and no detected dangerous functions. The attack surface, while present with AJAX handlers and shortcodes, appears to be well-protected, with no directly accessible unprotected entry points identified.
However, there are areas for concern. The presence of 23 SQL queries with 57% not using prepared statements is a notable risk, potentially leading to SQL injection vulnerabilities if not handled meticulously. While the taint analysis shows no critical or high severity flows, one flow with an unsanitized path indicates a potential weakness that could be exploited if an attacker can control the input. The plugin's history of 3 medium severity vulnerabilities, specifically around Cross-site Scripting and Guessable CAPTCHA, suggests recurring issues in input sanitization and CAPTCHA implementation, despite the current static analysis not flagging explicit XSS or unpatched issues.
In conclusion, the plugin demonstrates good practices in areas like output escaping and authentication checks. Nevertheless, the SQL query practices and the past vulnerability history, particularly concerning input handling and CAPTCHA logic, warrant careful consideration. While the current version shows no unpatched CVEs and a seemingly clean taint analysis, the potential for SQL injection and the historical trends suggest that ongoing vigilance and potentially further code review regarding SQL query handling are advisable.
Key Concerns
- SQL queries not using prepared statements
- Past medium severity vulnerabilities (3 total)
- Flows with unsanitized paths
reCaptcha by BestWebSoft Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
reCaptcha by BestWebSoft <= 1.78 - CAPTCHA Bypass
reCaptcha by BestWebSoft < 1.28 - Reflected Cross-Site Scripting
reCaptcha by BestWebSoft <= 1.12 - CAPTCHA Bypass
reCaptcha by BestWebSoft Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
reCaptcha by BestWebSoft Attack Surface
AJAX Handlers 4
Shortcodes 1
WordPress Hooks 61
Maintenance & Trust
reCaptcha by BestWebSoft Maintenance & Trust
Maintenance Signals
Community Trust
reCaptcha by BestWebSoft Alternatives
CAPTCHA 4WP – Antispam CAPTCHA solution for WordPress
advanced-nocaptcha-recaptcha
Use CAPTCHA to stop spam and allow customers & users to interact with your website easily. Block fake accounts and orders. Avoid false positives.
Friendly Captcha for WordPress
friendly-captcha
Friendly Captcha is a privacy-first anti-bot solution that protects WordPress website forms from spam and abuse.
reCAPTCHA in WP comments form
recaptcha-in-wp-comments-form
reCAPTCHA in WP comments form is an ANTISPAM tool that adds a Google reCAPTCHA to the comments form and protects your site from the spam robots threat …
Anti-spam, Spam protection, ReCaptcha for all forms and GDPR-compliant
gdpr-compliant-recaptcha-for-all-forms
Anti-spam - CAPTCHA that protects all forms against spam and brute-force. Invisible and GDPR-compliant.
Power Captcha reCAPTCHA
power-captcha-recaptcha
Protect WordPress/WooCommerce/Contact Form 7 forms from spam, brute-force attacks, fake comments, accounts, or registrations with Google reCAPTCHA.
reCaptcha by BestWebSoft Developer Profile
17 plugins · 207K total installs
How We Detect reCaptcha by BestWebSoft
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/google-captcha/css/style.css/wp-content/plugins/google-captcha/js/script.js/wp-content/plugins/google-captcha/js/recaptcha-v3.js/wp-content/plugins/google-captcha/js/admin-script.js/wp-content/plugins/google-captcha/css/admin-style.csshttps://www.google.com/recaptcha/api.js?onload=gglcptch_onloadCallback&render=explicitgoogle-captcha/css/style.css?ver=google-captcha/js/script.js?ver=google-captcha/js/recaptcha-v3.js?ver=google-captcha/js/admin-script.js?ver=google-captcha/css/admin-style.css?ver=HTML / DOM Fingerprints
gglcptch_captcha<!-- Start reCaptcha by BestWebSoft --><!-- End reCaptcha by BestWebSoft -->data-sitekeydata-callbackdata-badgegglcptch_onloadCallbackgglcptch_form_data