Gravity Forms No CAPTCHA reCAPTCHA Security & Risk Analysis

wordpress.org/plugins/gravity-forms-no-captcha-recaptcha

Adds "No CAPTCHA reCAPTCHA" field to Gravity Forms as an alternative CAPTCHA option

10K active installs v1.0.7 PHP + WP 4.0.0+ Updated Nov 28, 2017
captchagravity-formsno-captcharecaptcha
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Gravity Forms No CAPTCHA reCAPTCHA Safe to Use in 2026?

Generally Safe

Score 85/100

Gravity Forms No CAPTCHA reCAPTCHA has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The plugin "gravity-forms-no-captcha-recaptcha" version 1.0.7 exhibits a generally good security posture with no recorded vulnerabilities or critical code signals. The static analysis shows a remarkably small attack surface, with zero entry points identified that lack authentication or permission checks. Furthermore, all SQL queries are properly prepared, and there are no external HTTP requests or bundled libraries, which are positive indicators.

However, there are a few areas of concern. The taint analysis revealed two flows with unsanitized paths, which could potentially lead to vulnerabilities if not carefully handled, although no critical or high severity issues were flagged in this regard. The output escaping is also a point of weakness, with only 33% of outputs being properly escaped, which could open the door to cross-site scripting (XSS) vulnerabilities if user-supplied data is outputted without sufficient sanitization. The presence of file operations and a single capability check without other security measures like nonces also warrants attention.

In conclusion, while the plugin benefits from a lack of historical vulnerabilities and a minimal attack surface, the identified unsanitized paths and insufficient output escaping present potential risks. Developers should prioritize addressing these code-level concerns to further strengthen the plugin's security.

Key Concerns

  • Unsanitized paths found in taint analysis
  • Low percentage of properly escaped output
  • File operations present
  • No nonce checks on entry points
Vulnerabilities
None known

Gravity Forms No CAPTCHA reCAPTCHA Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Gravity Forms No CAPTCHA reCAPTCHA Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
4 escaped
Nonce Checks
0
Capability Checks
1
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

33% escaped12 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
gravity_forms_validate (public\class-gf-no-captcha-recaptcha-public.php:270)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Gravity Forms No CAPTCHA reCAPTCHA Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionplugins_loadedincludes\class-gf-no-captcha-recaptcha.php:149
actionadmin_initincludes\class-gf-no-captcha-recaptcha.php:165
actionadmin_menuincludes\class-gf-no-captcha-recaptcha.php:166
actionadmin_noticesincludes\class-gf-no-captcha-recaptcha.php:167
filtergform_add_field_buttonsincludes\class-gf-no-captcha-recaptcha.php:182
filtergform_field_type_titleincludes\class-gf-no-captcha-recaptcha.php:183
actiongform_field_inputincludes\class-gf-no-captcha-recaptcha.php:184
actiongform_editor_jsincludes\class-gf-no-captcha-recaptcha.php:185
actiongform_field_advanced_settingsincludes\class-gf-no-captcha-recaptcha.php:186
actiongform_enqueue_scriptsincludes\class-gf-no-captcha-recaptcha.php:187
filtergform_field_validationincludes\class-gf-no-captcha-recaptcha.php:188
Maintenance & Trust

Gravity Forms No CAPTCHA reCAPTCHA Maintenance & Trust

Maintenance Signals

WordPress version tested4.0.0
Last updatedNov 28, 2017
PHP min version
Downloads53K

Community Trust

Rating96/100
Number of ratings26
Active installs10K
Developer Profile

Gravity Forms No CAPTCHA reCAPTCHA Developer Profile

folkhack

1 plugin · 10K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Gravity Forms No CAPTCHA reCAPTCHA

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gravity-forms-no-captcha-recaptcha/public/js/gf-no-captcha-recaptcha-public.js
Script Paths
https://www.google.com/recaptcha/api.js
Version Parameters
gravity-forms-no-captcha-recaptcha/public/js/gf-no-captcha-recaptcha-public.js?ver=

HTML / DOM Fingerprints

CSS Classes
g-recaptcha
Data Attributes
data-sitekey
JS Globals
grecaptcha
FAQ

Frequently Asked Questions about Gravity Forms No CAPTCHA reCAPTCHA