
humanID – Anti-Spam Comment Filter Security & Risk Analysis
wordpress.org/plugins/humanid-spam-filterReplace ReCAPTCHA with a faster, user-friendly solution and block spammers & bots permanently
Is humanID – Anti-Spam Comment Filter Safe to Use in 2026?
Generally Safe
Score 100/100humanID – Anti-Spam Comment Filter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'humanid-spam-filter' v2.1.2 plugin presents a mixed security posture. On the positive side, the code demonstrates strong practices regarding SQL queries, with all 4 queries utilizing prepared statements, indicating a reduced risk of SQL injection. Furthermore, the plugin exhibits excellent output escaping hygiene, with 97% of outputs properly escaped, significantly mitigating cross-site scripting (XSS) vulnerabilities. The absence of file operations and bundled libraries also simplifies the attack surface. However, a significant concern is the presence of 3 AJAX handlers that lack any authentication or authorization checks. This creates a substantial attack vector, as any unauthenticated user could potentially trigger these actions, leading to unintended consequences or even exploitation if the handlers perform sensitive operations. The lack of nonce checks and capability checks on these AJAX endpoints further exacerbates this risk, making them highly vulnerable.
Key Concerns
- AJAX handlers without auth checks
- AJAX handlers without nonce checks
- AJAX handlers without capability checks
humanID – Anti-Spam Comment Filter Security Vulnerabilities
humanID – Anti-Spam Comment Filter Release Timeline
humanID – Anti-Spam Comment Filter Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
humanID – Anti-Spam Comment Filter Attack Surface
AJAX Handlers 3
WordPress Hooks 25
Maintenance & Trust
humanID – Anti-Spam Comment Filter Maintenance & Trust
Maintenance Signals
Community Trust
humanID – Anti-Spam Comment Filter Alternatives
WP Armour – Honeypot Anti Spam
honeypot
Fastest growing Anti Spam plugin. No API calls, subscriptions, captcha or puzzle. Full GDPR complaint. For comments, contact form, login, registration
Anti-Spam Protection – No API Key, GDPR Friendly
fullworks-anti-spam
Block spam on Contact Form 7, WPForms & comments. No API key. GDPR compliant. Free for commercial use. No configuration needed.
Advanced Spam Protection for Contact Form 7
gotechark-advanced-spam-shield-for-contact-form-7
A powerful spam protection plugin for Contact Form 7 that blocks bots, spam submissions, VPN users, repeated attempts, and automated attacks — without …
Antispam Bee
antispam-bee
Sophisticated antispam plugin for effective daily comment and trackback spam-fighting. Built with data protection and privacy in mind.
CF7 Apps – Honeypot, Database, Redirection, Webhook, and Addons for Contact Form 7
contact-form-7-honeypot
Addons for Contact Form 7 — Honeypot, Database Entries, Redirection, Spam Protection, Webhooks, ACF integration for Contact Form 7, and more.
humanID – Anti-Spam Comment Filter Developer Profile
1 plugin · 0 total installs
How We Detect humanID – Anti-Spam Comment Filter
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/humanid-spam-filter/assets/css/app.css/wp-content/plugins/humanid-spam-filter/assets/js/app.js/wp-content/plugins/humanid-spam-filter/assets/js/admin.js/wp-content/plugins/humanid-spam-filter/assets/js/app.js/wp-content/plugins/humanid-spam-filter/assets/js/admin.jshumanid-spam-filter/assets/css/app.css?ver=humanid-spam-filter/assets/js/app.js?ver=humanid-spam-filter/assets/js/admin.js?ver=HTML / DOM Fingerprints
update-pluginsupdate-counthid_ajax_object