Image Captcha For Gravity Forms Security & Risk Analysis

wordpress.org/plugins/image-captcha-for-gravity-forms

Adds a Honeypot and a clean image captcha to Gravity Forms. Images are made using Font Awesome's font icon.

400 active installs v2.0 PHP + WP 3.5+ Updated Jul 16, 2021
captchagravity-formsspam
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Image Captcha For Gravity Forms Safe to Use in 2026?

Generally Safe

Score 85/100

Image Captcha For Gravity Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The "image-captcha-for-gravity-forms" v2.0 plugin exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, the exclusive use of prepared statements for SQL queries, and 100% output escaping demonstrate adherence to core secure coding practices. Furthermore, the plugin has no recorded vulnerabilities, including CVEs, which suggests a history of security diligence from the developers.

The attack surface is minimal, with only one shortcode identified, and critically, no unprotected entry points were found. The lack of any reported taint flows, particularly those with unsanitized paths or critical/high severity, further bolsters confidence in its current security state. The absence of external HTTP requests and file operations also reduces potential attack vectors.

While the plugin presents a good security profile, the static analysis indicates a complete absence of nonce checks and capability checks. Although no vulnerabilities are currently apparent, this omission represents a potential weakness. If any of the identified entry points, particularly the shortcode, were to interact with sensitive data or perform privileged actions in the future, the lack of these checks could expose the site to risks. Therefore, while the current state is secure, future development should consider implementing robust authorization and integrity checks.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Image Captcha For Gravity Forms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Image Captcha For Gravity Forms Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Image Captcha For Gravity Forms Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[gfic] image-captcha-gravity-forms.php:164
WordPress Hooks 8
actioninitimage-captcha-gravity-forms.php:26
actionplugins_loadedimage-captcha-gravity-forms.php:32
filtergform_add_field_buttonsimage-captcha-gravity-forms.php:38
actiongform_editor_js_set_default_valuesimage-captcha-gravity-forms.php:62
filtergform_field_type_titleimage-captcha-gravity-forms.php:66
actiongform_editor_jsimage-captcha-gravity-forms.php:73
actiongform_field_inputimage-captcha-gravity-forms.php:84
filtergform_field_validationimage-captcha-gravity-forms.php:143
Maintenance & Trust

Image Captcha For Gravity Forms Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedJul 16, 2021
PHP min version
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs400
Developer Profile

Image Captcha For Gravity Forms Developer Profile

hookandhook

6 plugins · 121K total installs

75
trust score
Avg Security Score
94/100
Avg Patch Time
478 days
View full developer profile
Detection Fingerprints

How We Detect Image Captcha For Gravity Forms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/image-captcha-for-gravity-forms/style.css

HTML / DOM Fingerprints

Data Attributes
StartAddField('gfic');fieldSettings["gfic"] = "";case "gfic" :
Shortcode Output
fgfic_shortcode()
FAQ

Frequently Asked Questions about Image Captcha For Gravity Forms