
Invisible reCaptcha for WordPress Security & Risk Analysis
wordpress.org/plugins/invisible-recaptchaInvisible reCaptcha for WordPress plugin helps you to protect your sites against bad spam bots using the new Invisible reCaptcha by Google.
Is Invisible reCaptcha for WordPress Safe to Use in 2026?
Generally Safe
Score 85/100Invisible reCaptcha for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of "invisible-recaptcha" v1.2.3 reveals a mixed security posture. While the plugin demonstrates good practices by having no exposed AJAX handlers, REST API routes, shortcodes, or cron events without proper authentication or permission checks, and no recorded historical vulnerabilities, there are significant concerns within its code signals. The presence of two instances of the dangerous `exec` function is a major red flag, as it can lead to remote code execution if not handled with extreme caution and proper sanitization. Furthermore, the fact that 100% of SQL queries are not using prepared statements is a serious vulnerability, increasing the risk of SQL injection attacks. The relatively low rate of properly escaped output (53%) also suggests potential for cross-site scripting (XSS) vulnerabilities. The lack of any taint analysis results could indicate either a very simple codebase or a limitation in the analysis tool's ability to detect complex data flows, but given the other signals, it should not be seen as confirmation of safety.
Key Concerns
- Dangerous function 'exec' found
- Raw SQL queries without prepared statements
- Low percentage of properly escaped output
Invisible reCaptcha for WordPress Security Vulnerabilities
Invisible reCaptcha for WordPress Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Invisible reCaptcha for WordPress Attack Surface
WordPress Hooks 18
Maintenance & Trust
Invisible reCaptcha for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
Invisible reCaptcha for WordPress Alternatives
CF7 Invisible reCAPTCHA
cf7-invisible-recaptcha
CF7 Invisible reCAPTCHA plugin is an effective solution that secures your Contact form 7 forms on WordPress websites from spam entries while letting h …
Invisible Anti Spam for Contact Form 7 (Simple No-Bot)
simple-no-bot
Simple, lightweight, no captcha, no configuration. Just works.
Invisible reCaptcha for WordPress Developer Profile
2 plugins · 100K total installs
How We Detect Invisible reCaptcha for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/invisible-recaptcha/assets/admin/styles/invisible-recaptcha.csshttps://www.google.com/recaptcha/api.jsinvisible-recaptcha/assets/admin/styles/invisible-recaptcha.css?ver=HTML / DOM Fingerprints
g-recaptchadata-sitekeydata-sizedata-badgerenderInvisibleReCaptchagrecaptcha