
Math Captcha for Elementor Forms Security & Risk Analysis
wordpress.org/plugins/math-captcha-for-elementor-formsWordpress Plugin that will add a simple match captcha to your Elementor Forms.
Is Math Captcha for Elementor Forms Safe to Use in 2026?
Generally Safe
Score 85/100Math Captcha for Elementor Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'math-captcha-for-elementor-forms' v1.1.0 plugin exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The complete absence of dangerous functions, SQL injection vulnerabilities (all queries use prepared statements), file operations, and external HTTP requests is highly positive. Furthermore, the lack of any recorded CVEs or historical vulnerabilities suggests a stable and secure codebase.
However, a significant concern arises from the "Output escaping: 3 total outputs, 0% properly escaped" finding. This indicates that all three identified output points are vulnerable to cross-site scripting (XSS) attacks. Without proper escaping, user-supplied data displayed on the frontend could be maliciously crafted to execute arbitrary JavaScript in the user's browser, potentially leading to session hijacking, defacement, or other client-side attacks. The absence of taint analysis results is noted, but the direct finding of unescaped output is concrete evidence of risk.
In conclusion, while the plugin appears robust against common server-side attacks and has a clean vulnerability history, the lack of output escaping represents a critical weakness that must be addressed. This single vulnerability significantly undermines the otherwise positive security assessment.
Key Concerns
- Output is not properly escaped
Math Captcha for Elementor Forms Security Vulnerabilities
Math Captcha for Elementor Forms Code Analysis
Output Escaping
Math Captcha for Elementor Forms Attack Surface
WordPress Hooks 4
Maintenance & Trust
Math Captcha for Elementor Forms Maintenance & Trust
Maintenance Signals
Community Trust
Math Captcha for Elementor Forms Alternatives
Web-Art Login Shield with reCAPTCHA
webart-login-shield-recaptcha
Protect WordPress logins and Elementor Login/Forms using Google reCAPTCHA v2 and optional IP-based lockouts.
Advanced Google reCAPTCHA
advanced-google-recaptcha
Captcha protection against spam comments & brute force login attacks using Google reCAPTCHA.
ReCaptcha v2 for Contact Form 7
wpcf7-recaptcha
Adds reCaptcha v2 from Contact Form 7 5.0.5 that was dropped on Contact Form 7 5.1
CAPTCHA 4WP – Antispam CAPTCHA solution for WordPress
advanced-nocaptcha-recaptcha
Use CAPTCHA to stop spam and allow customers & users to interact with your website easily. Block fake accounts and orders. Avoid false positives.
Captcha Code
captcha-code-authentication
GDPR compatible captcha anti-spam protection for login form, comments form, registration form & lost password form. Eliminate spam with captcha.
Math Captcha for Elementor Forms Developer Profile
2 plugins · 3K total installs
How We Detect Math Captcha for Elementor Forms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/math-captcha-for-elementor-forms/assets/css/main.css/wp-content/plugins/math-captcha-for-elementor-forms/assets/js/arrive.min.js/wp-content/plugins/math-captcha-for-elementor-forms/assets/js/jquery.ebcaptcha.js/wp-content/plugins/math-captcha-for-elementor-forms/assets/js/main.js/wp-content/plugins/math-captcha-for-elementor-forms/assets/js/main.js/wp-content/plugins/math-captcha-for-elementor-forms/assets/js/jquery.ebcaptcha.js/wp-content/plugins/math-captcha-for-elementor-forms/assets/js/arrive.min.jsmath-captcha-for-elementor-forms/assets/css/main.css?ver=math-captcha-for-elementor-forms/assets/js/main.js?ver=math-captcha-for-elementor-forms/assets/js/jquery.ebcaptcha.js?ver=math-captcha-for-elementor-forms/assets/js/arrive.min.js?ver=HTML / DOM Fingerprints
bs-submit-button-eventid="bs_ebcaptchainput"bs_math_captcha_plus_signbs_math_captcha_minus_signbs_math_captcha_multiply_sign