MultiForm Anti-Spam Image CAPTCHA for Contact Form 7, WPForms and Formidable Forms by Plugin Brewery (DSGVO/GDPR) Security & Risk Analysis

wordpress.org/plugins/multiform-anti-spam-image-captcha

Add a GDPR-ready image CAPTCHA and honeypot to Contact Form 7, WPForms, and Formidable Forms. Fight spam!

0 active installs v1.0.2 PHP 7.4+ WP 5.0+ Updated Mar 5, 2026
captchacontact-form-7formidablespamwpforms
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is MultiForm Anti-Spam Image CAPTCHA for Contact Form 7, WPForms and Formidable Forms by Plugin Brewery (DSGVO/GDPR) Safe to Use in 2026?

Generally Safe

Score 100/100

MultiForm Anti-Spam Image CAPTCHA for Contact Form 7, WPForms and Formidable Forms by Plugin Brewery (DSGVO/GDPR) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 28d ago
Risk Assessment

The plugin "multiform-anti-spam-image-captcha" v1.0.2 exhibits a generally strong security posture based on the static analysis. The complete lack of identified AJAX handlers, REST API routes, shortcodes, or cron events, especially those without authentication, significantly limits its attack surface. Furthermore, the code signals are mostly positive, with a high percentage of SQL queries using prepared statements and a very low rate of unescaped output. The presence of nonce and capability checks, even though limited in number, indicates some consideration for security best practices.

However, a critical concern arises from the taint analysis, which revealed one flow with unsanitized paths. While no critical or high-severity taint flows were found, this single unsanitized path represents a potential avenue for exploitation if user-supplied input is not properly validated or escaped before being used in file operations or other sensitive contexts. The absence of any recorded vulnerabilities in its history is a positive indicator, suggesting the developers have a good track record. Nonetheless, the presence of an unsanitized path, even in a limited context, warrants attention and a cautious approach.

In conclusion, the plugin demonstrates good coding practices in many areas, particularly in minimizing its attack surface and utilizing prepared statements. The lack of historical vulnerabilities is a significant strength. The primary weakness identified is the single unsanitized path from the taint analysis, which, despite not leading to critical or high severity findings in this analysis, presents a tangible risk that should be addressed.

Key Concerns

  • Flows with unsanitized paths
Vulnerabilities
None known

MultiForm Anti-Spam Image CAPTCHA for Contact Form 7, WPForms and Formidable Forms by Plugin Brewery (DSGVO/GDPR) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

MultiForm Anti-Spam Image CAPTCHA for Contact Form 7, WPForms and Formidable Forms by Plugin Brewery (DSGVO/GDPR) Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
4 prepared
Unescaped Output
2
30 escaped
Nonce Checks
1
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

80% prepared5 total queries

Output Escaping

94% escaped32 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
render_admin_page (includes\class-admin.php:91)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

MultiForm Anti-Spam Image CAPTCHA for Contact Form 7, WPForms and Formidable Forms by Plugin Brewery (DSGVO/GDPR) Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 14
actionadmin_menuincludes\class-admin.php:25
actioninitincludes\class-assets.php:14
actionadmin_enqueue_scriptsincludes\class-assets.php:15
actionadmin_initincludes\class-plugin.php:40
actionadmin_noticesincludes\class-plugin.php:106
actionwpcf7_initincludes\modules\class-contact-form-7.php:14
actionwpcf7_admin_initincludes\modules\class-contact-form-7.php:15
actioninitincludes\modules\class-contact-form-7.php:16
filterwpcf7_validateincludes\modules\class-contact-form-7.php:58
filterfrm_validate_entryincludes\modules\class-formidable.php:15
actioninitincludes\modules\class-wpforms.php:18
actionwpforms_loadedincludes\modules\class-wpforms.php:28
actioninitmultiform-anti-spam-image-captcha.php:35
actionwpmu_new_blogmultiform-anti-spam-image-captcha.php:40
Maintenance & Trust

MultiForm Anti-Spam Image CAPTCHA for Contact Form 7, WPForms and Formidable Forms by Plugin Brewery (DSGVO/GDPR) Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 5, 2026
PHP min version7.4
Downloads289

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

MultiForm Anti-Spam Image CAPTCHA for Contact Form 7, WPForms and Formidable Forms by Plugin Brewery (DSGVO/GDPR) Developer Profile

Plugin Brewery

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect MultiForm Anti-Spam Image CAPTCHA for Contact Form 7, WPForms and Formidable Forms by Plugin Brewery (DSGVO/GDPR)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/multiform-anti-spam-image-captcha/css/fontawesome.css/wp-content/plugins/multiform-anti-spam-image-captcha/css/front-end-style.css/wp-content/plugins/multiform-anti-spam-image-captcha/js/front-end.js/wp-content/plugins/multiform-anti-spam-image-captcha/css/admin-style.css
Script Paths
/wp-content/plugins/multiform-anti-spam-image-captcha/js/front-end.js
Version Parameters
/wp-content/plugins/multiform-anti-spam-image-captcha/css/fontawesome.css?ver=8.0/wp-content/plugins/multiform-anti-spam-image-captcha/css/front-end-style.css?ver=1.3.1/wp-content/plugins/multiform-anti-spam-image-captcha/js/front-end.js?ver=1.3.1/wp-content/plugins/multiform-anti-spam-image-captcha/css/admin-style.css?ver=1.0.0

HTML / DOM Fingerprints

CSS Classes
pbmfasic-style1pbmfasic_instructionspbmfasic-icon-wrapperpbmfasic-sr-fspbmfasic-sr-lepbmfasic-fields
Data Attributes
name="pbmfasic_captcha"name="pbmfasic_exists"name="pbmfasic_key"name="pbmfasic_hp"
Shortcode Output
[pbmfasic][pbmfasic_demo]
FAQ

Frequently Asked Questions about MultiForm Anti-Spam Image CAPTCHA for Contact Form 7, WPForms and Formidable Forms by Plugin Brewery (DSGVO/GDPR)