
MultiForm Anti-Spam Image CAPTCHA for Contact Form 7, WPForms and Formidable Forms by Plugin Brewery (DSGVO/GDPR) Security & Risk Analysis
wordpress.org/plugins/multiform-anti-spam-image-captchaAdd a GDPR-ready image CAPTCHA and honeypot to Contact Form 7, WPForms, and Formidable Forms. Fight spam!
Is MultiForm Anti-Spam Image CAPTCHA for Contact Form 7, WPForms and Formidable Forms by Plugin Brewery (DSGVO/GDPR) Safe to Use in 2026?
Generally Safe
Score 100/100MultiForm Anti-Spam Image CAPTCHA for Contact Form 7, WPForms and Formidable Forms by Plugin Brewery (DSGVO/GDPR) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "multiform-anti-spam-image-captcha" v1.0.2 exhibits a generally strong security posture based on the static analysis. The complete lack of identified AJAX handlers, REST API routes, shortcodes, or cron events, especially those without authentication, significantly limits its attack surface. Furthermore, the code signals are mostly positive, with a high percentage of SQL queries using prepared statements and a very low rate of unescaped output. The presence of nonce and capability checks, even though limited in number, indicates some consideration for security best practices.
However, a critical concern arises from the taint analysis, which revealed one flow with unsanitized paths. While no critical or high-severity taint flows were found, this single unsanitized path represents a potential avenue for exploitation if user-supplied input is not properly validated or escaped before being used in file operations or other sensitive contexts. The absence of any recorded vulnerabilities in its history is a positive indicator, suggesting the developers have a good track record. Nonetheless, the presence of an unsanitized path, even in a limited context, warrants attention and a cautious approach.
In conclusion, the plugin demonstrates good coding practices in many areas, particularly in minimizing its attack surface and utilizing prepared statements. The lack of historical vulnerabilities is a significant strength. The primary weakness identified is the single unsanitized path from the taint analysis, which, despite not leading to critical or high severity findings in this analysis, presents a tangible risk that should be addressed.
Key Concerns
- Flows with unsanitized paths
MultiForm Anti-Spam Image CAPTCHA for Contact Form 7, WPForms and Formidable Forms by Plugin Brewery (DSGVO/GDPR) Security Vulnerabilities
MultiForm Anti-Spam Image CAPTCHA for Contact Form 7, WPForms and Formidable Forms by Plugin Brewery (DSGVO/GDPR) Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
MultiForm Anti-Spam Image CAPTCHA for Contact Form 7, WPForms and Formidable Forms by Plugin Brewery (DSGVO/GDPR) Attack Surface
WordPress Hooks 14
Maintenance & Trust
MultiForm Anti-Spam Image CAPTCHA for Contact Form 7, WPForms and Formidable Forms by Plugin Brewery (DSGVO/GDPR) Maintenance & Trust
Maintenance Signals
Community Trust
MultiForm Anti-Spam Image CAPTCHA for Contact Form 7, WPForms and Formidable Forms by Plugin Brewery (DSGVO/GDPR) Alternatives
Image CAPTCHA for Contact Form 7 and WPForms by HookAndHook (DSGVO/GDPR)
contact-form-7-image-captcha
Adds an Image CAPTCHA to Contact Form 7 and WPForms, GDPR ready, perfect WPForms or Contact Form 7 Spam Protection Image CAPTCHA, adds a honeypot
ReCaptcha v2 for Contact Form 7
wpcf7-recaptcha
Adds reCaptcha v2 from Contact Form 7 5.0.5 that was dropped on Contact Form 7 5.1
Contact Form 7 Captcha
contact-form-7-simple-recaptcha
Protect your Contact Form 7 forms with Google reCAPTCHA V2, Google reCAPTCHA V3, hCAPTCHA, or Cloudflare Turnstile.
SilentShield – Captcha & Anti-Spam for WordPress (CF7, WPForms, Elementor, WooCommerce)
captcha-for-contact-form-7
SilentShield – the invisible shield against spam. Spam is the weed of the internet. It clogs your forms, steals your time, and corrupts your data.
WP Advanced Math Captcha
wp-advanced-math-captcha
Protect your WordPress site with a powerful and user-friendly Math Captcha. Now with seamless WooCommerce, WPForms, and Formidable Forms integration!
MultiForm Anti-Spam Image CAPTCHA for Contact Form 7, WPForms and Formidable Forms by Plugin Brewery (DSGVO/GDPR) Developer Profile
1 plugin · 0 total installs
How We Detect MultiForm Anti-Spam Image CAPTCHA for Contact Form 7, WPForms and Formidable Forms by Plugin Brewery (DSGVO/GDPR)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/multiform-anti-spam-image-captcha/css/fontawesome.css/wp-content/plugins/multiform-anti-spam-image-captcha/css/front-end-style.css/wp-content/plugins/multiform-anti-spam-image-captcha/js/front-end.js/wp-content/plugins/multiform-anti-spam-image-captcha/css/admin-style.css/wp-content/plugins/multiform-anti-spam-image-captcha/js/front-end.js/wp-content/plugins/multiform-anti-spam-image-captcha/css/fontawesome.css?ver=8.0/wp-content/plugins/multiform-anti-spam-image-captcha/css/front-end-style.css?ver=1.3.1/wp-content/plugins/multiform-anti-spam-image-captcha/js/front-end.js?ver=1.3.1/wp-content/plugins/multiform-anti-spam-image-captcha/css/admin-style.css?ver=1.0.0HTML / DOM Fingerprints
pbmfasic-style1pbmfasic_instructionspbmfasic-icon-wrapperpbmfasic-sr-fspbmfasic-sr-lepbmfasic-fieldsname="pbmfasic_captcha"name="pbmfasic_exists"name="pbmfasic_key"name="pbmfasic_hp"[pbmfasic][pbmfasic_demo]