
ReCaptcha JS Alert Security & Risk Analysis
wordpress.org/plugins/recaptcha-js-alertReCaptcha JS Alert provides the [recaptcha-js-alert] shortcode, which (if necessary) informs visitors of your website that a form requires JavaScript …
Is ReCaptcha JS Alert Safe to Use in 2026?
Generally Safe
Score 100/100ReCaptcha JS Alert has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The recaptcha-js-alert v1.0.1 plugin exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, reliance on prepared statements for SQL queries, and 100% proper output escaping indicate good development practices. The plugin also has no recorded vulnerability history, further contributing to its seemingly secure profile.
However, the analysis reveals a critical weakness: a complete lack of nonce checks and capability checks. While the attack surface is small with only one shortcode entry point and no unprotected AJAX handlers or REST API routes, the absence of nonces means that an attacker could potentially trigger the shortcode's functionality repeatedly without proper authorization. This could lead to denial-of-service or other unintended consequences if the shortcode performs any sensitive operations. The plugin's history of no vulnerabilities is positive, but it doesn't mitigate the inherent risks presented by missing fundamental security checks.
Key Concerns
- Missing nonce checks
- Missing capability checks
ReCaptcha JS Alert Security Vulnerabilities
ReCaptcha JS Alert Code Analysis
Output Escaping
ReCaptcha JS Alert Attack Surface
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
ReCaptcha JS Alert Maintenance & Trust
Maintenance Signals
Community Trust
ReCaptcha JS Alert Alternatives
Wp Js Detect
wp-js-detect
This plugin is used to display a notification message if the browser's Javascript is disabled. Travis CI
Contact Dialog
contact-dialog
Enables display of an AJAX driven contact form when a user clicks on links with a specified class.
MailPoet – Newsletters, Email Marketing, and Automation
mailpoet
Send beautiful newsletters from WordPress. Collect subscribers with signup forms, automate your emails for WooCommerce, blog post notifications & more
Advanced Google reCAPTCHA
advanced-google-recaptcha
Captcha protection against spam comments & brute force login attacks using Google reCAPTCHA.
ReCaptcha v2 for Contact Form 7
wpcf7-recaptcha
Adds reCaptcha v2 from Contact Form 7 5.0.5 that was dropped on Contact Form 7 5.1
ReCaptcha JS Alert Developer Profile
3 plugins · 10K total installs
How We Detect ReCaptcha JS Alert
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/recaptcha-js-alert/css/recaptcha-js-alert.css/wp-content/plugins/recaptcha-js-alert/js/recaptcha-js-alert.js/wp-content/plugins/recaptcha-js-alert/js/recaptcha-js-alert-admin.jsrecaptcha-js-alert/css/recaptcha-js-alert.css?ver=recaptcha-js-alert/js/recaptcha-js-alert.js?ver=recaptcha-js-alert/js/recaptcha-js-alert-admin.js?ver=HTML / DOM Fingerprints
data-default-colordelay<span id='recaptcha_js_alert_box'