
reCAPTCHA Login Security & Risk Analysis
wordpress.org/plugins/recaptcha-loginAdd reCAPTCHA to your WordPress login form
Is reCAPTCHA Login Safe to Use in 2026?
Generally Safe
Score 85/100reCAPTCHA Login has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "recaptcha-login" plugin v1.0 exhibits a generally positive security posture with no known vulnerabilities or CVEs recorded. The absence of an attack surface, dangerous functions, and external HTTP requests are strong indicators of good security practices. However, the static analysis reveals some concerning areas. Specifically, the low percentage of properly escaped output (24%) suggests a risk of Cross-Site Scripting (XSS) vulnerabilities, especially since there are 33 total outputs analyzed. Furthermore, the presence of two unsanitized paths in the taint analysis, even without critical or high severity, indicates potential vulnerabilities in file handling or path manipulation, which could be exploited in conjunction with other weaknesses. The plugin also has no explicit nonce checks, which, combined with the lack of a defined attack surface, might indicate it's not designed for highly interactive or sensitive operations, or that these checks are implicitly handled elsewhere (though this is less likely to be a secure default).
Key Concerns
- Low percentage of properly escaped output
- Taint flows with unsanitized paths found
- No nonce checks implemented
reCAPTCHA Login Security Vulnerabilities
reCAPTCHA Login Code Analysis
Output Escaping
Data Flow Analysis
reCAPTCHA Login Attack Surface
WordPress Hooks 7
Maintenance & Trust
reCAPTCHA Login Maintenance & Trust
Maintenance Signals
Community Trust
reCAPTCHA Login Alternatives
Hostvn Admin Optimize
hostvn-admin-optimize
Hostvn Admin Optimize
Login With Google reCaptcha For WordPress And Woocomerce
evg-google-recaptcha
Extended WordPress\Woocomerce Login With Google reCaptcha and hiding user/password errors
Advanced Google reCAPTCHA
advanced-google-recaptcha
Captcha protection against spam comments & brute force login attacks using Google reCAPTCHA.
Captcha Code
captcha-code-authentication
GDPR compatible captcha anti-spam protection for login form, comments form, registration form & lost password form. Eliminate spam with captcha.
Login No Captcha reCAPTCHA
login-recaptcha
Adds a Google No Captcha ReCaptcha checkbox to your Wordpress and Woocommerce login, forgot password, and user registration pages.
reCAPTCHA Login Developer Profile
4 plugins · 100 total installs
How We Detect reCAPTCHA Login
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/recaptcha-login/recaptcha-fluid.cssHTML / DOM Fingerprints
recaptchalogin_otherlinksavatar_containerlogin_erroradd admin settingsInit widget/styles/scriptsTo add more extend i.e when terms came from themes - suggested by dev.xiligroup.comUser is logged in+3 moredata-recaptcha-tokenRecaptchaOptions