Recapture for Restrict Content Pro Security & Risk Analysis

wordpress.org/plugins/recapture-for-restrict-content-pro

Recapture is the easiest and most effective way to recover abandoned carts and do email marketing for your Restrict Content Pro site in WordPress.

20 active installs v1.0.21 PHP 5.6+ WP 6.2+ Updated Dec 3, 2025
cart-abandonmentemail-marketingmembership-pluginsrestrict-content-protags-abandoned-carts
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Recapture for Restrict Content Pro Safe to Use in 2026?

Generally Safe

Score 100/100

Recapture for Restrict Content Pro has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The "recapture-for-restrict-content-pro" plugin, version 1.0.21, exhibits a mixed security posture. While it demonstrates strong practices in database interaction with 100% prepared statements and generally good output escaping (96%), the significant attack surface of five AJAX handlers, all lacking authentication checks, is a major concern. This means any unauthenticated user could potentially interact with these handlers, opening up possibilities for various attacks if those handlers perform sensitive operations or expose information. The absence of any recorded CVEs and the lack of critical or high severity taint flows are positive indicators, suggesting a history of relatively secure code. However, the large number of unprotected entry points is a significant weakness that outweighs the other strengths, creating a notable risk.

Key Concerns

  • Unprotected AJAX handlers
  • High number of unprotected entry points
  • Minor output escaping concern
Vulnerabilities
None known

Recapture for Restrict Content Pro Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Recapture for Restrict Content Pro Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
132 escaped
Nonce Checks
3
Capability Checks
1
File Operations
1
External Requests
2
Bundled Libraries
0

Output Escaping

96% escaped137 total outputs
Attack Surface
5 unprotected

Recapture for Restrict Content Pro Attack Surface

Entry Points5
Unprotected5

AJAX Handlers 5

authwp_ajax_recapture_get_level_detailsplatforms\class-rcp.php:13
noprivwp_ajax_recapture_get_level_detailsplatforms\class-rcp.php:14
authwp_ajax_recapture_connection_statusrecapture.php:73
authwp_ajax_recapture_submit_reviewsrecapture.php:76
noprivwp_ajax_recapture_submit_reviewsrecapture.php:77
WordPress Hooks 35
actionedd_post_add_to_cartplatforms\class-edd.php:21
actionedd_post_remove_from_cartplatforms\class-edd.php:22
actionedd_complete_purchaseplatforms\class-edd.php:23
actionwpplatforms\class-edd.php:24
actionedd_straight_to_gateway_purchase_dataplatforms\class-edd.php:26
actionrcp_transition_membership_statusplatforms\class-rcp.php:9
actionrcp_membership_post_renewplatforms\class-rcp.php:10
actionrcp_after_register_form_fieldsplatforms\class-rcp.php:11
actionrecapture_run_exportplatforms\class-rcp.php:12
actionadmin_noticesplatforms\class-rcp.php:17
actionwpplatforms\class-rcp.php:20
actionwoocommerce_order_status_changedplatforms\class-woocommerce.php:10
actionwoocommerce_checkout_order_processedplatforms\class-woocommerce.php:12
actionadmin_initrecapture.php:47
actionadmin_noticesrecapture.php:48
actioninitrecapture.php:57
actioninitrecapture.php:58
actioninitrecapture.php:59
actioninitrecapture.php:60
actioninitrecapture.php:61
actionadmin_enqueue_scriptsrecapture.php:62
actionwp_enqueue_scriptsrecapture.php:63
actioninitrecapture.php:66
actionwp_loadedrecapture.php:67
actionwp_loadedrecapture.php:68
actionadmin_noticesrecapture.php:69
actionadmin_menurecapture.php:70
actionadmin_post_recapture_disconnectrecapture.php:80
actionadmin_post_recapture_connectrecapture.php:83
actionadmin_post_recapture_confirm_disconnectrecapture.php:86
actionadmin_post_recapture_export_membersrecapture.php:90
filterallowed_redirect_hostsrecapture.php:93
actionadmin_initrecapture.php:405
actionplugins_loadedrecapture.php:779
actionactivated_pluginrecapture.php:789

Scheduled Events 2

recapture_run_export
recapture_run_export
Maintenance & Trust

Recapture for Restrict Content Pro Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 3, 2025
PHP min version5.6
Downloads4K

Community Trust

Rating100/100
Number of ratings1
Active installs20
Developer Profile

Recapture for Restrict Content Pro Developer Profile

Recapture Cart Recovery and Email Marketing

3 plugins · 1K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
8 days
View full developer profile
Detection Fingerprints

How We Detect Recapture for Restrict Content Pro

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/recapture-for-restrict-content-pro/css/reviews.css/wp-content/plugins/recapture-for-restrict-content-pro/js/reviews.js
Script Paths
https://loader.recapture.io/v1/loader.min.js
Version Parameters
recapture-for-restrict-content-pro/css/reviews.css?ver=recapture-for-restrict-content-pro/js/reviews.js?ver=

HTML / DOM Fingerprints

CSS Classes
recapture-review-widget
HTML Comments
Ignoring wpecs warning because we receive this URL from Recaptureso we can't add/check a nonce
Data Attributes
data-recapture-order-hashdata-recapture-order-iddata-recapture-api-key
JS Globals
window.rawindow.ra.q___recapture
FAQ

Frequently Asked Questions about Recapture for Restrict Content Pro