Samurai Honeypot for Forms Security & Risk Analysis

wordpress.org/plugins/samurai-honeypot-for-forms

Invisible 15-layer anti-spam for Contact Form 7 & WPForms. Score-based 3-Tier Triage silently blocks bots — no CAPTCHA, no user friction.

0 active installs v1.1.5 PHP 7.4+ WP 5.9+ Updated Mar 3, 2026
antispamcontact-form-7honeypotspamwpforms
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Samurai Honeypot for Forms Safe to Use in 2026?

Generally Safe

Score 100/100

Samurai Honeypot for Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "samurai-honeypot-for-forms" plugin version 1.1.5 demonstrates a generally good security posture based on the provided static analysis. The plugin exhibits strong adherence to secure coding practices, with 100% of its SQL queries utilizing prepared statements and all output being properly escaped. Furthermore, there are no recorded historical vulnerabilities (CVEs), which suggests a history of stable and secure development. The absence of dangerous functions, file operations, and the presence of nonce and capability checks on its entry points are all positive indicators. However, the taint analysis reveals two flows with unsanitized paths, classified as high severity. While the plugin has a small attack surface and all identified entry points have authentication checks, these two unsanitized paths represent a potential risk that needs to be addressed. This indicates a weakness in how external or user-supplied data is handled within these specific code flows, which could be exploited if an attacker can control the input leading to these paths. Therefore, while the overall security practices are commendable, these two high-severity taint flows are a significant concern that elevates the risk profile.

Key Concerns

  • High severity unsanitized taint flows
Vulnerabilities
None known

Samurai Honeypot for Forms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Samurai Honeypot for Forms Release Timeline

v1.1.5Current
v1.1.4
v1.1.3
v1.1.2
v1.1.1
v1.1.0
v1.0.0
Code Analysis
Analyzed Apr 16, 2026

Samurai Honeypot for Forms Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
16 prepared
Unescaped Output
0
157 escaped
Nonce Checks
3
Capability Checks
6
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

100% prepared16 total queries

Output Escaping

100% escaped157 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
prepare_items (includes/class-samhp-quarantine-list-table.php:68)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Samurai Honeypot for Forms Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_samhp_dismiss_donationincludes/class-samhp-core.php:197
WordPress Hooks 17
actionrest_api_initincludes/class-samhp-core.php:188
actionwp_enqueue_scriptsincludes/class-samhp-core.php:189
actionadmin_menuincludes/class-samhp-core.php:192
actionadmin_initincludes/class-samhp-core.php:193
actionadmin_post_samhp_regen_saltincludes/class-samhp-core.php:194
actionadmin_enqueue_scriptsincludes/class-samhp-core.php:195
actionadmin_noticesincludes/class-samhp-core.php:196
actionadmin_initsamurai-honeypot-for-forms.php:28
actionsamhp_hourly_cleanupsamurai-honeypot-for-forms.php:112
actioninitsamurai-honeypot-for-forms.php:119
actionplugins_loadedsamurai-honeypot-for-forms.php:133
filterwpcf7_skip_mailsamurai-honeypot-for-forms.php:170
filterwpcf7_flamingo_submit_ifsamurai-honeypot-for-forms.php:206
actionplugins_loadedsamurai-honeypot-for-forms.php:226
actionwpforms_processsamurai-honeypot-for-forms.php:279
filterwpforms_entry_emailsamurai-honeypot-for-forms.php:310
actionwpforms_process_entry_savesamurai-honeypot-for-forms.php:314

Scheduled Events 2

samhp_hourly_cleanup
samhp_hourly_cleanup
Maintenance & Trust

Samurai Honeypot for Forms Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 3, 2026
PHP min version7.4
Downloads380

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Samurai Honeypot for Forms Developer Profile

Team beta version

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Samurai Honeypot for Forms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/samurai-honeypot-for-forms/assets/css/samurai-honeypot-for-forms.css/wp-content/plugins/samurai-honeypot-for-forms/assets/js/samurai-honeypot-for-forms.js/wp-content/plugins/samurai-honeypot-for-forms/assets/js/samurai-honeypot-for-forms-frontend.js
Script Paths
/wp-content/plugins/samurai-honeypot-for-forms/assets/js/samurai-honeypot-for-forms.js/wp-content/plugins/samurai-honeypot-for-forms/assets/js/samurai-honeypot-for-forms-frontend.js
Version Parameters
/wp-content/plugins/samurai-honeypot-for-forms/assets/css/samurai-honeypot-for-forms.css?ver=/wp-content/plugins/samurai-honeypot-for-forms/assets/js/samurai-honeypot-for-forms.js?ver=/wp-content/plugins/samurai-honeypot-for-forms/assets/js/samurai-honeypot-for-forms-frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
samurai-honeypot-form-wrapper
HTML Comments
<!-- Samurai Honeypot for Forms -->
Data Attributes
data-samhp-form-iddata-samhp-nonce
JS Globals
samuraiHoneypotFrontend
FAQ

Frequently Asked Questions about Samurai Honeypot for Forms