
Script Filter for Contact Form 7 Google reCAPTCHA Security & Risk Analysis
wordpress.org/plugins/script-filter-for-contact-form-7-google-recaptchaLoad Google reCAPTCHA v3 script only in those pages where Contact Form 7 shortcode exists.
Is Script Filter for Contact Form 7 Google reCAPTCHA Safe to Use in 2026?
Generally Safe
Score 85/100Script Filter for Contact Form 7 Google reCAPTCHA has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "script-filter-for-contact-form-7-google-recaptcha" v1.0.0 demonstrates a strong security posture based on the provided static analysis. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the potential attack surface. Furthermore, the code signals indicate a good development practice with all SQL queries utilizing prepared statements and a lack of dangerous functions or file operations. The presence of a capability check also suggests some level of authorization is considered.
Taint analysis shows no identified flows with unsanitized paths, which is a positive indicator of secure coding. The vulnerability history being completely clear of any CVEs, regardless of severity, further strengthens the perceived security of this version. However, the fact that only 50% of outputs are properly escaped presents a minor concern, as unescaped output can potentially lead to cross-site scripting (XSS) vulnerabilities if the data originates from untrusted sources. While no critical issues were flagged, this area warrants attention.
In conclusion, this plugin appears to be developed with security in mind, exhibiting a small attack surface and robust data handling for SQL. The lack of historical vulnerabilities is a significant strength. The only notable weakness is the incomplete output escaping, which, while not critical in this analysis, should be addressed in future development to ensure a completely secure product. Overall, the plugin is in a good security state with a minor area for improvement.
Key Concerns
- Outputs not properly escaped
Script Filter for Contact Form 7 Google reCAPTCHA Security Vulnerabilities
Script Filter for Contact Form 7 Google reCAPTCHA Code Analysis
Output Escaping
Script Filter for Contact Form 7 Google reCAPTCHA Attack Surface
WordPress Hooks 7
Maintenance & Trust
Script Filter for Contact Form 7 Google reCAPTCHA Maintenance & Trust
Maintenance Signals
Community Trust
Script Filter for Contact Form 7 Google reCAPTCHA Alternatives
ReCaptcha v2 for Contact Form 7
wpcf7-recaptcha
Adds reCaptcha v2 from Contact Form 7 5.0.5 that was dropped on Contact Form 7 5.1
Contact Form 7 Captcha
contact-form-7-simple-recaptcha
Protect your Contact Form 7 forms with Google reCAPTCHA V2, Google reCAPTCHA V3, hCAPTCHA, or Cloudflare Turnstile.
Invisible reCaptcha for WordPress
invisible-recaptcha
Invisible reCaptcha for WordPress plugin helps you to protect your sites against bad spam bots using the new Invisible reCaptcha by Google.
Business Essentials for Contact Form 7
cf7-redirect-thank-you-page
Business Essentials for Contact Form 7
CF7 Invisible reCAPTCHA
cf7-invisible-recaptcha
CF7 Invisible reCAPTCHA plugin is an effective solution that secures your Contact form 7 forms on WordPress websites from spam entries while letting h …
Script Filter for Contact Form 7 Google reCAPTCHA Developer Profile
2 plugins · 0 total installs
How We Detect Script Filter for Contact Form 7 Google reCAPTCHA
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
sfcf7-class<label>Google reCAPTCHA script will only be loaded in pages and posts where [