Script Filter for Contact Form 7 Google reCAPTCHA Security & Risk Analysis

wordpress.org/plugins/script-filter-for-contact-form-7-google-recaptcha

Load Google reCAPTCHA v3 script only in those pages where Contact Form 7 shortcode exists.

0 active installs v1.0.0 PHP 7.0+ WP 4.8+ Updated Jun 25, 2021
contact-form-7recaptcha
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Script Filter for Contact Form 7 Google reCAPTCHA Safe to Use in 2026?

Generally Safe

Score 85/100

Script Filter for Contact Form 7 Google reCAPTCHA has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The plugin "script-filter-for-contact-form-7-google-recaptcha" v1.0.0 demonstrates a strong security posture based on the provided static analysis. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the potential attack surface. Furthermore, the code signals indicate a good development practice with all SQL queries utilizing prepared statements and a lack of dangerous functions or file operations. The presence of a capability check also suggests some level of authorization is considered.

Taint analysis shows no identified flows with unsanitized paths, which is a positive indicator of secure coding. The vulnerability history being completely clear of any CVEs, regardless of severity, further strengthens the perceived security of this version. However, the fact that only 50% of outputs are properly escaped presents a minor concern, as unescaped output can potentially lead to cross-site scripting (XSS) vulnerabilities if the data originates from untrusted sources. While no critical issues were flagged, this area warrants attention.

In conclusion, this plugin appears to be developed with security in mind, exhibiting a small attack surface and robust data handling for SQL. The lack of historical vulnerabilities is a significant strength. The only notable weakness is the incomplete output escaping, which, while not critical in this analysis, should be addressed in future development to ensure a completely secure product. Overall, the plugin is in a good security state with a minor area for improvement.

Key Concerns

  • Outputs not properly escaped
Vulnerabilities
None known

Script Filter for Contact Form 7 Google reCAPTCHA Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Script Filter for Contact Form 7 Google reCAPTCHA Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
1 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

50% escaped2 total outputs
Attack Surface

Script Filter for Contact Form 7 Google reCAPTCHA Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionadmin_noticesscript-filter-for-cf7-recaptcha.php:16
actionadmin_initscript-filter-for-cf7-recaptcha.php:34
filterwpcf7_load_jsscript-filter-for-cf7-recaptcha.php:43
filterwpcf7_load_cssscript-filter-for-cf7-recaptcha.php:44
actionwp_enqueue_scriptsscript-filter-for-cf7-recaptcha.php:50
actionadmin_menuscript-filter-for-cf7-recaptcha.php:72
actionadmin_initscript-filter-for-cf7-recaptcha.php:103
Maintenance & Trust

Script Filter for Contact Form 7 Google reCAPTCHA Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.15
Last updatedJun 25, 2021
PHP min version7.0
Downloads831

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

Script Filter for Contact Form 7 Google reCAPTCHA Developer Profile

Renzo Castillo

2 plugins · 0 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Script Filter for Contact Form 7 Google reCAPTCHA

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
sfcf7-class
Shortcode Output
<label>Google reCAPTCHA script will only be loaded in pages and posts where [
FAQ

Frequently Asked Questions about Script Filter for Contact Form 7 Google reCAPTCHA