Text Captcha For Contact Form 7 [GWE] Security & Risk Analysis

wordpress.org/plugins/text-captcha-for-contact-form-7

Adds a text captcha to Contact Form 7

10 active installs v1.0.3 PHP 7.0+ WP 4.7+ Updated Dec 3, 2023
captchacontact-form-7recaptchaspam-protectiontext-captcha
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Text Captcha For Contact Form 7 [GWE] Safe to Use in 2026?

Generally Safe

Score 85/100

Text Captcha For Contact Form 7 [GWE] has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The 'text-captcha-for-contact-form-7' plugin version 1.0.3 exhibits a strong security posture based on the provided static analysis. The absence of identified dangerous functions, SQL queries not using prepared statements, proper output escaping, file operations, external HTTP requests, and taint analysis flows all indicate that the code has been written with security best practices in mind. Furthermore, the plugin has no recorded vulnerabilities (CVEs) and no history of past security issues, which is a very positive sign. The limited attack surface, with zero AJAX handlers, REST API routes, shortcodes, or cron events, also significantly reduces the potential for exploitation.

While the code analysis is very reassuring, the complete lack of nonce checks and capability checks is a potential area of concern. Although the current attack surface is zero, if functionality were to be added in the future that exposed these entry points, the absence of these security measures could become a critical vulnerability. The current version appears secure due to its limited exposure, but this could change if the plugin evolves. Overall, this plugin is currently a low-risk addition to a WordPress site due to its clean code and lack of vulnerability history, but the absence of fundamental security checks warrants attention for future development.

Key Concerns

  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Text Captcha For Contact Form 7 [GWE] Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Text Captcha For Contact Form 7 [GWE] Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped3 total outputs
Attack Surface

Text Captcha For Contact Form 7 [GWE] Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionplugins_loadedcontact-form-7-text-captcha.php:36
actionwp_enqueue_scriptscontact-form-7-text-captcha.php:37
actionwp_enqueue_scriptscontact-form-7-text-captcha.php:38
actionwpcf7_initcontact-form-7-text-captcha.php:58
actionwpcf7_admin_initcontact-form-7-text-captcha.php:79
actionadmin_menucontact-form-7-text-captcha.php:103
actionadmin_initcontact-form-7-text-captcha.php:104
actionadmin_initcontact-form-7-text-captcha.php:105
Maintenance & Trust

Text Captcha For Contact Form 7 [GWE] Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedDec 3, 2023
PHP min version7.0
Downloads1K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Text Captcha For Contact Form 7 [GWE] Developer Profile

Mukul Hossain

4 plugins · 150 total installs

90
trust score
Avg Security Score
94/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Text Captcha For Contact Form 7 [GWE]

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/text-captcha-for-contact-form-7/assets/public/css/cf7tcmain.css/wp-content/plugins/text-captcha-for-contact-form-7/assets/public/js/cf7tcmain.js
Script Paths
/wp-content/plugins/text-captcha-for-contact-form-7/assets/public/js/cf7tcmain.js
Version Parameters
cf7tcmain.css?ver=cf7tcmain.js?ver=

HTML / DOM Fingerprints

CSS Classes
cf7tc_containernoticecf7tccf7tc_setting_form_field
Data Attributes
cf7tc
Shortcode Output
<div class="cf7tc_container"><p class="noticecf7tc"><span id="firstNumber"></span> +<span id="secondNumber"></span> =
FAQ

Frequently Asked Questions about Text Captcha For Contact Form 7 [GWE]