
TomS reCAPTCHA Security & Risk Analysis
wordpress.org/plugins/toms-recaptchaIntegrated Google ReCaptcha for WordPress.Protect the login, register, lostpassword and comment forms. Support Woocommerce, Ultimate Member and more p …
Is TomS reCAPTCHA Safe to Use in 2026?
Generally Safe
Score 85/100TomS reCAPTCHA has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'toms-recaptcha' v1.2.0 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of any recorded CVEs, particularly critical or high-severity ones, is a significant positive indicator. The code also demonstrates good practices such as proper output escaping (99%) and the presence of nonce and capability checks, which are crucial for preventing common WordPress attacks. However, there are areas that warrant attention. The presence of 3 flows with unsanitized paths in the taint analysis, while not reaching a critical or high severity in this instance, indicates potential vectors for injection or path traversal vulnerabilities. Furthermore, the use of raw SQL queries in 50% of cases is a concern, as it increases the risk of SQL injection if not handled with extreme care, especially if user-supplied data is involved.
Key Concerns
- Unsanitized paths in taint analysis
- SQL queries not using prepared statements
TomS reCAPTCHA Security Vulnerabilities
TomS reCAPTCHA Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
TomS reCAPTCHA Attack Surface
Shortcodes 1
WordPress Hooks 41
Maintenance & Trust
TomS reCAPTCHA Maintenance & Trust
Maintenance Signals
Community Trust
TomS reCAPTCHA Alternatives
Login No Captcha reCAPTCHA
login-recaptcha
Adds a Google No Captcha ReCaptcha checkbox to your Wordpress and Woocommerce login, forgot password, and user registration pages.
JC Recaptcha
jc-recaptcha
The Add new recaptcha google plugin allows you to implement a super security REcaptcha form into web forms.
Protect Ai Login
protect-ai-login
Change default login site to a custom URL, block spam, bot registration, and brute-force using Google reCAPTCHA.
Sargas reCAPTCHA
sargas-recaptcha
reCAPTCHA for login, signup, comment, WooCommerce, Mailchimp and other forms.
Advanced Google reCAPTCHA
advanced-google-recaptcha
Captcha protection against spam comments & brute force login attacks using Google reCAPTCHA.
TomS reCAPTCHA Developer Profile
7 plugins · 1K total installs
How We Detect TomS reCAPTCHA
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/toms-recaptcha/inc/assets/css/toms-recaptcha.cssHTML / DOM Fingerprints
toms-menu-itemtoms-recaptchatoms-menu-texttoms_recaptcha_v3_site_keytoms_recaptcha_v3_secret_keytoms_recaptcha_v2_checkbox_site_keytoms_recaptcha_v2_checkbox_secret_keytoms_recaptcha_v2_invisible_site_keytoms_recaptcha_v2_invisible_secret_key+11 more