
TomS reCAPTCHA Security & Risk Analysis
wordpress.org/plugins/toms-recaptchaIntegrated Google ReCaptcha for WordPress.Protect the login, register, lostpassword and comment forms. Support Woocommerce, Ultimate Member and more p …
Is TomS reCAPTCHA Safe to Use in 2026?
Generally Safe
Score 85/100TomS reCAPTCHA has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'toms-recaptcha' v1.2.0 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of any recorded CVEs, particularly critical or high-severity ones, is a significant positive indicator. The code also demonstrates good practices such as proper output escaping (99%) and the presence of nonce and capability checks, which are crucial for preventing common WordPress attacks. However, there are areas that warrant attention. The presence of 3 flows with unsanitized paths in the taint analysis, while not reaching a critical or high severity in this instance, indicates potential vectors for injection or path traversal vulnerabilities. Furthermore, the use of raw SQL queries in 50% of cases is a concern, as it increases the risk of SQL injection if not handled with extreme care, especially if user-supplied data is involved.
Key Concerns
- Unsanitized paths in taint analysis
- SQL queries not using prepared statements
TomS reCAPTCHA Security Vulnerabilities
TomS reCAPTCHA Release Timeline
TomS reCAPTCHA Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
TomS reCAPTCHA Attack Surface
Shortcodes 1
WordPress Hooks 41
Maintenance & Trust
TomS reCAPTCHA Maintenance & Trust
Maintenance Signals
Community Trust
TomS reCAPTCHA Alternatives
Login No Captcha reCAPTCHA
login-recaptcha
Adds a Google No Captcha ReCaptcha checkbox to your Wordpress and Woocommerce login, forgot password, and user registration pages.
JC Recaptcha
jc-recaptcha
The Add new recaptcha google plugin allows you to implement a super security REcaptcha form into web forms.
Protect Ai Login
protect-ai-login
Change default login site to a custom URL, block spam, bot registration, and brute-force using Google reCAPTCHA.
Sargas reCAPTCHA
sargas-recaptcha
reCAPTCHA for login, signup, comment, WooCommerce, Mailchimp and other forms.
Advanced Google reCAPTCHA
advanced-google-recaptcha
Captcha protection against spam comments & brute force login attacks using Google reCAPTCHA.
TomS reCAPTCHA Developer Profile
7 plugins · 1K total installs
How We Detect TomS reCAPTCHA
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/toms-recaptcha/inc/assets/css/toms-recaptcha.cssHTML / DOM Fingerprints
toms-menu-itemtoms-recaptchatoms-menu-texttoms_recaptcha_v3_site_keytoms_recaptcha_v3_secret_keytoms_recaptcha_v2_checkbox_site_keytoms_recaptcha_v2_checkbox_secret_keytoms_recaptcha_v2_invisible_site_keytoms_recaptcha_v2_invisible_secret_key+11 more