Users Ultra Pro reCaptcha 3.0 Add-on Security & Risk Analysis

wordpress.org/plugins/users-ultra-pro-recaptcha

This is a free add-on for Users Ultra Pro 3.0 Plugin.

10 active installs v1.0.1 PHP + WP 3.0.1+ Updated Dec 18, 2020
members-registrationrecaptchaspam-control
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Users Ultra Pro reCaptcha 3.0 Add-on Safe to Use in 2026?

Generally Safe

Score 85/100

Users Ultra Pro reCaptcha 3.0 Add-on has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The 'users-ultra-pro-recaptcha' plugin, version 1.0.1, exhibits a generally strong security posture based on the provided static analysis. The plugin reports zero AJAX handlers, REST API routes, shortcodes, or cron events, indicating a very small attack surface. Furthermore, the absence of dangerous functions, raw SQL queries, file operations, and known CVEs suggests a robust development approach. The plugin also utilizes prepared statements for all its SQL queries.

However, there are significant concerns related to output escaping and the lack of fundamental security checks. Specifically, 100% of the identified output points are not properly escaped, posing a risk of Cross-Site Scripting (XSS) vulnerabilities. Additionally, the absence of nonce checks and capability checks on any potential entry points, although the analysis shows zero entry points, is a critical oversight. The presence of an external HTTP request without any context on its security implications also warrants attention. The plugin's vulnerability history being clean is a positive sign, but the identified code analysis issues could lead to severe vulnerabilities if not addressed.

In conclusion, while the plugin benefits from a small attack surface and good database practices, the critical lack of output escaping and the absence of essential security checks like nonces and capability checks present significant risks. The single external HTTP request also introduces an unknown factor. Addressing the output escaping and implementing proper authentication/authorization mechanisms for any future or existing functionalities is paramount to improving its security.

Key Concerns

  • Unescaped output detected
  • Missing nonce checks
  • Missing capability checks
  • External HTTP request without context
Vulnerabilities
None known

Users Ultra Pro reCaptcha 3.0 Add-on Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Users Ultra Pro reCaptcha 3.0 Add-on Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

0% escaped3 total outputs
Attack Surface

Users Ultra Pro reCaptcha 3.0 Add-on Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionwp_enqueue_scriptsclasses\recaptcha.class.php:15
actionadmin_enqueue_scriptsclasses\recaptcha.class.php:16
actionadmin_menuclasses\recaptcha.class.php:17
actionadmin_initclasses\recaptcha.class.php:18
Maintenance & Trust

Users Ultra Pro reCaptcha 3.0 Add-on Maintenance & Trust

Maintenance Signals

WordPress version tested5.6.17
Last updatedDec 18, 2020
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Users Ultra Pro reCaptcha 3.0 Add-on Developer Profile

ExpressTech Systems

21 plugins · 122K total installs

75
trust score
Avg Security Score
94/100
Avg Patch Time
560 days
View full developer profile
Detection Fingerprints

How We Detect Users Ultra Pro reCaptcha 3.0 Add-on

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/users-ultra-pro-recaptcha/admin/scripts/admin.js/wp-content/plugins/users-ultra-pro-recaptcha/admin/css/admin.css/wp-content/plugins/users-ultra-pro-recaptcha/admin/tabs/
Script Paths
https://www.google.com/recaptcha/api.js
Version Parameters
users-ultra-pro-recaptcha/index.php?ver=users-ultra-pro-recaptcha/admin/scripts/admin.js?ver=users-ultra-pro-recaptcha/admin/css/admin.css?ver=

HTML / DOM Fingerprints

CSS Classes
users-ultra-pro-recaptcha-adming-recaptcha
Data Attributes
data-sitekey
Shortcode Output
<div class="g-recaptcha" data-sitekey="
FAQ

Frequently Asked Questions about Users Ultra Pro reCaptcha 3.0 Add-on