reCaptcha by WebDesignBy Security & Risk Analysis

wordpress.org/plugins/webdesignby-recaptcha

Add Google’s simple checkbox reCAPTCHA to WordPress wp-admin login page.

200 active installs v1.7 PHP + WP 3.0.1+ Updated Mar 26, 2026
captchare-captcharecaptchasecuritywp-admin
99
A · Safe
CVEs total1
Unpatched0
Last CVEApr 24, 2026
Safety Verdict

Is reCaptcha by WebDesignBy Safe to Use in 2026?

Generally Safe

Score 99/100

reCaptcha by WebDesignBy has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Apr 24, 2026Updated 1mo ago
Risk Assessment

The plugin "webdesignby-recaptcha" v1.7 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of any detected dangerous functions, SQL injection vulnerabilities through prepared statements, and a clean vulnerability history are significant strengths. Furthermore, the limited attack surface with zero entry points without authentication checks is highly commendable. However, a concerning area lies in output escaping, where only 8% of outputs are properly escaped, indicating a potential for cross-site scripting (XSS) vulnerabilities. The presence of one external HTTP request without specific details raises a minor flag, as it could be a vector for certain types of attacks if not handled securely on the server-side. The single nonce check is a positive sign, but its absence on other potential interaction points could be a weakness if such points existed. Overall, while the plugin avoids common critical vulnerabilities, the insufficient output escaping is a notable concern that requires immediate attention to mitigate XSS risks.

Key Concerns

  • Insufficient output escaping
  • External HTTP request without details
Vulnerabilities
1 published

reCaptcha by WebDesignBy Security Vulnerabilities

CVEs by Year

1 CVE in 2026
2026
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2026-4512medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

reCaptcha by WebDesignBy < 2.0 - Authenticated (Administrator+) Stored Cross-Site Scripting

Apr 24, 2026 Patched in 2.0 (7d)
Version History

reCaptcha by WebDesignBy Release Timeline

v2.0
v1.7Current1 CVE
v1.61 CVE
Code Analysis
Analyzed Mar 16, 2026

reCaptcha by WebDesignBy Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
11
1 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

8% escaped12 total outputs
Attack Surface

reCaptcha by WebDesignBy Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
filterlogin_messageclass\Recaptcha.php:38
actionadmin_enqueue_scriptsclass\Recaptcha.php:41
actionadmin_menuclass\Recaptcha.php:42
Maintenance & Trust

reCaptcha by WebDesignBy Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 26, 2026
PHP min version
Downloads6K

Community Trust

Rating100/100
Number of ratings2
Active installs200
Developer Profile

reCaptcha by WebDesignBy Developer Profile

webdesignby

1 plugin · 200 total installs

99
trust score
Avg Security Score
99/100
Avg Patch Time
7 days
View full developer profile
Detection Fingerprints

How We Detect reCaptcha by WebDesignBy

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/webdesignby-recaptcha/css/recaptcha.css/wp-content/plugins/webdesignby-recaptcha/js/recaptcha.js
Script Paths
/wp-content/plugins/webdesignby-recaptcha/js/recaptcha.js
Version Parameters
webdesignby-recaptcha/css/recaptcha.css?ver=webdesignby-recaptcha/js/recaptcha.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about reCaptcha by WebDesignBy