
WP Login Image Captcha Security & Risk Analysis
wordpress.org/plugins/wp-login-image-captchaAdds an image captcha and honeypot to the WordPress login page
Is WP Login Image Captcha Safe to Use in 2026?
Generally Safe
Score 85/100WP Login Image Captcha has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-login-image-captcha" v1.2 plugin exhibits a generally secure posture based on the provided static analysis. It avoids dangerous functions, uses prepared statements for all SQL queries, and has no recorded vulnerabilities or CVEs. This suggests a diligent development approach regarding common security pitfalls.
However, a significant concern arises from the output escaping analysis. With 0% of the 4 identified output points being properly escaped, this plugin presents a risk of Cross-Site Scripting (XSS) vulnerabilities. If any user-supplied data or dynamic content is outputted without proper sanitization, an attacker could inject malicious scripts. Additionally, the absence of nonce checks and capability checks, while potentially acceptable given the limited attack surface of 1 shortcode, is a notable deviation from best practices for handling user interactions and access control. While no taint flows were identified, the lack of proper output escaping makes the plugin susceptible if data flows are introduced in future versions or if the current outputs are not strictly static.
In conclusion, the plugin's lack of critical vulnerabilities and adherence to secure SQL practices are strengths. Nevertheless, the critical deficiency in output escaping and the absence of nonce/capability checks introduce a clear risk of XSS and potential privilege escalation or unauthorized actions, respectively. Addressing the output escaping is paramount to improving the plugin's security.
Key Concerns
- All output points are unescaped
- No nonce checks implemented
- No capability checks implemented
WP Login Image Captcha Security Vulnerabilities
WP Login Image Captcha Code Analysis
Output Escaping
WP Login Image Captcha Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
WP Login Image Captcha Maintenance & Trust
Maintenance Signals
Community Trust
WP Login Image Captcha Alternatives
BotBlocker Security – Firewall & Bot Protection
botblocker-security
Protect your WordPress site: firewall, bot & brute-force protection, anti-spam, multi-layer CAPTCHA, optional cloud threat intel.
Kaya Login Captcha
kaya-login-captcha
Adds a simple captcha on login form, register form and lost-password form.
Web-Art Login Shield with reCAPTCHA
webart-login-shield-recaptcha
Protect WordPress logins and Elementor Login/Forms using Google reCAPTCHA v2 and optional IP-based lockouts.
Admintosh – WordPress admin customization and security tools
admintosh
login attempts, Firewall, reCAPTCHA, country restriction, Login History, change wp-login.php to anything make sure your site security.
Protect Ai Login
protect-ai-login
Change default login site to a custom URL, block spam, bot registration, and brute-force using Google reCAPTCHA.
WP Login Image Captcha Developer Profile
6 plugins · 121K total installs
How We Detect WP Login Image Captcha
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-login-image-captcha/style.csswp-login-image-captcha/style.css?ver=1.1.0HTML / DOM Fingerprints
captcha-imagename="kc_captcha"value="kc_human"value="bot"name="kc_honeypot"name="FormType"name="wplicic_exists"<div class="captcha-image"><input type="radio" name="kc_captcha"<i class="fa<input type="text" name="kc_honeypot">