
WP reCAPTCHA Library Security & Risk Analysis
wordpress.org/plugins/wp-recaptcha-libraryProvides functions to easily display and validate a reCAPTCHA
Is WP reCAPTCHA Library Safe to Use in 2026?
Generally Safe
Score 85/100WP reCAPTCHA Library has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-recaptcha-library v1.0.2 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of identified AJAX handlers, REST API routes, shortcodes, and cron events significantly limits its attack surface, especially as none of these are found to be unprotected. The plugin also demonstrates good practice by exclusively using prepared statements for any SQL queries and has no recorded vulnerability history, suggesting a well-maintained and secure development process. However, a notable concern is the complete lack of output escaping, meaning that all four identified output points are vulnerable to cross-site scripting (XSS) attacks. Additionally, the absence of nonce and capability checks on any potential entry points, while not currently exploitable due to the limited attack surface, represents a significant weakness that could be exploited if new entry points are added in future versions without proper security measures.
Key Concerns
- Unescaped output
- Missing nonce checks
- Missing capability checks
WP reCAPTCHA Library Security Vulnerabilities
WP reCAPTCHA Library Release Timeline
WP reCAPTCHA Library Code Analysis
Output Escaping
WP reCAPTCHA Library Attack Surface
WordPress Hooks 3
Maintenance & Trust
WP reCAPTCHA Library Maintenance & Trust
Maintenance Signals
Community Trust
WP reCAPTCHA Library Alternatives
SiteGuard WP Plugin
siteguard
SiteGurad WP Plugin is the plugin specialized for the protection against the attack to the management page and login.
CF7 Apps – Honeypot, Database, Redirection, Webhook, and Addons for Contact Form 7
contact-form-7-honeypot
Addons for Contact Form 7 — Honeypot, Database Entries, Redirection, Spam Protection, Webhooks, ACF integration for Contact Form 7, and more.
Really Simple CAPTCHA
really-simple-captcha
Really Simple CAPTCHA is a CAPTCHA module intended to be called from other plugins. It is originally created for my Contact Form 7 plugin.
Advanced Google reCAPTCHA
advanced-google-recaptcha
Captcha protection against spam comments & brute force login attacks using Google reCAPTCHA.
Spam protection, Honeypot, Anti-Spam by CleanTalk
cleantalk-spam-protect
Blocks spam comments, fake users, contact form spam and more. No impact on SEO. Privacy focused. CAPTCHA free, premium Antispam plugin.
WP reCAPTCHA Library Developer Profile
1 plugin · 10 total installs
How We Detect WP reCAPTCHA Library
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-recaptcha-library/recaptchalib.phpHTML / DOM Fingerprints
WPHC_AFF_IDWPHC_WP_VERSION