
WP reCaptcha Login Security & Risk Analysis
wordpress.org/plugins/wp-recaptcha-loginLicense: GPLv2 or later This plugin uses reCaptcha V3 to add an extra layer of security at your login screen, preventing brute-force attacks.
Is WP reCaptcha Login Safe to Use in 2026?
Generally Safe
Score 85/100WP reCaptcha Login has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'wp-recaptcha-login' v1.0 plugin exhibits a generally good security posture based on the static analysis. The absence of known CVEs and the plugin's development history without recorded vulnerabilities are positive indicators. The code signals show a strong adherence to secure coding practices, with a high percentage of properly escaped outputs and the exclusive use of prepared statements for SQL queries. The attack surface is commendably small, with no identified AJAX handlers, REST API routes, shortcodes, or cron events, further limiting potential entry points for attackers.
However, there are a few areas that warrant attention. The presence of two taint flows with unsanitized paths, while not reaching critical or high severity in this analysis, suggests a potential for subtle vulnerabilities. Additionally, the plugin makes one external HTTP request. While not explicitly flagged as a risk, such requests can be a vector for server-side request forgery (SSRF) or man-in-the-middle attacks if not handled with extreme care and proper validation. The lack of nonce checks and capability checks on any identified entry points (though there are none) would be a significant concern if an attack surface were present.
In conclusion, 'wp-recaptcha-login' v1.0 appears to be a securely developed plugin, particularly regarding SQL and output handling. The primary weaknesses lie in the two identified unsanitized taint flows and the single external HTTP request, which, although not critically severe in this analysis, represent potential areas for future exploitation. The plugin's clean vulnerability history is a significant strength.
Key Concerns
- Taint flows with unsanitized paths
- External HTTP request present
WP reCaptcha Login Security Vulnerabilities
WP reCaptcha Login Release Timeline
WP reCaptcha Login Code Analysis
Output Escaping
Data Flow Analysis
WP reCaptcha Login Attack Surface
WordPress Hooks 5
Maintenance & Trust
WP reCaptcha Login Maintenance & Trust
Maintenance Signals
Community Trust
WP reCaptcha Login Alternatives
Login No Captcha reCAPTCHA
login-recaptcha
Adds a Google No Captcha ReCaptcha checkbox to your Wordpress and Woocommerce login, forgot password, and user registration pages.
Login Security Captcha
login-security-recaptcha
Secure WordPress login, registration, and comment form with Google reCAPTCHA or Cloudflare Turnstile. Prevent Brute-force attacks and more.
ReCaptcha Integration for WordPress
wp-recaptcha-integration
reCaptcha for login, signup, comment forms, Ninja Forms and woocommerce.
DoLogin Security
dologin
Easy Login. 2FA login. Passwordless login. Cloudflare Turnstile reCAPTCHA. GeoLocation (Continent/Country/City)/IP range to limit login attempts.
No CAPTCHA reCAPTCHA
no-captcha-recaptcha
Protect WordPress login, registration, comment and BuddyPress registration forms with Google's No CAPTCHA reCAPTCHA.
WP reCaptcha Login Developer Profile
20 plugins · 1K total installs
How We Detect WP reCaptcha Login
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
https://www.google.com/recaptcha/api.jsHTML / DOM Fingerprints
g-recaptchaAint nobody got time fo datdata-sitekeydata-callbackdata-sizeonSubmit