
ReCaptcha v2 for Contact Form 7 Security & Risk Analysis
wordpress.org/plugins/wpcf7-recaptchaAdds reCaptcha v2 from Contact Form 7 5.0.5 that was dropped on Contact Form 7 5.1
Is ReCaptcha v2 for Contact Form 7 Safe to Use in 2026?
Generally Safe
Score 100/100ReCaptcha v2 for Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wpcf7-recaptcha plugin, version 1.4.9, exhibits a generally good security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits its attack surface. The code also demonstrates good practices with 100% of SQL queries using prepared statements and a high percentage of output being properly escaped. The presence of a nonce check is also a positive indicator. However, the plugin does make one external HTTP request, which, without further analysis of its context, represents a potential point of vulnerability if not handled securely. The vulnerability history is completely clean, with no recorded CVEs, suggesting a well-maintained and secure plugin over time. The lack of any taint analysis findings further reinforces the impression of a secure codebase. Overall, the plugin appears to be robustly developed with strong security awareness, with the minor concern being the unscrutinized external HTTP request.
Key Concerns
- External HTTP request made without clear context
ReCaptcha v2 for Contact Form 7 Security Vulnerabilities
ReCaptcha v2 for Contact Form 7 Code Analysis
Output Escaping
Data Flow Analysis
ReCaptcha v2 for Contact Form 7 Attack Surface
WordPress Hooks 17
Maintenance & Trust
ReCaptcha v2 for Contact Form 7 Maintenance & Trust
Maintenance Signals
Community Trust
ReCaptcha v2 for Contact Form 7 Alternatives
KP Fastest Contact Form 7 Recaptcha V3
kp-fastest-cf7-recaptcha
Speeds up websites that use Contact Form 7 Recaptcha V3. Built by Kreativo Pro WordPress Speed Specialists.
Contact Form 7 Captcha
contact-form-7-simple-recaptcha
Protect your Contact Form 7 forms with Google reCAPTCHA V2, Google reCAPTCHA V3, hCAPTCHA, or Cloudflare Turnstile.
Contact Form 7 Text CAPTCHA
text-captcha-contact-form-7
Secure your website Contact Form 7 forms from bots and hackers using plugin Contact Form 7 Text CAPTCHA. Just place shortcode [captchacf7* input-captc …
Invisible Anti Spam for Contact Form 7 (Simple No-Bot)
simple-no-bot
Simple, lightweight, no captcha, no configuration. Just works.
Show Recaptcha Where Nedeed
show-recaptcha-where-nedeed
This plugin fixes Contact Form 7's Recaptcha v3 so it only appears on pages with contact forms.
ReCaptcha v2 for Contact Form 7 Developer Profile
2 plugins · 200K total installs
How We Detect ReCaptcha v2 for Contact Form 7
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.