
Easy Spam Filter – Privacy-Friendly CAPTCHA Alternative with Turnstile for Contact Form 7, WPForms, BuddyPress, Elementor Security & Risk Analysis
wordpress.org/plugins/wppool-turnstile-captcha-spam-filterAdd Cloudflare Turnstile to WordPress, Contact Form 7, WooCommerce, WPForms, BuddyPress & Elementor. A CAPTCHA, reCAPTCHA alternative for WordPress.
Is Easy Spam Filter – Privacy-Friendly CAPTCHA Alternative with Turnstile for Contact Form 7, WPForms, BuddyPress, Elementor Safe to Use in 2026?
Generally Safe
Score 100/100Easy Spam Filter – Privacy-Friendly CAPTCHA Alternative with Turnstile for Contact Form 7, WPForms, BuddyPress, Elementor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wppool-turnstile-captcha-spam-filter" plugin v2.3.11 exhibits a generally strong security posture, with excellent practices in place for SQL query sanitization and output escaping. The absence of known vulnerabilities and a history free of CVEs are positive indicators. However, a significant concern arises from the presence of one AJAX handler that lacks authentication checks. This creates a direct entry point for potential exploitation without proper authorization, which is a fundamental security oversight. While the plugin demonstrates good coding hygiene in most areas, this single unprotected AJAX handler represents a clear and present risk that could be leveraged by attackers to execute unintended actions or gather sensitive information if the handler performs any such operations. The taint analysis did not reveal critical or high severity issues, suggesting that even with the unprotected endpoint, the immediate impact might be limited, but it should not be overlooked.
Key Concerns
- Unprotected AJAX handler
Easy Spam Filter – Privacy-Friendly CAPTCHA Alternative with Turnstile for Contact Form 7, WPForms, BuddyPress, Elementor Security Vulnerabilities
Easy Spam Filter – Privacy-Friendly CAPTCHA Alternative with Turnstile for Contact Form 7, WPForms, BuddyPress, Elementor Release Timeline
Easy Spam Filter – Privacy-Friendly CAPTCHA Alternative with Turnstile for Contact Form 7, WPForms, BuddyPress, Elementor Code Analysis
Output Escaping
Data Flow Analysis
Easy Spam Filter – Privacy-Friendly CAPTCHA Alternative with Turnstile for Contact Form 7, WPForms, BuddyPress, Elementor Attack Surface
AJAX Handlers 7
Shortcodes 1
WordPress Hooks 44
Maintenance & Trust
Easy Spam Filter – Privacy-Friendly CAPTCHA Alternative with Turnstile for Contact Form 7, WPForms, BuddyPress, Elementor Maintenance & Trust
Maintenance Signals
Community Trust
Easy Spam Filter – Privacy-Friendly CAPTCHA Alternative with Turnstile for Contact Form 7, WPForms, BuddyPress, Elementor Alternatives
CubeMage Login Guard
cubemage-login-guard
Integrates Cloudflare Turnstile, Limits Login Attempts, and Disables XML-RPC to protect WordPress forms.
CAPTCHA 4WP – Antispam CAPTCHA solution for WordPress
advanced-nocaptcha-recaptcha
Use CAPTCHA to stop spam and allow customers & users to interact with your website easily. Block fake accounts and orders. Avoid false positives.
DoLogin Security
dologin
Easy Login. 2FA login. Passwordless login. Cloudflare Turnstile reCAPTCHA. GeoLocation (Continent/Country/City)/IP range to limit login attempts.
Kitgenix CAPTCHA for Cloudflare Turnstile
kitgenix-captcha-for-cloudflare-turnstile
Add Cloudflare Turnstile CAPTCHA to WordPress, WooCommerce, Elementor, and popular form plugins with privacy-first server-side verification.
BWG CF Turnstile
bwg-cf-turnstile
Add Cloudflare Turnstile protection to your Gravity Forms to prevent spam and bot submissions.
Easy Spam Filter – Privacy-Friendly CAPTCHA Alternative with Turnstile for Contact Form 7, WPForms, BuddyPress, Elementor Developer Profile
16 plugins · 32K total installs
How We Detect Easy Spam Filter – Privacy-Friendly CAPTCHA Alternative with Turnstile for Contact Form 7, WPForms, BuddyPress, Elementor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wppool-turnstile-captcha-spam-filter/assets/css/admin.css/wp-content/plugins/wppool-turnstile-captcha-spam-filter/build/index.css/wp-content/plugins/wppool-turnstile-captcha-spam-filter/build/index.js/wppool-turnstile-captcha-spam-filter/assets/css/admin.css?ver=/wppool-turnstile-captcha-spam-filter/build/index.css?ver=/wppool-turnstile-captcha-spam-filter/build/index.js?ver=HTML / DOM Fingerprints
data-wppool-turnstile-keyECT_APP