Spam Protection WordPress Plugins with Most Issues
27 indexed plugins
Plugins
27
Active Installs
3m+
Average Score
56
Audited
27
Most Issues
| Rank | Plugin | Score | Errors | Warnings | Installs | Added | Updated | Top Issue |
|---|---|---|---|---|---|---|---|---|
| #1 | CF7 Apps – Honeypot, Database, Redirection, Webhook, and Addons for Contact Form 7 | 24 | 1,034 | 1,396 | 300k+ | Non-prefixed global variable | ||
| #2 | Captcha by BestWebSoft – Advanced Spam Protection, Math & OCR-Friendly Captcha for Site Forms | 22 | 493 | 295 | 10k+ | Text Domain Mismatch | ||
| #3 | Disable Comments & Delete All Comments | 25 | 503 | 185 | 9k+ | Output is not escaped | ||
| #4 | Anti-spam, Spam protection, ReCaptcha for all forms and GDPR-compliant | 30 | 264 | 221 | 4k+ | Non Singular String Literal Text | ||
| #5 | SilentShield – Captcha & Anti-Spam for WordPress (CF7, WPForms, Elementor, WooCommerce) | 25 | 235 | 214 | 10k+ | Database parameter is not escaped | ||
| #6 | mosparo Integration | 35 | 114 | 301 | 900 | Missing nonce verification | ||
| #7 | Titan Anti-spam & Security – Brute Force Protection, 2FA & Spam Filter | 31 | 57 | 196 | 50k+ | Nonce verification recommended | ||
| #8 | Stop Spammers Classic | 94 | 185 | 1 | 30k+ | wp function not compatible with requires wp | ||
| #9 | Uber reCaptcha | 43 | 129 | 45 | 1k+ | Text Domain Mismatch | ||
| #10 | WP Armour – Honeypot Anti Spam | 40 | 55 | 66 | 400k+ | Missing nonce verification | ||
| #11 | Custom Contact Forms | 39 | 13 | 106 | 6k+ | Missing nonce verification | ||
| #12 | Universal Honey Pot | 40 | 23 | 94 | 1k+ | Missing nonce verification | ||
| #13 | Anti-Spam Protection – No API Key, GDPR Friendly | 49 | 2 | 106 | 1k+ | Direct Query | ||
| #14 | FluentComments – Spam protection, AntiSpam, Ajax Enhanced Comments | 40 | 50 | 47 | 700 | Non-prefixed global variable | ||
| #15 | Contact Form 7 Captcha | 41 | 7 | 75 | 100k+ | Request data is not unslashed | ||
| #16 | Proxy & VPN Blocker | 42 | 10 | 72 | 1k+ | Nonce verification recommended | ||
| #17 | CHEQ Essentials | 56 | 14 | 49 | 700 | Request data is not unslashed | ||
| #18 | Disable Comments – Remove Comments & Stop Spam [Multi-Site Support] | 53 | 15 | 46 | 1m+ | Non-prefixed global variable | ||
| #19 | Contact Form 7 Text CAPTCHA | 76 | 14 | 34 | 1k+ | Non-prefixed global variable | ||
| #20 | Antispam Bee | 80 | 4 | 38 | 700k+ | Nonce verification recommended | ||
| #21 | CryptX | 69 | 11 | 30 | 10k+ | Missing nonce verification | ||
| #22 | Enable Turnstile (Cloudflare) for Gravity Forms | 84 | 8 | 7 | 700 | Missing direct file access protection | ||
| #23 | Honeypot Anti-Spam | 78 | 5 | 7 | 10k+ | Missing nonce verification | ||
| #24 | Hostbox Google reCAPTCHA | 99 | 1 | 7 | 600 | Non-prefixed global variable | ||
| #25 | Simple Honeypot for Contact Form 7 | 91 | 1 | 6 | 500 | Missing nonce verification | ||
| #26 | ActiveLayer Anti-Spam: Spam Protection for Forms & Comments | 96 | 2 | 2k+ | Database parameter is not escaped | |||
| #27 | Dam Spam | 100 | 1 | 1k+ | unexpected markdown file |