Is this a security issue or not?
-
Hello Developers,
First of all a very good job you people done and many many thanks for your effort on this plugin.
Now come to the issue. I used shortcode for embedding recaptcha in my custom form. In the plugin folder, I found a file google_captcha_check.php . I used the code given in file for validating the captcha and no success could be met. Issue was with $_POST[‘gglcptch_private_key’] field, as it returns null. Using browser’s view-source, I tried to find if there exists a field with same name and what I found is recaptcha’s private-key in javascript code See here. What I want to ask is, is this secure to use private key in public? As per Google recommendation and what I think, private keys must be kept secret, as seen here. See here.
Am I missing some point here? Please clarify and put some light over it.
Thanks,
Nishant Kumar
- The topic ‘Is this a security issue or not?’ is closed to new replies.