WordPress.org

Ready to get started?Download WordPress

Plugin Directory

WP-reCAPTCHA

Integrates reCAPTCHA anti-spam methods with WordPress including comment, registration, and email spam protection.

HELP, I'm still getting spam!

There are four common issues that make reCAPTCHA appear to be broken:

  1. Moderation Emails: reCAPTCHA marks comments as spam, so even though the comments don't actually get posted, you will be notified of what is supposedly new spam. It is recommended to turn off moderation emails with reCAPTCHA.
  2. Akismet Spam Queue: Again, because reCAPTCHA marks comments with a wrongly entered CAPTCHA as spam, they are added to the spam queue. These comments however weren't posted to the blog so reCAPTCHA is still doing it's job. It is recommended to either ignore the Spam Queue and clear it regularly or disable Akismet completely. reCAPTCHA takes care of all of the spam created by bots, which is the usual type of spam. The only other type of spam that would get through is human spam, where humans are hired to manually solve CAPTCHAs. If you still get spam while only having reCAPTCHA enabled, you could be a victim of the latter practice. If this is the case, then turning on Akismet will most likely solve your problem. Again, just because it shows up in the Spam Queue does NOT mean that spam is being posted to your blog, it's more of a 'comments that have been caught as spam by reCAPTCHA' queue.
  3. Trackbacks and Pingbacks: reCAPTCHA can't do anything about pingbacks and trackbacks. You can disable pingbacks and trackbacks in Options > Discussion > Allow notifications from other Weblogs (Pingbacks and trackbacks).
  4. Human Spammers: Believe it or not, there are people who are paid (or maybe slave labor?) to solve CAPTCHAs all over the internet and spam. This is the last and rarest reason for which it might appear that reCAPTCHA is not working, but it does happen. On this plugin's page, these people sometimes attempt to post spam to try and make it seem as if reCAPTCHA is not working. A combination of reCAPTCHA and Akismet might help to solve this problem, and if spam still gets through for this reason, it would be very minimal and easy to manually take care of.

= Why am I getting Warning: pack() [function.pack]: Type H: illegal hex digit? You have the keys in the wrong place. Remember, the reCAPTCHA keys are different from the MailHide keys. And the Public keys are different from the Private keys as well. You can't mix them around. Go through your keys and make sure you have them each in the correct box.

Aren't you increasing the time users spend solving CAPTCHAs by requiring them to type two words instead of one?

Actually, no. Most CAPTCHAs on the Web ask users to enter strings of random characters, which are slower to type than English words. reCAPTCHA requires no more time to solve than most other CAPTCHAs.

Are reCAPTCHAs less secure than other CAPTCHAs that use random characters instead of words?

Because we ask users to enter two words instead of one, we can increase the security of reCAPTCHA against programs that attempt to guess the words using a dictionary. Whenever an IP address fails one reCAPTCHA, we can show them more distorted words, and give them challenges for which we know both words. The probability of randomly guessing both words correctly would be less than one in ten million.

Are CAPTCHAs secure? I heard spammers are using porn sites to solve them: the CAPTCHAs are sent to a porn site, and the porn site users are asked to solve the CAPTCHA before being able to see a pornographic image.

CAPTCHAs offer great protection against abuse from automated programs. While it might be the case that some spammers have started using porn sites to attack CAPTCHAs (although there is no recorded evidence of this), the amount of damage this can inflict is tiny (so tiny that we haven't even seen this happen!). Whereas it is trivial to write a bot that abuses an unprotected site millions of times a day, redirecting CAPTCHAs to be solved by humans viewing pornography would only allow spammers to abuse systems a few thousand times per day. The economics of this attack just don't add up: every time a porn site shows a CAPTCHA before a porn image, they risk losing a customer to another site that doesn't do this.

Requires: 2.7 or higher
Compatible up to: 2.9.2
Last Updated: 2013-12-10
Downloads: 507,421

Ratings

4 stars
4.1 out of 5 stars

Support

1 of 9 support threads in the last two months have been resolved.

Got something to say? Need help?

Compatibility

+
=
Not enough data

0 people say it works.
0 people say it's broken.

100,2,2
83,6,5
50,10,5 0,2,0 0,2,0
75,4,3 0,2,0 0,2,0
100,10,10 33,3,1 0,2,0
71,7,5 65,17,11 0,2,0
71,17,12 0,2,0
60,15,9 50,2,1 70,33,23
67,6,4
67,3,2
100,3,3 0,2,0
70,20,14 0,1,0
43,7,3 0,2,0 100,1,1 63,8,5
100,1,1 36,14,5
22,18,4 0,1,0
0,1,0
0,2,0
57,28,16 100,1,1
88,8,7
60,15,9 0,3,0 93,14,13
86,7,6
50,2,1
86,7,6
78,9,7
83,6,5
71,17,12
100,2,2
67,3,2
50,2,1
0,1,0
100,3,3
100,1,1
100,2,2