Description
Protect your WordPress forms from spam, bots, and automated abuse with Arcoria FormShield — a simple and lightweight CAPTCHA solution built for WordPress.
Unlike services that require you to create a separate account and manage API keys manually, Arcoria FormShield is configured from your WordPress dashboard. The plugin connects to Arcoria-hosted services to provide CAPTCHA protection (see External services below).
Enable protection for the forms that matter most — including login, registration, password reset, comments, contact forms, and other user input areas.
Key Features
Simple setup
Install and activate Arcoria FormShield, then choose which forms you want to protect from the Forms section in the plugin settings. No separate Arcoria account or external dashboard is required for day-to-day use.
Protect WordPress core forms
Secure built-in WordPress forms including:
- Login
- Registration
- Lost Password
- Comments
Works with popular form plugins
Arcoria FormShield supports popular WordPress form builders and integrations, including:
- Contact Form 7
- WPForms
- Elementor Forms
User-friendly CAPTCHA protection
Add CAPTCHA protection to your forms without creating a frustrating experience for your visitors. Designed to provide a simple balance between security and usability.
Lightweight and WordPress native
Built specifically for WordPress. Arcoria FormShield runs inside your website and keeps the setup simple without unnecessary complexity.
Free to use
All Arcoria FormShield features are free. There are no premium tiers, paid upgrades, or feature limits inside the plugin.
External services
This plugin uses FormShield Captcha, an Arcoria service, to verify users and protect WordPress forms against spam and automated submissions. It relies on external services operated by ARCONIA TECHNOLOGIES LTD (brand: Arcoria) to provide CAPTCHA protection, credential provisioning, and optional support. To perform CAPTCHA verification and bot detection, the plugin communicates with FormShield servers and may process technical and behavioral information, such as browser information and interaction signals. This data is used only for security, spam prevention, and bot mitigation purposes. By using Arcoria FormShield, data may be transmitted to these services as described below.
Arcoria CAPTCHA API (`https://api.arcoria.xyz`)
Used to initialize the plugin and to verify CAPTCHA submissions on your website.
Plugin initialization (/api/formshield-init)
- When: On plugin load when site credentials are not yet stored locally, and when initialization is triggered again after credentials are missing.
- What is sent: An HTTP
Authorization: Bearerheader containing the plugin API token configured for your site. No form-submission or visitor CAPTCHA data is sent during initialization. - What is received: A
site_keyandsecret_key, which are stored in your WordPress database for CAPTCHA verification.
CAPTCHA verification (/api/verify)
- When: Each time a protected form is submitted on your site and the plugin validates the CAPTCHA server-side.
- What is sent: The CAPTCHA
challenge_idtoken from the form submission, together with your storedsite_keyandsecret_key.
Terms of use: https://arcoria.xyz/formshield/terms
Privacy policy: https://arcoria.xyz/formshield/privacy
Arcoria CAPTCHA Widget (`https://widget.arcoria.xyz`)
Used to load and display the CAPTCHA widget in visitors’ browsers.
- When: When a page containing an Arcoria FormShield field is loaded and the visitor interacts with the CAPTCHA widget.
- What is sent: The visitor’s browser loads JavaScript from
https://widget.arcoria.xyz/1/api.jsand communicates with Arcoria widget servers to render and complete the CAPTCHA. This may include technical and behavioral information needed for bot detection, such as IP address, browser user-agent, device/browser details, language settings, and CAPTCHA interaction signals. That browser-side processing is described in Arcoria’s privacy policy.
Terms of use: https://arcoria.xyz/formshield/terms
Privacy policy: https://arcoria.xyz/formshield/privacy
Arcoria Support API (`https://tools.arcoria.xyz`)
Used only when a site administrator submits the optional support form in the plugin Help settings tab.
- When: When an administrator with the
manage_optionscapability submits a support request from the WordPress admin area. - What is sent: The administrator-provided name, email address, website URL, issue type, and message. An optional file attachment may also be sent if the administrator chooses to include one. If the administrator opts in to include technical diagnostics, the request may also include WordPress version, PHP version, Arcoria FormShield version, active theme, active plugins, enabled Arcoria FormShield integrations, site language, and site URL.
Terms of use: https://arcoria.xyz/formshield/terms
Privacy policy: https://arcoria.xyz/formshield/privacy
Privacy
Arcoria FormShield processes visitor and site data only as needed to provide CAPTCHA verification, plugin initialization, and optional administrator support. For full details on data collection, retention, and user rights, see Arcoria’s privacy policy at https://arcoria.xyz/privacy
Reviews
There are no reviews for this plugin.
Contributors & Developers
“Arcoria-FormShield” is open source software. The following people have contributed to this plugin.
ContributorsTranslate “Arcoria-FormShield” into your language.
Interested in development?
Browse the code, check out the SVN repository, or subscribe to the development log by RSS.





