Description
Gate House helps reduce automated spam on native WordPress and WooCommerce forms. Start with built-in keyless checks, or connect Cloudflare Turnstile, Google reCAPTCHA v2/v3 or hCaptcha. Free needs no Gate House account, license, credit card or trial.
WordPress login, registration and comment spam protection
Choose Off, Invisible or Human check for native WordPress login, registration, password-reset requests and comments. The checks act on supported submissions; they do not classify comment content or prove that every visitor is legitimate.
WooCommerce checkout, account and review forms
Add checks to WooCommerce My Account forms, product reviews, classic checkout, Checkout Blocks and native order-payment forms. Checkout checks are an explicit choice: test complete sandbox payment journeys before enabling them. Custom forms, headless routes, express wallets and gateway-specific flows need separate assessment.
Start without CAPTCHA keys
Automatic protection runs on your server using a signed form proof, a hidden honeypot and a minimum submission time. No external provider account or browser challenge is needed for this mode. Fresh settings observe until you choose protection. Turn on recommended protection enables invisible checks for supported sign-in, registration, reset, comment and review forms while leaving checkout unchanged.
Choose Turnstile, reCAPTCHA or hCaptcha
All three provider integrations are included in Free: Cloudflare Turnstile Managed, Google reCAPTCHA v2 checkbox or v3 score, and standard hCaptcha. Connect one external provider at a time, save that provider’s keys and run the browser-to-server connection test. Then select Human check on the forms you want to protect. Provider key creation takes place in the provider’s own dashboard.
See form coverage and blocked attempts
Guided setup includes form discovery, provider diagnostics and daily blocked-attempt totals. Overview separates enabled form types from successful-use observations. A detected form or passing provider test is not proof that every theme or payment journey works. Try successful and rejected submissions on the actual forms your visitors use.
Free protection and optional Pro controls
Free includes the form checks above, keyless setup, provider testing, coverage and the aggregate blocked-attempt counter. Gate House Pro is a separately distributed add-on for configurable rate limits and presets, advanced rules, disposable-email and account-abuse checks, card-testing signals, held-order review, detailed local activity, Contact Form 7 and administration tools. Free keeps working independently. Learn more: https://gatehousewp.com/
External services
Automatic protection runs locally and sends no data to Gate House or a CAPTCHA vendor. The Free edition has no Gate House license updater, install check-in or setup-status telemetry. Its CSS, JavaScript and fonts ship locally.
External verification is optional. An administrator chooses a provider, saves that provider’s keys, runs an explicit connection test, and enables Human check on selected forms. Only that selected provider’s browser script is loaded on forms configured for its check and on explicit administrator diagnostics. Automatic forms do not load a vendor challenge. The script receives the public site key and, where supported, the form’s verification action; the provider processes browser/challenge data under its own privacy policy, including the browser’s network connection and IP address.
When a visitor submits a provider challenge, or an administrator submits the connection test, Gate House sends an HTTPS POST containing the verification secret (secret), challenge token (response), and trusted client IP when available (remoteip) to the selected provider’s verification endpoint. hCaptcha also receives the expected public site key (sitekey). The plugin does not send account passwords, payment details, or order contents to these verification endpoints. Raw challenge tokens, secrets and IP addresses are not retained in plugin counters.
Cloudflare Turnstile
Purpose: managed human verification for the selected forms and administrator connection test.
Browser script: https://challenges.cloudflare.com/turnstile/v0/api.js?render=explicit
Server verification: https://challenges.cloudflare.com/turnstile/v0/siteverify
Terms: https://www.cloudflare.com/website-terms/
Privacy: https://www.cloudflare.com/privacypolicy/
Google reCAPTCHA
Purpose: reCAPTCHA v2 checkbox or v3 verification for the selected forms and administrator connection test.
Browser script: https://www.google.com/recaptcha/api.js (render=explicit for v2; render= for v3).
Server verification: https://www.google.com/recaptcha/api/siteverify
Terms: https://policies.google.com/terms
Privacy: https://policies.google.com/privacy
hCaptcha
Purpose: standard human verification for the selected forms and administrator connection test.
Browser script: https://js.hcaptcha.com/1/api.js?render=explicit
Server verification: https://api.hcaptcha.com/siteverify
Terms: https://www.hcaptcha.com/terms
Privacy: https://www.hcaptcha.com/privacy
Review your selected provider’s terms, privacy information and quotas before configuring it. Provider keys are optional when using Automatic protection. Preserve provider branding and any privacy notices required for your site.
Source code and build instructions
Readable TypeScript and CSS for the compiled assets are included in assets/src/. The build entry point is tools/build.mjs; package.json, package-lock.json and tsconfig.json contain the build configuration and locked dependencies. No private repository or Pro source is needed to rebuild the Free assets.
On a development copy, use Node.js 22 LTS (22.13 or later) with npm. From the installed gate-house-spam-protection-captcha directory (gate-house/ in the source repository), run:
npm ci
npm run build
The build writes assets/build/admin.js, assets/build/frontend.js, assets/build/frontend-recovery.js, assets/build/admin.css and assets/build/frontend.css. The local recovery helper can restore the frontend bundle when a page builder removes it; it waits for a configured Human-check widget and does not contact an additional service. To check the source, run npm run typecheck and npm run lint. Prebuilt assets ship in the installation ZIP, so site owners do not need Node.js or a build step. Keep node_modules and other development dependencies out of distributable ZIPs. Local font files are covered by assets/fonts/OFL.txt.
Screenshots

Installation
- Install and activate Gate House on an individual WordPress site.
- Open Settings > Gate House and review the detected forms.
- Choose Automatic, or save your external provider keys and complete its connection test.
- Enable protection for the forms you use and verify the actual visitor journeys, including rejected submissions and sandbox checkout.
PHP 8.1 and WordPress 7.1 minimum. WooCommerce integrations require 11.1.2 or later. Selected test targets are WordPress 7.1.2 and WooCommerce 11.1.2; other versions need testing. WordPress protection works without WooCommerce. Network activation is not supported.
FAQ
-
Can I use spam protection without CAPTCHA keys?
-
Yes. Automatic protection uses local honeypot, timing and signed-form checks. External Human checks require keys from the selected provider; Free itself needs no Gate House account.
-
Does this stop all fake accounts or fraudulent orders?
-
No. Form verification helps reduce automated submissions; a passed check does not establish a buyer’s identity or a genuine purchase. Pro adds specific abuse-pattern controls, not a universal fraud guarantee.
-
Does checkout protection turn on automatically?
-
No. Fresh settings observe, and recommended setup leaves checkout unchanged. Enable the supported checkout checks after testing complete sandbox orders with your site’s payment methods.
-
Are rate limits and activity logs included in Free?
-
Free shows aggregate blocked-attempt totals. Configurable attempt limits, Light/Balanced/Strict presets and detailed local activity history are Pro features.
-
Does Gate House work without WooCommerce?
-
Yes. Native WordPress login, registration, password-reset and comment checks work independently of WooCommerce.
-
Does form discovery protect every form plugin?
-
No. Discovery reports known form entry points and adapter coverage. Free protects its supported native WordPress and WooCommerce forms. Other form plugins need an implemented adapter; Contact Form 7 support is in Pro.
-
Does Free expire?
-
No. Free protection needs no Gate House license or account.
-
Can I install this over the older complete paid plugin?
-
Back up the site. Update the complete legacy edition to 1.17.0, then install or update the standalone Gate House Pro add-on to 1.17.0 and activate it before migrating the base. Turn off Delete data on uninstall in the existing settings. Install and activate the branded Free package as gate-house-spam-protection-captcha/gate-house-spam-protection-captcha.php while keeping Pro active. The new base waits while the old base protects the site. On the Plugins page, use Switch to this installation in the new Gate House row after its compatibility checks pass. Verify your settings and real visitor journeys. Never uninstall the old base as a migration step; existing settings, keys, licensing and restrictions keep their original storage identifiers. A Free-only replacement would omit advanced protections.
-
How do I move from an earlier Gate House folder?
-
Back up the site and, if you use Pro, update and activate Pro 1.17.0 first. Turn off Delete data on uninstall. Install and activate this package alongside the earlier gate-house/gate-house.php or gatehouse-spam-protection-captcha/gatehouse-spam-protection-captcha.php installation; the earlier installation continues protecting the site until you choose Switch to this installation on the Plugins page. Follow its compatibility checks, retain the inactive earlier folder and verify real visitor journeys. Never uninstall the earlier base as part of the switch.
-
What does the connection test prove?
-
It verifies a fresh provider challenge. It does not certify your theme, payment gateway or every form. Test your real visitor journeys separately.
-
How do I recover access?
-
Set GATE_HOUSE_RECOVERY_MODE=true in server-side wp-config.php. There is no public bypass URL.
-
Are orders or accounts deleted?
-
No. Uninstall retains plugin-owned data unless its explicit deletion setting is enabled.
Reviews
There are no reviews for this plugin.
Contributors & Developers
“Gate House – Spam Protection & CAPTCHA” is open source software. The following people have contributed to this plugin.
ContributorsTranslate “Gate House – Spam Protection & CAPTCHA” into your language.
Interested in development?
Browse the code, check out the SVN repository, or subscribe to the development log by RSS.
Changelog
1.20.1
Marks the atomic settings write as a reviewed direct database query, clearing the last Plugin Check warning. No behavior or stored-data changes.
1.20.0
Retires the remaining short-prefix names: front-end markup, submitted form fields, error codes, the held-order status and the notice parameter now use the unique gate_house / gate-house names, and orders held under the earlier status move automatically. The old wp usp command alias and the USP_RECOVERY_MODE, USP_SITE_KEY and USP_SECRET_KEY wp-config fallbacks are removed; use the GATE_HOUSE_ names. If you use Gate House Pro, update it together with this plugin: Pro 1.20.0 or later is required.
1.19.0
Addresses WordPress.org review feedback. Stored data, hooks, scripts, capabilities and database tables now use the unique gate_house prefix instead of a short one, and earlier settings, provider connection state, coverage evidence and administrator access are copied forward automatically on first load (the originals are left in place). The Protection Test builds the login URL with wp_login_url() and no longer touches submitted form data. If you use Gate House Pro, update it together with this plugin: Pro 1.19.0 or later is required.
1.18.1
Uses WordPress.org language packs for Free translations and omits bundled translation catalogs and the explicit translation loader. Package checks guard against bundled translations returning. Existing settings and protection behavior are preserved.
1.18.0
Gate House Pro can now protect WPForms forms (verified against WPForms Lite 2.0.2.1). With Pro active, every WPForms form gets the same per-form check ladder (Off, Invisible, Human check) and rate limits as the built-in forms; a blocked attempt surfaces as WPForms’ own error and stores nothing. The Coverage tab’s entry-points card counts WPForms forms and reports them covered with Pro, and says plainly that no adapter is available yet without it. This update contains the base-side wiring; the adapter itself ships in the Pro add-on of the same version.
1.17.0
Base compatibility for separately consented Cloud rule lists; existing Free protection and local settings are preserved.
1.16.0
Compatible settings support for separately consented Cloud templates. The assigned WordPress.org identity and existing settings are preserved.
1.15.2
Uses the WordPress.org-assigned gate-house-spam-protection-captcha directory, entrypoint and shared translation domain. Preserves safe migration from earlier installation folders, existing settings and the WooCommerce checkout extension contract.
1.15.1
Introduces the public title Gate House – Spam Protection & CAPTCHA and the matching directory identity. Clarifies Free form protection, keyless setup, checkout opt-in and optional Pro controls while preserving existing settings and the checkout extension contract.
1.15.0
Uses the branded gate-house directory, entrypoint and text domain for the WordPress.org candidate. Preserves existing settings and data, with an explicit Pro-first migration from older installations.
1.14.1
Prepares the Free edition for WordPress.org review with contributor metadata, explicit external-service disclosures and reproducible asset-build instructions. Enqueues the recovery helper through WordPress, improves translation extraction, and guards direct file access. Keeps the existing plugin identity and separate Pro and legacy distributions.
1.14.0
Introduces separate Free and Pro distribution, preserves the legacy complete-product update channel, and removes anonymous Gate House store requests. Existing product history remains in CHANGELOG.md.
