Description
Codenitive CAPTCHA Security helps protect WordPress, WooCommerce and Contact Form 7 forms from spam, bots and automated abuse.
Choose a single CAPTCHA provider from the plugin settings:
- Google reCAPTCHA v2 Checkbox
- Google reCAPTCHA v3
- Cloudflare Turnstile
- Disabled
Protect forms including:
- WordPress Login
- WordPress Registration
- WordPress Lost Password
- WordPress Comments
- WooCommerce Login
- WooCommerce Registration
- WooCommerce Checkout
- WooCommerce Product Reviews
- Contact Form 7
Google reCAPTCHA v2 supports Light and Dark themes plus Normal and Compact sizes. Cloudflare Turnstile supports Managed, Non-Interactive and Invisible widget modes plus Auto, Light and Dark themes for visible widgets.
Features
- Google reCAPTCHA v2 Checkbox support
- Google reCAPTCHA v2 theme and size customization
- Google reCAPTCHA v3 score-based support
- Cloudflare Turnstile support
- Single CAPTCHA provider selection
- Option to completely disable CAPTCHA protection
- Cloudflare Turnstile theme customization
- Cloudflare Turnstile Managed, Non-Interactive and Invisible mode mapping
- Cloudflare Turnstile appearance customization
- Cloudflare Turnstile widget size customization
- WordPress Login, Registration, Lost Password and Comments protection
- WooCommerce Login, Registration, classic Checkout, Checkout Block and Product Reviews protection
- Contact Form 7 integration
- Hide CAPTCHA for logged-in users
- CAPTCHA verification logs
- Provider error reporting for failed verification attempts
- Helps prevent spam, bots and brute-force attacks
- Easy configuration through the WordPress admin settings panel
- Compatible with most themes and caching plugins
Usage
After activating the plugin:
- Go to Settings Codenitive CAPTCHA Security.
- Select your preferred CAPTCHA provider.
- Enter the Site Key and Secret Key for the selected provider.
- Configure additional provider settings if required.
- Open the Options tab and enable protection for the desired forms.
- Save your settings.
To disable CAPTCHA protection completely, select Disabled as the CAPTCHA provider.
Google reCAPTCHA v2 Customization
When Google reCAPTCHA v2 is selected, the checkbox widget supports:
Theme
- Light (default)
- Dark
Size
- Normal (default)
- Compact
These options apply only to the visible reCAPTCHA v2 checkbox. reCAPTCHA v3 is score-based and has no checkbox theme or size setting.
Cloudflare Turnstile Customization
When Cloudflare Turnstile is selected as the CAPTCHA provider, the following widget customization options are available:
Widget Mode
- Managed (recommended)
- Non-Interactive
- Invisible
The widget mode is bound to the Turnstile Site Key in Cloudflare. Select the same mode in the plugin so it can apply compatible presentation settings. The plugin does not send an unsupported mode value to the browser API.
Theme
- Auto
- Light
- Dark
Appearance
- Always
- Execute
- Interaction-only
Size
- Normal
- Compact
- Flexible
Theme, appearance and size apply to Managed and Non-Interactive widgets. Invisible widgets have no visual footprint, so those display settings are omitted when Invisible mode is selected.
CAPTCHA Verification Logs
The plugin can record failed CAPTCHA verification attempts to help administrators troubleshoot CAPTCHA configuration and verification issues.
Verification logs may include information such as:
- CAPTCHA provider
- Protected form or integration
- Verification result
- Provider error codes
- Date and time of the failed verification
Logs are intended for troubleshooting and monitoring CAPTCHA verification failures.
Privacy
This plugin connects to external CAPTCHA services to help prevent spam and automated abuse.
Data is sent to the currently selected CAPTCHA provider when CAPTCHA protection is used on a protected form.
Supported external services:
- Google reCAPTCHA
- Cloudflare Turnstile
If CAPTCHA is disabled, the plugin does not load or perform CAPTCHA verification through these providers.
External Services Used
This plugin uses one of the following third-party services depending on the CAPTCHA provider selected by the site administrator.
Google reCAPTCHA v2
- Purpose: Helps prevent spam and automated abuse during protected form submissions.
- Data Sent: Browser and interaction information may be sent to Google as part of the CAPTCHA verification process.
- When Sent: When Google reCAPTCHA is selected and a visitor interacts with a protected form.
- Service Provider: Google LLC
- Terms of Service: https://policies.google.com/terms
- Privacy Policy: https://policies.google.com/privacy
Google reCAPTCHA v3
- Purpose: Provides score-based protection against spam and automated abuse without displaying a checkbox challenge.
- Data Sent: Browser, interaction and form-action information may be sent to Google as part of CAPTCHA scoring and verification.
- When Sent: When Google reCAPTCHA v3 is selected and a visitor submits a protected form.
- Service Provider: Google LLC
- Terms of Service: https://policies.google.com/terms
- Privacy Policy: https://policies.google.com/privacy
Cloudflare Turnstile
- Purpose: Helps prevent spam and automated abuse on protected forms.
- Data Sent: Browser, network and other information required by the Turnstile verification service may be sent to Cloudflare.
- When Sent: When Cloudflare Turnstile is selected and CAPTCHA protection is used on a protected form.
- Service Provider: Cloudflare, Inc.
- Terms of Service: https://www.cloudflare.com/website-terms/
- Privacy Policy: https://www.cloudflare.com/privacypolicy/
If Invisible Turnstile mode is used, review Cloudflare’s Turnstile Privacy Addendum and reference it in your site’s privacy policy as required by Cloudflare:
https://www.cloudflare.com/turnstile-privacy-policy/
Feedback
If you like this plugin, please leave us a 5-star review:
https://wordpress.org/support/plugin/codenitive-captcha/reviews/#new-post
Need help or have a feature request? Use the Support Forum:
https://wordpress.org/support/plugin/codenitive-captcha/
Screenshots




![Contact Form 7 integration using the [codenit_recaptcha] shortcode.](https://ps.w.org/codenitive-captcha/assets/screenshot-5.png?rev=3641178)
[codenit_recaptcha] shortcode.Installation
- Upload the plugin folder
codenitive-captchato/wp-content/plugins, or install it through the Plugins screen in WordPress. - Activate the plugin through the Plugins menu.
- Go to Settings Codenitive CAPTCHA Security.
- Select your preferred CAPTCHA provider:
- Google reCAPTCHA v2 Checkbox
- Google reCAPTCHA v3
- Cloudflare Turnstile
- Enter the Site Key and Secret Key for your selected provider.
- If using Google reCAPTCHA v2, optionally select the Light or Dark theme and Normal or Compact size.
- If using Cloudflare Turnstile, select the same widget mode configured for the Site Key in Cloudflare, then configure the optional theme, appearance and size settings.
- Select the forms you want to protect.
- Save your settings.
FAQ
-
Which CAPTCHA providers are supported?
-
The plugin currently supports:
- Google reCAPTCHA v2 Checkbox
- Google reCAPTCHA v3
- Cloudflare Turnstile
You can select one provider at a time from the plugin settings.
-
Can I disable CAPTCHA without disabling the plugin?
-
Yes. Select Disabled from the CAPTCHA Provider setting. CAPTCHA widgets and verification will not be used while the provider is disabled.
-
Does this plugin support Cloudflare Turnstile?
-
Yes. Select Cloudflare Turnstile as your CAPTCHA provider and enter your Turnstile Site Key and Secret Key.
-
Can I customize the Google reCAPTCHA widget?
-
Yes. Google reCAPTCHA v2 supports Light and Dark themes and Normal and Compact sizes. reCAPTCHA v3 has no visible checkbox, so these options do not apply to v3.
-
Can I customize the Cloudflare Turnstile widget?
-
Yes. You can map the Turnstile widget mode and configure the theme, appearance and widget size from the plugin settings.
Available widget modes:
- Managed
- Non-Interactive
- Invisible
Available themes:
- Auto
- Light
- Dark
Available appearance options:
- Always
- Execute
- Interaction-only
Available sizes:
- Normal
- Compact
- Flexible
-
What if CAPTCHA does not show?
-
Make sure:
- A CAPTCHA provider is selected.
- Valid Site Key and Secret Key values are configured for the selected provider.
- The form is enabled in the plugin settings.
- CAPTCHA is not configured to be hidden for the currently logged-in user.
-
Does this plugin work with WooCommerce?
-
Yes. It supports CAPTCHA protection for WooCommerce login, registration, checkout and product review forms.
-
Does this plugin work with Contact Form 7?
-
Yes.
- Go to Settings Codenitive CAPTCHA Security.
- Select and configure a CAPTCHA provider.
- Open the Options tab.
- Enable Contact Form 7 protection.
- Add the
[codenit_recaptcha]shortcode to your Contact Form 7 form. - Save your settings.
The
[codenit_recaptcha]shortcode uses the CAPTCHA provider currently selected in the plugin settings. -
Can I customize where CAPTCHA appears?
-
You can enable or disable CAPTCHA protection for supported forms through the plugin settings.
-
Where can I generate my Google reCAPTCHA Site and Secret Keys?
-
https://www.google.com/recaptcha/admin/create
-
Where can I generate Cloudflare Turnstile Site and Secret Keys?
-
https://dash.cloudflare.com/?to=/:account/turnstile
Reviews
There are no reviews for this plugin.
Contributors & Developers
“Codenitive CAPTCHA Security” is open source software. The following people have contributed to this plugin.
ContributorsTranslate “Codenitive CAPTCHA Security” into your language.
Interested in development?
Browse the code, check out the SVN repository, or subscribe to the development log by RSS.
Changelog
1.2.0
- Added Google reCAPTCHA v3 support.
- Added Google reCAPTCHA v2 Light/Dark theme and Normal/Compact size settings.
- Added separate reCAPTCHA v3 Site Key and Secret Key settings.
- Added configurable reCAPTCHA v3 score threshold.
- Added reCAPTCHA v3 support for WordPress, WooCommerce, comments and Contact Form 7.
- Added server-side reCAPTCHA v3 score and action verification.
- Added Cloudflare Turnstile widget mode mapping for Managed, Non-Interactive and Invisible widgets.
- Added strict settings sanitization for providers, v3 score threshold and Turnstile options.
- Added form-specific Turnstile action values and server-side action verification.
- Added legacy provider migration so existing v2 and Turnstile settings continue to work after upgrade.
- Fixed the reCAPTCHA v3 script URL and checkout script dependency.
1.1.3
- Added a single CAPTCHA provider selection setting.
- Added an option to disable CAPTCHA protection without disabling the plugin.
- Added Cloudflare Turnstile theme options: Auto, Light and Dark.
- Added Cloudflare Turnstile appearance options: Always, Execute and Interaction-only.
- Added Cloudflare Turnstile widget size options: Normal, Compact and Flexible.
- Improved CAPTCHA provider configuration and handling.
1.1.2
- Added CAPTCHA verification logs.
- Added provider error reporting for failed CAPTCHA verification attempts.
1.1.1
- Fixed Contact Form 7 CAPTCHA validation issues.
1.1.0
- Added Cloudflare Turnstile support.
- Added Turnstile settings with Site Key and Secret Key fields.
- Added server-side Turnstile verification using Cloudflare Siteverify.
- Updated frontend rendering to avoid duplicate CAPTCHA script and widget rendering.
1.0.5
- Fixed login CAPTCHA validation.
1.0.4
- Added Contact Form 7 integration.
1.0.0
- Initial release.
- Added Google reCAPTCHA v2 support.
- Added WordPress and WooCommerce form integrations.
