Title: Gate House – Spam Protection &amp; CAPTCHA
Author: gatehousewp
Published: <strong>October 10, 2026</strong>
Last modified: October 10, 2026

---

Search plugins

![](https://ps.w.org/gate-house-spam-protection-captcha/assets/banner-772x250.png?
rev=3738509)

![](https://ps.w.org/gate-house-spam-protection-captcha/assets/icon.svg?rev=3738509)

# Gate House – Spam Protection & CAPTCHA

 By [gatehousewp](https://profiles.wordpress.org/gatehousewp/)

[Download](https://downloads.wordpress.org/plugin/gate-house-spam-protection-captcha.1.20.1.zip)

 * [Details](https://wordpress.org/plugins/gate-house-spam-protection-captcha/#description)
 * [Reviews](https://wordpress.org/plugins/gate-house-spam-protection-captcha/#reviews)
 *  [Installation](https://wordpress.org/plugins/gate-house-spam-protection-captcha/#installation)
 * [Development](https://wordpress.org/plugins/gate-house-spam-protection-captcha/#developers)

 [Support](https://wordpress.org/support/plugin/gate-house-spam-protection-captcha/)

## Description

Gate House helps reduce automated spam on native WordPress and WooCommerce forms.
Start with built-in keyless checks, or connect Cloudflare Turnstile, Google reCAPTCHA
v2/v3 or hCaptcha. Free needs no Gate House account, license, credit card or trial.

#### WordPress login, registration and comment spam protection

Choose Off, Invisible or Human check for native WordPress login, registration, password-
reset requests and comments. The checks act on supported submissions; they do not
classify comment content or prove that every visitor is legitimate.

#### WooCommerce checkout, account and review forms

Add checks to WooCommerce My Account forms, product reviews, classic checkout, Checkout
Blocks and native order-payment forms. Checkout checks are an explicit choice: test
complete sandbox payment journeys before enabling them. Custom forms, headless routes,
express wallets and gateway-specific flows need separate assessment.

#### Start without CAPTCHA keys

Automatic protection runs on your server using a signed form proof, a hidden honeypot
and a minimum submission time. No external provider account or browser challenge
is needed for this mode. Fresh settings observe until you choose protection. Turn
on recommended protection enables invisible checks for supported sign-in, registration,
reset, comment and review forms while leaving checkout unchanged.

#### Choose Turnstile, reCAPTCHA or hCaptcha

All three provider integrations are included in Free: Cloudflare Turnstile Managed,
Google reCAPTCHA v2 checkbox or v3 score, and standard hCaptcha. Connect one external
provider at a time, save that provider’s keys and run the browser-to-server connection
test. Then select Human check on the forms you want to protect. Provider key creation
takes place in the provider’s own dashboard.

#### See form coverage and blocked attempts

Guided setup includes form discovery, provider diagnostics and daily blocked-attempt
totals. Overview separates enabled form types from successful-use observations. 
A detected form or passing provider test is not proof that every theme or payment
journey works. Try successful and rejected submissions on the actual forms your 
visitors use.

#### Free protection and optional Pro controls

Free includes the form checks above, keyless setup, provider testing, coverage and
the aggregate blocked-attempt counter. Gate House Pro is a separately distributed
add-on for configurable rate limits and presets, advanced rules, disposable-email
and account-abuse checks, card-testing signals, held-order review, detailed local
activity, Contact Form 7 and administration tools. Free keeps working independently.
Learn more: https://gatehousewp.com/

### External services

Automatic protection runs locally and sends no data to Gate House or a CAPTCHA vendor.
The Free edition has no Gate House license updater, install check-in or setup-status
telemetry. Its CSS, JavaScript and fonts ship locally.

External verification is optional. An administrator chooses a provider, saves that
provider’s keys, runs an explicit connection test, and enables Human check on selected
forms. Only that selected provider’s browser script is loaded on forms configured
for its check and on explicit administrator diagnostics. Automatic forms do not 
load a vendor challenge. The script receives the public site key and, where supported,
the form’s verification action; the provider processes browser/challenge data under
its own privacy policy, including the browser’s network connection and IP address.

When a visitor submits a provider challenge, or an administrator submits the connection
test, Gate House sends an HTTPS POST containing the verification secret (secret),
challenge token (response), and trusted client IP when available (remoteip) to the
selected provider’s verification endpoint. hCaptcha also receives the expected public
site key (sitekey). The plugin does not send account passwords, payment details,
or order contents to these verification endpoints. Raw challenge tokens, secrets
and IP addresses are not retained in plugin counters.

#### Cloudflare Turnstile

Purpose: managed human verification for the selected forms and administrator connection
test.
 Browser script: https://challenges.cloudflare.com/turnstile/v0/api.js?render
=explicit Server verification: https://challenges.cloudflare.com/turnstile/v0/siteverify
Terms: https://www.cloudflare.com/website-terms/ Privacy: https://www.cloudflare.
com/privacypolicy/

#### Google reCAPTCHA

Purpose: reCAPTCHA v2 checkbox or v3 verification for the selected forms and administrator
connection test.
 Browser script: https://www.google.com/recaptcha/api.js (render
=explicit for v2; render= for v3). Server verification: https://www.google.com/recaptcha/
api/siteverify Terms: https://policies.google.com/terms Privacy: https://policies.
google.com/privacy

#### hCaptcha

Purpose: standard human verification for the selected forms and administrator connection
test.
 Browser script: https://js.hcaptcha.com/1/api.js?render=explicit Server verification:
https://api.hcaptcha.com/siteverify Terms: https://www.hcaptcha.com/terms Privacy:
https://www.hcaptcha.com/privacy

Review your selected provider’s terms, privacy information and quotas before configuring
it. Provider keys are optional when using Automatic protection. Preserve provider
branding and any privacy notices required for your site.

### Source code and build instructions

Readable TypeScript and CSS for the compiled assets are included in assets/src/.
The build entry point is tools/build.mjs; package.json, package-lock.json and tsconfig.
json contain the build configuration and locked dependencies. No private repository
or Pro source is needed to rebuild the Free assets.

On a development copy, use Node.js 22 LTS (22.13 or later) with npm. From the installed
gate-house-spam-protection-captcha directory (gate-house/ in the source repository),
run:

    ```
    npm ci
    npm run build
    ```

The build writes assets/build/admin.js, assets/build/frontend.js, assets/build/frontend-
recovery.js, assets/build/admin.css and assets/build/frontend.css. The local recovery
helper can restore the frontend bundle when a page builder removes it; it waits 
for a configured Human-check widget and does not contact an additional service. 
To check the source, run npm run typecheck and npm run lint. Prebuilt assets ship
in the installation ZIP, so site owners do not need Node.js or a build step. Keep
node_modules and other development dependencies out of distributable ZIPs. Local
font files are covered by assets/fonts/OFL.txt.

## Screenshots

[⌊Overview: start with keyless checks and review enabled forms, successful-use observations
and blocked-attempt totals.⌉⌊Overview: start with keyless checks and review enabled
forms, successful-use observations and blocked-attempt totals.⌉[

Overview: start with keyless checks and review enabled forms, successful-use observations
and blocked-attempt totals.

## Installation

 1. Install and activate Gate House on an individual WordPress site.
 2. Open Settings > Gate House and review the detected forms.
 3. Choose Automatic, or save your external provider keys and complete its connection
    test.
 4. Enable protection for the forms you use and verify the actual visitor journeys,
    including rejected submissions and sandbox checkout.

PHP 8.1 and WordPress 7.1 minimum. WooCommerce integrations require 11.1.2 or later.
Selected test targets are WordPress 7.1.2 and WooCommerce 11.1.2; other versions
need testing. WordPress protection works without WooCommerce. Network activation
is not supported.

## FAQ

### Can I use spam protection without CAPTCHA keys?

Yes. Automatic protection uses local honeypot, timing and signed-form checks. External
Human checks require keys from the selected provider; Free itself needs no Gate 
House account.

### Does this stop all fake accounts or fraudulent orders?

No. Form verification helps reduce automated submissions; a passed check does not
establish a buyer’s identity or a genuine purchase. Pro adds specific abuse-pattern
controls, not a universal fraud guarantee.

### Does checkout protection turn on automatically?

No. Fresh settings observe, and recommended setup leaves checkout unchanged. Enable
the supported checkout checks after testing complete sandbox orders with your site’s
payment methods.

### Are rate limits and activity logs included in Free?

Free shows aggregate blocked-attempt totals. Configurable attempt limits, Light/
Balanced/Strict presets and detailed local activity history are Pro features.

### Does Gate House work without WooCommerce?

Yes. Native WordPress login, registration, password-reset and comment checks work
independently of WooCommerce.

### Does form discovery protect every form plugin?

No. Discovery reports known form entry points and adapter coverage. Free protects
its supported native WordPress and WooCommerce forms. Other form plugins need an
implemented adapter; Contact Form 7 support is in Pro.

### Does Free expire?

No. Free protection needs no Gate House license or account.

### Can I install this over the older complete paid plugin?

Back up the site. Update the complete legacy edition to 1.17.0, then install or 
update the standalone Gate House Pro add-on to 1.17.0 and activate it before migrating
the base. Turn off Delete data on uninstall in the existing settings. Install and
activate the branded Free package as gate-house-spam-protection-captcha/gate-house-
spam-protection-captcha.php while keeping Pro active. The new base waits while the
old base protects the site. On the Plugins page, use Switch to this installation
in the new Gate House row after its compatibility checks pass. Verify your settings
and real visitor journeys. Never uninstall the old base as a migration step; existing
settings, keys, licensing and restrictions keep their original storage identifiers.
A Free-only replacement would omit advanced protections.

### How do I move from an earlier Gate House folder?

Back up the site and, if you use Pro, update and activate Pro 1.17.0 first. Turn
off Delete data on uninstall. Install and activate this package alongside the earlier
gate-house/gate-house.php or gatehouse-spam-protection-captcha/gatehouse-spam-protection-
captcha.php installation; the earlier installation continues protecting the site
until you choose Switch to this installation on the Plugins page. Follow its compatibility
checks, retain the inactive earlier folder and verify real visitor journeys. Never
uninstall the earlier base as part of the switch.

### What does the connection test prove?

It verifies a fresh provider challenge. It does not certify your theme, payment 
gateway or every form. Test your real visitor journeys separately.

### How do I recover access?

Set GATE_HOUSE_RECOVERY_MODE=true in server-side wp-config.php. There is no public
bypass URL.

### Are orders or accounts deleted?

No. Uninstall retains plugin-owned data unless its explicit deletion setting is 
enabled.

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“Gate House – Spam Protection & CAPTCHA” is open source software. The following 
people have contributed to this plugin.

Contributors

 *   [ gatehousewp ](https://profiles.wordpress.org/gatehousewp/)

[Translate “Gate House – Spam Protection & CAPTCHA” into your language.](https://translate.wordpress.org/projects/wp-plugins/gate-house-spam-protection-captcha)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/gate-house-spam-protection-captcha/),
check out the [SVN repository](https://plugins.svn.wordpress.org/gate-house-spam-protection-captcha/),
or subscribe to the [development log](https://plugins.trac.wordpress.org/log/gate-house-spam-protection-captcha/)
by [RSS](https://plugins.trac.wordpress.org/log/gate-house-spam-protection-captcha/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 1.20.1

Marks the atomic settings write as a reviewed direct database query, clearing the
last Plugin Check warning. No behavior or stored-data changes.

#### 1.20.0

Retires the remaining short-prefix names: front-end markup, submitted form fields,
error codes, the held-order status and the notice parameter now use the unique gate_house/
gate-house names, and orders held under the earlier status move automatically. The
old wp usp command alias and the USP_RECOVERY_MODE, USP_SITE_KEY and USP_SECRET_KEY
wp-config fallbacks are removed; use the GATE_HOUSE_ names. If you use Gate House
Pro, update it together with this plugin: Pro 1.20.0 or later is required.

#### 1.19.0

Addresses WordPress.org review feedback. Stored data, hooks, scripts, capabilities
and database tables now use the unique gate_house prefix instead of a short one,
and earlier settings, provider connection state, coverage evidence and administrator
access are copied forward automatically on first load (the originals are left in
place). The Protection Test builds the login URL with wp_login_url() and no longer
touches submitted form data. If you use Gate House Pro, update it together with 
this plugin: Pro 1.19.0 or later is required.

#### 1.18.1

Uses WordPress.org language packs for Free translations and omits bundled translation
catalogs and the explicit translation loader. Package checks guard against bundled
translations returning. Existing settings and protection behavior are preserved.

#### 1.18.0

Gate House Pro can now protect WPForms forms (verified against WPForms Lite 2.0.2.1).
With Pro active, every WPForms form gets the same per-form check ladder (Off, Invisible,
Human check) and rate limits as the built-in forms; a blocked attempt surfaces as
WPForms’ own error and stores nothing. The Coverage tab’s entry-points card counts
WPForms forms and reports them covered with Pro, and says plainly that no adapter
is available yet without it. This update contains the base-side wiring; the adapter
itself ships in the Pro add-on of the same version.

#### 1.17.0

Base compatibility for separately consented Cloud rule lists; existing Free protection
and local settings are preserved.

#### 1.16.0

Compatible settings support for separately consented Cloud templates. The assigned
WordPress.org identity and existing settings are preserved.

#### 1.15.2

Uses the WordPress.org-assigned gate-house-spam-protection-captcha directory, entrypoint
and shared translation domain. Preserves safe migration from earlier installation
folders, existing settings and the WooCommerce checkout extension contract.

#### 1.15.1

Introduces the public title Gate House – Spam Protection & CAPTCHA and the matching
directory identity. Clarifies Free form protection, keyless setup, checkout opt-
in and optional Pro controls while preserving existing settings and the checkout
extension contract.

#### 1.15.0

Uses the branded gate-house directory, entrypoint and text domain for the WordPress.
org candidate. Preserves existing settings and data, with an explicit Pro-first 
migration from older installations.

#### 1.14.1

Prepares the Free edition for WordPress.org review with contributor metadata, explicit
external-service disclosures and reproducible asset-build instructions. Enqueues
the recovery helper through WordPress, improves translation extraction, and guards
direct file access. Keeps the existing plugin identity and separate Pro and legacy
distributions.

#### 1.14.0

Introduces separate Free and Pro distribution, preserves the legacy complete-product
update channel, and removes anonymous Gate House store requests. Existing product
history remains in CHANGELOG.md.

## Meta

 *  Version **1.20.1**
 *  Last updated **1 day ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 7.1 or higher **
 *  Tested up to **7.1.3**
 *  PHP version ** 8.1 or higher **
 * Tags
 * [anti-spam](https://wordpress.org/plugins/tags/anti-spam/)[captcha](https://wordpress.org/plugins/tags/captcha/)
   [recaptcha](https://wordpress.org/plugins/tags/recaptcha/)[turnstile](https://wordpress.org/plugins/tags/turnstile/)
   [woocommerce](https://wordpress.org/plugins/tags/woocommerce/)
 *  [Advanced View](https://wordpress.org/plugins/gate-house-spam-protection-captcha/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/gate-house-spam-protection-captcha/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/gate-house-spam-protection-captcha/reviews/)

## Contributors

 *   [ gatehousewp ](https://profiles.wordpress.org/gatehousewp/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/gate-house-spam-protection-captcha/)