Built from the open-source Securimage PHP Captcha, this plugin allows you to add CAPTCHA protection to your WordPress site. This plugin gives you the option to add CAPTCHA images to your comment, registration, login, and/or signup forms on your site. You can also add CAPTCHA protection to any post or page using a shortcode provided by the plugin.
The image appearance can be easily customized to match your site’s look and feel from the WordPress Settings menu.
Securimage-WP also has the ability to stream secure, high-quality, dynamic audio CAPTCHAs to visitors using HTML5 audio tags or Flash.
- Protect comment, registration, login, or lost password forms
- Shortcode support
- Customize code-length, image dimensions, colors and distortion factors from a menu
- Word or math based CAPTCHA images and audio
- Add a custom signature to your images
- Stream audio using HTML5 (compatible with mobile) with optional Flash fallback
- Easily add CSS classes and styles to the CAPTCHA inputs
- Select the sequence of the CAPTCHA inputs to match your site layout
- Allows pingbacks and trackbacks, and replies from administration panel
- Doesn’t require cookies or PHP session support; codes are stored in the WordPress database
- Works with BuddyPress
- Contact Form 7 Integration – Add Securimage to your CF7 forms with the [securimage_wp] tag
- Formidable Forms integration – Add Securimage with a single click
- Supports multiple captchas on a single post or page
- WordPress 3.0 or greater
- Requires PHP 5.2+ with GD and FreeType
About This Plugin:
This plugin was developed by Drew Phillips, the developer of Securimage PHP CAPTCHA. Securimage is completely free and open-source for the community and your use, as is this WordPress plugin. If you find either of these things useful, please consider donating. Thank you for using this plugin!
Installation of Securimage-WP is simple.
- From the
Add Newand then
Upload. Select the .zip file containing Securimage-WP. Alternatively, you can upload the
securimage-wpdirectory to your
- Activate the plugin through the ‘Plugins’ menu in WordPress.
- Customize the CAPTCHA options from
Securimage-WPunder the WordPress
- What are the requirements?
If you install Securimage-WP, there is a test script that will tell you whether or not your system meets the requirements.
- The CAPTCHA image appears broken
From the Securimage-WP settings menu, enable the
Debug Image Errorsoption, save the settings, and then click the link labeled
View Image Directly. Ideally, this will reveal any error messages that may be causing the image generation to fail. Try to troubleshoot the error, or contact us for assistance.
- Can I display a CAPTCHA somewhere other than the comment or registration forms?
Yes, since version 3.6.1 you can display a captcha using the shortcode
[siwp_show_captcha]anywhere on your WordPress site.
To validate the user’s input, call the function siwp_check_captcha. Note: To validate from a WordPress page, you will need a plugin like Exec-PHP installed, or your PHP form processor needs to hook into WordPress (typically by including wp-load.php from your PHP script).
See here for an example WordPress page with a simple form and captcha with validation.
- I enabled the captcha on my comment form, registration page, login form, or lost password form but no captcha image appears
Securimage-WP relies on some standard function hooks for displaying the CAPTCHA. If the image doesn’t appear on your site’s forms, it may be due to those templates not implementing the proper hooks.
To fix this, you can either edit your templates to include the proper hooks, or if the site uses a custom registration page, use the
[siwp_show_captcha]shortcode on your registration form.
For the comment form, the proper hook needed is
<?php do_action( 'comment_form', $post_id ); ?>
For the registration form, the proper hook needed is
<?php do_action( 'register_form' ); ?>
The calls to these actions should go in the template where you want the CAPTCHA image to appear.
- How to install audio files for CAPTCHA audio
Automatic installation of audio files may not work for a number of reasons (e.g. directories not writable by the server, http wrapper not enabled for fopen/file_get_contents, low memory limits) but this does not mean audio files cannot be used.
If automatic installation is not available, audio files can be downloaded from https://www.phpcaptcha.org/download and manually placed in the Securimage-WP plugin directory.
To install audio files, extract the contents of the language pack you wish to use to the
wp-content/plugins/securimage-wp/libdirectory preserving the directory structure from the audio package (so the resulting directories are
- Audio FAQ/General Info
Since version 3.6.4 HTML5 audio is used for better browser support without the need for plugins. Consider the following when using HTML5 audio streaming:
- Audio files are generated in WAV format which is supported by all browsers except Internet Explorer
- To support Internet Explorer 9+ using HTML5 audio, audio files can be streamed in MP3 format if the LAME MP3 encoder is installed on the system
- To support older browsers without HTML5 audio capability, optional Flash fallback can be used
- If LAME is not available, browsers that don’t support WAV or HTML5 audio, Flash fallback will be used, or if disabled, the audio button will be hidden
- If possible, install LAME for MP3 output since the resulting audio files are smaller and will use less bandwidth (average 30-60 KB versus 200-300 KB for WAV files)
- To install LAME on Windows, download the LAME bundle from RareWares (http://www.rarewares.org/mp3-lame-bundle.php)
- To install LAME on Linux, either compile from source or install using your package manager (e.g. Debian/Ubuntu: apt-get install lame; CentOS: yum install lame)
- Securimage-WP needs to know where LAME is installed on your system which is configured from the Securimage-WP settings menu
- The refresh button does not work
- I noticed the image refresh by itself when I was looking at my comment form
CAPTCHA codes have expiration times in order to reduce the amount of time spammers have to break the CAPTCHA. The default time is 15 minutes. After this time lapses, the CAPTCHA refreshes since it is no longer valid. You can customize this setting in the options menu.
Drew is quick to patch as needed, plugin works well.
Drew is incredible. I asked him about formidable forms compatibility as this captcha has an incredible visual wow factor and within a couple of days he created a new version with a solution at a time/holiday when everyone else is taking off work.
Contributors & Developers
“Securimage-WP” is open source software. The following people have contributed to this plugin.Contributors
- Fix warning in securimage-wp.php – can’t use return value in write context
- Upgrade Securimage library to 4.0
- Switch over to Securimage WordPress storage adapter for database access
- Test with WordPress 4.7 and 4.8-alpha
- Add Contact Form 7 integration. Easily add Securimage-WP to your CF7 forms
- Add Formidable forms integration. Easily add Securimage-WP to Formidable Forms
- Fix messages emitted from PHP 5.3 strict standards
- Fix errors with wp_enqueue_script and wp_enqueue_style calls
- WordPress 4.4 fix – enqueue audio script on login page if audio enabled
- Fix audio streaming on iOS devices; upgrade Securimage library to 3.6.2
- Fix tabindex on audio play button so it is excluded
- Add Spanish and Chilean Spanish language to available audio languages
- HTML5 audio support
- Ability to stream audio as MP3 (requires LAME encoder, see FAQ)
- Compatibility with BuddyPress registration form
- Disable audio by default and remove audio files from distribution
- Automatic language pack installation from plugin options page
- Add options to protect login and lost password forms
- Add plugin stats (number of captchas displayed, passed, and failed)
- Cleanup/improve options page
[siwp_show_captcha]shortcode for displaying a captcha in any WordPress post or page
- Add option to protect site registration form
- WordPress 4.2 compatibility
- Confirm compatibilty with WordPress 4.1.1
- Upgrade Securimage code to 3.5.4
- Fix potential XSS vulnerability in siwp_test.php
- Upgrade Securimage library to latest version
- Initial release of WordPress plugin