{"id":294066,"date":"2026-08-10T16:38:17","date_gmt":"2026-08-10T16:38:17","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/puzzle-shield-login\/"},"modified":"2026-08-10T16:46:14","modified_gmt":"2026-08-10T16:46:14","slug":"human-verification-brain-puzzle-for-login-security-guard","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/human-verification-brain-puzzle-for-login-security-guard\/","author":17705928,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.1.0","stable_tag":"trunk","tested":"7.0.3","requires":"5.8","requires_php":"7.4","requires_plugins":null,"header_name":"Human Verification Brain Puzzle For Login Security Guard","header_author":"Kamrul Islam","header_description":"Protects the WordPress login page with a simple 3\u00d73 Sudoku puzzle. Users must solve the puzzle before they can log in.","assets_banners_color":"063086","last_updated":"2026-08-10 16:46:14","external_support_url":"","external_repository_url":"","donate_link":"https:\/\/codewithkamrul.com\/","header_plugin_uri":"https:\/\/wordpress.org\/plugins\/human-verification-brain-puzzle-for-login-security-guard\/","header_author_uri":"https:\/\/codewithkamrul.com\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":70,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0":{"tag":"1.0","author":"kamrulislam0093","date":"2026-08-10 16:38:08"}},"upgrade_notice":{"1.1.0":"<p>Security hardening: the puzzle answer is no longer exposed to the browser and PHP sessions are no longer used. No action required.<\/p>","1.0.0":"<p>Initial release \u2014 no upgrade steps required.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3640904,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3640904,"resolution":"256x256","location":"assets","locale":"","width":866,"height":866}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3640904,"resolution":"1544x500","location":"assets","locale":"","width":2203,"height":714},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3640904,"resolution":"772x250","location":"assets","locale":"","width":2203,"height":714}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3640904,"resolution":"1","location":"assets","locale":"","width":1008,"height":1560}},"screenshots":{"1":"The login page with the 3\u00d73 puzzle."}},"plugin_section":[],"plugin_tags":[362,602,600,599],"plugin_category":[38,44,54],"plugin_contributors":[224302],"plugin_business_model":[],"class_list":["post-294066","plugin","type-plugin","status-publish","hentry","plugin_tags-captcha","plugin_tags-login","plugin_tags-security","plugin_tags-spam","plugin_category-authentication","plugin_category-discussion-and-community","plugin_category-security-and-spam-protection","plugin_contributors-kamrulislam0093","plugin_committers-kamrulislam0093"],"banners":{"banner":"https:\/\/ps.w.org\/human-verification-brain-puzzle-for-login-security-guard\/assets\/banner-772x250.png?rev=3640904","banner_2x":"https:\/\/ps.w.org\/human-verification-brain-puzzle-for-login-security-guard\/assets\/banner-1544x500.png?rev=3640904","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/human-verification-brain-puzzle-for-login-security-guard\/assets\/icon-128x128.png?rev=3640904","icon_2x":"https:\/\/ps.w.org\/human-verification-brain-puzzle-for-login-security-guard\/assets\/icon-256x256.png?rev=3640904","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/human-verification-brain-puzzle-for-login-security-guard\/assets\/screenshot-1.png?rev=3640904","caption":"The login page with the 3\u00d73 puzzle."}],"raw_content":"<!--section=description-->\n<p><strong>Human Verification Brain Puzzle For Login Security Guard<\/strong> replaces the traditional CAPTCHA with a lightweight, accessible 3\u00d73 puzzle on the WordPress login page. Users must correctly complete the puzzle before the Log In button becomes active. The answer is also verified server-side, so it cannot be bypassed by disabling JavaScript.<\/p>\n\n<h4>How it works<\/h4>\n\n<ol>\n<li>A random 3\u00d73 puzzle is displayed on the login page.<\/li>\n<li>Each row and each column must contain the digits 1, 2, and 3 exactly once.<\/li>\n<li>Click (or tap) an empty cell to select it, then pick a number from the picker \u2014 or press <strong>1<\/strong>, <strong>2<\/strong>, or <strong>3<\/strong> on your keyboard.<\/li>\n<li>Once the puzzle is solved correctly, the <strong>Log In<\/strong> button becomes clickable.<\/li>\n<li>The answer is validated server-side on submission for extra security.<\/li>\n<\/ol>\n\n<h4>Features<\/h4>\n\n<ul>\n<li>6 built-in puzzle variations chosen at random each visit.<\/li>\n<li>Client-side validation with instant feedback (wrong cells highlighted in red).<\/li>\n<li>Server-side answer verification \u2014 cannot be bypassed without JavaScript.<\/li>\n<li>WP nonce protection against CSRF attacks.<\/li>\n<li>Accessible: full keyboard navigation, ARIA roles and labels, <code>aria-live<\/code> status region.<\/li>\n<li>No external requests \u2014 no JavaScript frameworks or CDN dependencies.<\/li>\n<li>Tiny footprint: one CSS file, one JS file, one PHP class.<\/li>\n<li>Fully translatable via standard WordPress i18n functions.<\/li>\n<li>Matches native WordPress login page styling.<\/li>\n<li>Works on the standard <code>wp-login.php<\/code> screen, the WooCommerce \"My Account\" login form, and the MemberPress login form.<\/li>\n<\/ul>\n\n<h4>Privacy<\/h4>\n\n<p>This plugin is stateless \u2014 it does not use PHP sessions, cookies, or any database storage. The puzzle shown to a visitor is bound to a signed WordPress nonce embedded in the form itself. No personal data is stored or transmitted to third parties.<\/p>\n\n<!--section=installation-->\n<h4>Automatic installation<\/h4>\n\n<ol>\n<li>Log in to your WordPress admin panel.<\/li>\n<li>Go to <strong>Plugins \u2192 Add New<\/strong>.<\/li>\n<li>Search for <strong>Human Verification Brain Puzzle For Login Security Guard<\/strong>.<\/li>\n<li>Click <strong>Install Now<\/strong>, then <strong>Activate<\/strong>.<\/li>\n<\/ol>\n\n<h4>Manual installation<\/h4>\n\n<ol>\n<li>Download the plugin <code>.zip<\/code> file.<\/li>\n<li>Upload and extract the <code>human-verification-brain-puzzle-for-login-security-guard<\/code> folder to <code>\/wp-content\/plugins\/<\/code>.<\/li>\n<li>Go to <strong>Plugins \u2192 Installed Plugins<\/strong> in your WordPress admin and activate the plugin.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"will%20this%20stop%20all%20bots%3F\"><h3>Will this stop all bots?<\/h3><\/dt>\n<dd><p>Human Verification Brain Puzzle For Login Security Guard significantly raises the bar for automated login attacks compared to a simple username\/password form. It is not intended to replace a full security suite \u2014 it works best alongside strong passwords and two-factor authentication.<\/p><\/dd>\n<dt id=\"is%20it%20accessible%3F\"><h3>Is it accessible?<\/h3><\/dt>\n<dd><p>Yes. Every interactive element has ARIA roles and labels, keyboard navigation is fully supported, and status messages are announced via an <code>aria-live<\/code> region.<\/p><\/dd>\n<dt id=\"does%20it%20work%20with%20custom%20login%20pages%3F\"><h3>Does it work with custom login pages?<\/h3><\/dt>\n<dd><p>The plugin hooks into the standard <code>login_form<\/code> action and <code>authenticate<\/code> filter for <code>wp-login.php<\/code>, plus <code>woocommerce_login_form<\/code> (WooCommerce \"My Account\" login) and <code>mepr-login-form-before-submit<\/code> (MemberPress login) so the puzzle appears and is enforced on those forms too. Custom login page plugins that call <code>do_action('login_form')<\/code> inside their form will also work.<\/p><\/dd>\n<dt id=\"can%20i%20add%20my%20own%20puzzles%3F\"><h3>Can I add my own puzzles?<\/h3><\/dt>\n<dd><p>Not through the admin UI in this release. Developers can filter the puzzles array by modifying the class \u2014 a settings screen and puzzle filter hook are planned for v2.<\/p><\/dd>\n<dt id=\"does%20it%20conflict%20with%20other%20security%20plugins%3F\"><h3>Does it conflict with other security plugins?<\/h3><\/dt>\n<dd><p>The plugin uses standard WordPress hooks at conventional priority levels and does not modify the database schema. It has been tested alongside Wordfence and iThemes Security without conflicts.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>Security: the puzzle solution is no longer sent to the browser \u2014 client-side feedback now relies on local row\/column conflict detection instead of exposing the answer in page source.<\/li>\n<li>Security: removed PHP session usage entirely in favor of a stateless, nonce-based puzzle token, avoiding the cache\/session conflicts native PHP sessions can cause on WordPress hosting.<\/li>\n<li>A new random puzzle is now shown on every page load\/reload, not just after a failed attempt.<\/li>\n<li>Added compatibility with the WooCommerce \"My Account\" login form.<\/li>\n<li>Added compatibility with the MemberPress login form.<\/li>\n<li>Fixed an incorrect ARIA label on empty puzzle cells.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release.<\/li>\n<\/ul>","raw_excerpt":"Protect your WordPress login page with a fun 3\u00d73 puzzle. Users must solve it before they can log in.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/294066","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=294066"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/kamrulislam0093"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=294066"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=294066"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=294066"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=294066"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=294066"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=294066"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}