{"id":348447,"date":"2026-08-14T09:30:49","date_gmt":"2026-08-14T09:30:49","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/captchaflow-universal-form-protection\/"},"modified":"2026-08-15T11:47:18","modified_gmt":"2026-08-15T11:47:18","slug":"templatesell-captchaflow","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/templatesell-captchaflow\/","author":14952961,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.1.1","stable_tag":"1.1.1","tested":"7.0.4","requires":"6.5","requires_php":"7.4","requires_plugins":null,"header_name":"CaptchaFlow \u2013 CAPTCHA & Spam Protection for Forms","header_author":"TemplateSell","header_description":"Protect Contact Form 7, Elementor, WooCommerce, WPForms, Gravity Forms, Fluent Forms, login, registration, comments, and more using Google reCAPTCHA, Cloudflare Turnstile, hCaptcha, and intelligent spam protection.","assets_banners_color":"c8e5e1","last_updated":"2026-08-15 11:47:18","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/templatesell.net\/captchaflow\/","header_author_uri":"https:\/\/templatesell.net\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":43,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"templatesell","date":"2026-08-14 09:30:24"},"1.1.0":{"tag":"1.1.0","author":"templatesell","date":"2026-08-14 14:18:36"},"1.1.1":{"tag":"1.1.1","author":"templatesell","date":"2026-08-15 11:47:18"}},"upgrade_notice":{"1.1.1":"<p>Recommended for everyone. Fixes a bug where a mis-registered reCAPTCHA key could lock administrators out of wp-login.php, and protects forms that load after the page does.<\/p>","1.1.0":"<p>Adds a Pro information screen in the admin. Form protection, providers, and visitor-data handling are unchanged.<\/p>","1.0.0":"<p>Initial release.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3647044,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3647044,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256},"icon.svg":{"filename":"icon.svg","revision":3647044,"resolution":false,"location":"assets","locale":false}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3647044,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3647044,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.0","1.1.0","1.1.1"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3647044,"resolution":"1","location":"assets","locale":"","width":2560,"height":1536},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3647044,"resolution":"2","location":"assets","locale":"","width":2560,"height":1956},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3647044,"resolution":"3","location":"assets","locale":"","width":2560,"height":1536},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3647044,"resolution":"4","location":"assets","locale":"","width":2560,"height":1536},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3647044,"resolution":"5","location":"assets","locale":"","width":2560,"height":1536},"screenshot-6.png":{"filename":"screenshot-6.png","revision":3647044,"resolution":"6","location":"assets","locale":"","width":2560,"height":1536}},"screenshots":{"1":"Dashboard \u2014 protection status, blocked-spam counters, and a 30-day trend.","2":"Setup wizard \u2014 protected in under a minute.","3":"Forms \u2014 every detected form source with one protect-all switch.","4":"Provider \u2014 challenge cards with plain-language trade-offs and key testing.","5":"Tools \u2014 one-click diagnostics and the theme compatibility checker.","6":"Dark mode \u2014 the whole admin, at night."}},"plugin_section":[],"plugin_tags":[2656,362,595,2419,214603],"plugin_category":[38,44,54],"plugin_contributors":[192103],"plugin_business_model":[],"class_list":["post-348447","plugin","type-plugin","status-publish","hentry","plugin_tags-anti-spam","plugin_tags-captcha","plugin_tags-recaptcha","plugin_tags-spam-protection","plugin_tags-turnstile","plugin_category-authentication","plugin_category-discussion-and-community","plugin_category-security-and-spam-protection","plugin_contributors-templatesell","plugin_committers-templatesell"],"banners":{"banner":"https:\/\/ps.w.org\/templatesell-captchaflow\/assets\/banner-772x250.png?rev=3647044","banner_2x":"https:\/\/ps.w.org\/templatesell-captchaflow\/assets\/banner-1544x500.png?rev=3647044","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":"https:\/\/ps.w.org\/templatesell-captchaflow\/assets\/icon.svg?rev=3647044","icon":"https:\/\/ps.w.org\/templatesell-captchaflow\/assets\/icon.svg?rev=3647044","icon_2x":false,"generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/templatesell-captchaflow\/assets\/screenshot-1.png?rev=3647044","caption":"Dashboard \u2014 protection status, blocked-spam counters, and a 30-day trend."},{"src":"https:\/\/ps.w.org\/templatesell-captchaflow\/assets\/screenshot-2.png?rev=3647044","caption":"Setup wizard \u2014 protected in under a minute."},{"src":"https:\/\/ps.w.org\/templatesell-captchaflow\/assets\/screenshot-3.png?rev=3647044","caption":"Forms \u2014 every detected form source with one protect-all switch."},{"src":"https:\/\/ps.w.org\/templatesell-captchaflow\/assets\/screenshot-4.png?rev=3647044","caption":"Provider \u2014 challenge cards with plain-language trade-offs and key testing."},{"src":"https:\/\/ps.w.org\/templatesell-captchaflow\/assets\/screenshot-5.png?rev=3647044","caption":"Tools \u2014 one-click diagnostics and the theme compatibility checker."},{"src":"https:\/\/ps.w.org\/templatesell-captchaflow\/assets\/screenshot-6.png?rev=3647044","caption":"Dark mode \u2014 the whole admin, at night."}],"raw_content":"<!--section=description-->\n<p>\ud83d\udee1\ufe0f <strong>Stop form spam across your whole site with one switch<\/strong><\/p>\n\n<p><strong>CaptchaFlow<\/strong> protects every form on your WordPress site with one switch. Choose a CAPTCHA provider \u2014 or a self-hosted challenge that needs no signup at all \u2014 and CaptchaFlow attaches it to your login page, comment form, checkout, and every supported form plugin automatically. No template editing, no per-form configuration, no code.<\/p>\n\n<p>\ud83d\udd17 <a href=\"https:\/\/templatesell.net\/captchaflow\/\">Plugin home<\/a> \u00b7 <a href=\"https:\/\/templatesell.net\/captchaflow\/demo\/\">Live demo<\/a> \u00b7 <a href=\"https:\/\/templatesell.net\/captchaflow\/features\/\">All features<\/a> \u00b7 <a href=\"https:\/\/templatesell.net\/captchaflow\/docs\/\">Documentation<\/a> \u00b7 <a href=\"https:\/\/templatesell.net\/captchaflow\/faq\/\">FAQ<\/a> \u00b7 <a href=\"https:\/\/templatesell.net\/captchaflow\/changelog\/\">Changelog<\/a><\/p>\n\n<h4>\ud83e\uddea Try it before you install it<\/h4>\n\n<p>You do not have to take any of this on trust. There is a <a href=\"https:\/\/templatesell.net\/captchaflow\/demo\/\">live demo<\/a> that runs in your browser with nothing to install:<\/p>\n\n<ul>\n<li>Answer a math or question challenge and watch the submission pass.<\/li>\n<li>Press <strong>Submit like a bot<\/strong> and watch the honeypot stop it, with the same reason code the plugin writes to your activity log.<\/li>\n<li>Submit instantly and watch the timing trap catch it.<\/li>\n<li>Load a Cloudflare Turnstile, reCAPTCHA or hCaptcha widget \u2014 only if you choose to; nothing third-party loads until you press a button that names the host.<\/li>\n<\/ul>\n\n<h4>\u2728 Why choose CaptchaFlow?<\/h4>\n\n<p>\ud83e\udde9 <strong>Every Form, One Switch<\/strong> \u2013 CaptchaFlow detects the forms on your site and protects them all. New forms are covered the moment you create them.<\/p>\n\n<p>\ud83e\udea4 <strong>Three Layers on Every Submission<\/strong> \u2013 A honeypot field with a randomized name, a time trap that catches inhumanly fast submissions, and your chosen challenge. Obvious bots are rejected by the first two layers without ever reaching your provider, which keeps your pages fast and your provider quota low.<\/p>\n\n<p>\ud83c\udf9b\ufe0f <strong>Six Challenge Types<\/strong> \u2013 Cloudflare Turnstile, Google reCAPTCHA v2 and v3, hCaptcha, or a self-hosted Math or Question challenge that needs no account at all.<\/p>\n\n<p>\u26a1 <strong>Built for Fast Sites<\/strong> \u2013 Zero assets on pages without a protected form, a dependency-free public script under 3 KB compressed, and under 5 ms of server time per verification.<\/p>\n\n<p>\ud83d\uddc4\ufe0f <strong>Works With Page Caching<\/strong> \u2013 Challenge data is never baked into cached HTML, so a cached page stays correct for every visitor.<\/p>\n\n<p>\ud83d\udd12 <strong>Privacy First<\/strong> \u2013 No telemetry, no account, and nothing sent to us. IP addresses are shortened before logging and email addresses stored only as one-way hashes.<\/p>\n\n<p>\ud83e\ude7a <strong>Diagnostics You Can Trust<\/strong> \u2013 One click tests your keys, latency, REST, cron, and cache setup, and warns you before another plugin double-injects a CAPTCHA.<\/p>\n\n<p>\ud83c\udf0d <strong>Translation Ready<\/strong> \u2013 Every string is translatable, a POT file ships with the plugin, and the admin fully supports RTL languages.<\/p>\n\n<p>\u267f <strong>Accessible by Default<\/strong> \u2013 Challenges are keyboard-operable, labelled for screen readers, and respect reduced-motion preferences. The no-JavaScript fallback is plain accessible HTML.<\/p>\n\n<p>\ud83e\uddd1\u200d\ud83d\udcbb <strong>Developer Friendly<\/strong> \u2013 Documented hooks and filters, a PHP SDK for custom forms, and a CSS-selector adapter for anything hand-built.<\/p>\n\n<h4>\ud83d\udccb Supported forms<\/h4>\n\n<ul>\n<li>WordPress login, registration, password reset, and comments<\/li>\n<li>WooCommerce login, registration, and password reset<\/li>\n<li>Contact Form 7<\/li>\n<li>WPForms<\/li>\n<li>Fluent Forms<\/li>\n<li>Forminator<\/li>\n<li>Ninja Forms<\/li>\n<li>Gravity Forms<\/li>\n<li>Elementor Pro forms<\/li>\n<li>Any other form, via a CSS selector<\/li>\n<\/ul>\n\n<h4>\ud83d\udd10 Supported challenges<\/h4>\n\n<ul>\n<li><strong>Cloudflare Turnstile<\/strong> \u2014 free, privacy-friendly, usually invisible (recommended)<\/li>\n<li><strong>Google reCAPTCHA v2<\/strong> \u2014 the familiar checkbox<\/li>\n<li><strong>Google reCAPTCHA v3<\/strong> \u2014 invisible, score-based<\/li>\n<li><strong>hCaptcha<\/strong> \u2014 privacy-focused alternative<\/li>\n<li><strong>Math challenge<\/strong> \u2014 a simple sum; no account, no external service<\/li>\n<li><strong>Question challenge<\/strong> \u2014 your own question and answer; no external service<\/li>\n<\/ul>\n\n<h4>\u23f1\ufe0f 60-second setup<\/h4>\n\n<p>Activate the plugin, pick a challenge in the setup wizard, paste your keys (or skip that step with a self-hosted challenge), and you are protected. The wizard ends with a live test so you can see your site issuing challenges before you close it.<\/p>\n\n<p>Step-by-step guides for every provider are in the <a href=\"https:\/\/templatesell.net\/captchaflow\/docs\/\">documentation<\/a>.<\/p>\n\n<h4>\ud83d\udd0f Privacy first<\/h4>\n\n<p>CaptchaFlow sends no data to us \u2014 there is no phoning home, no telemetry, and no account. The only external requests are the verification calls to the CAPTCHA provider you choose, and the self-hosted Math and Question challenges make no external requests at all. Visitor email addresses are stored only as one-way hashes in your own database, and the event log trims itself on the schedule you set.<\/p>\n\n<p>Visitor IP addresses are shortened to the network they came from before they are logged \u2014 enough to spot a flood from one place, not enough to single out a person. You can turn that off if you need exact addresses for investigating abuse. CaptchaFlow also writes suggested wording for your privacy policy that describes your actual configuration, and plugs into Tools \u2192 Export Personal Data and Erase Personal Data so a visitor's request covers the spam log too.<\/p>\n\n<p>CaptchaFlow uses the official public APIs of Cloudflare Turnstile, Google reCAPTCHA, and hCaptcha. Those names are trademarks of their respective owners; CaptchaFlow is not affiliated with or endorsed by Cloudflare, Google, or Intuition Machines.<\/p>\n\n<h4>\ud83e\ude7a Diagnostics you can trust<\/h4>\n\n<p>One click runs a full self-test: provider reachability and key validity with round-trip latency, REST availability, cron health, cache-plugin detection with copy-paste exclusion rules, and a curated list of plugins known to double-inject CAPTCHAs. Export the whole report as text and attach it to a support ticket.<\/p>\n\n<h4>\ud83d\ude80 CaptchaFlow Pro<\/h4>\n\n<p>Everything above is free and stays free. Pro is for sites where spam has stopped being accidental \u2014 <a href=\"https:\/\/templatesell.net\/captchaflow\/pricing\/\">see the full comparison and pricing<\/a>.<\/p>\n\n<p>\ud83d\udea6 <strong>Rate Limiting &amp; IP Firewall<\/strong> \u2013 Throttle repeat submitters with a sliding window, and block or allow individual addresses and whole countries.<\/p>\n\n<p>\ud83d\udce7 <strong>Email &amp; Phone Validation<\/strong> \u2013 Reject disposable mailboxes and malformed numbers before they reach your inbox or your CRM.<\/p>\n\n<p>\ud83e\udde0 <strong>Behaviour Analysis &amp; Spam Scoring<\/strong> \u2013 Every submission is scored on how it was filled in, so borderline cases are challenged instead of silently allowed.<\/p>\n\n<p>\ud83c\udf10 <strong>Country Rules &amp; Conditional Challenges<\/strong> \u2013 Ask for a harder challenge only where abuse actually comes from, and leave everyone else undisturbed.<\/p>\n\n<p>\ud83d\uded2 <strong>WooCommerce Checkout &amp; Review Protection<\/strong> \u2013 Extends protection to checkout and product reviews, where store spam actually costs you money.<\/p>\n\n<p>\ud83d\udcca <strong>Analytics, Alerts &amp; Health Reports<\/strong> \u2013 See what is being blocked and why, and get told when something changes rather than finding out later.<\/p>\n\n<p>\ud83d\udd0c <strong>Developer API, Webhooks &amp; White Label<\/strong> \u2013 Hook verification into your own systems, and hand clients a plugin that carries your name.<\/p>\n\n<p>\ud83d\udca1 <strong>Recommendations &amp; Auto-Optimization<\/strong> \u2013 CaptchaFlow watches its own results and suggests the settings that would block more with less friction.<\/p>\n\n<p>Every Pro plan includes a 14-day trial with no card required.<\/p>\n\n<h3>External services<\/h3>\n\n<p>CaptchaFlow contacts an external service only when you have chosen a challenge that is hosted by one \u2014 Cloudflare Turnstile, Google reCAPTCHA v2, Google reCAPTCHA v3, or hCaptcha. If you choose the Math or Question challenge, CaptchaFlow makes no external requests at all and nothing on this list applies to your site.<\/p>\n\n<p>CaptchaFlow itself is not a service. It has no servers, no account, and no telemetry: nothing is ever sent to CaptchaFlow or to TemplateSell.<\/p>\n\n<h4>Cloudflare Turnstile<\/h4>\n\n<p>Used only when Turnstile is the selected challenge.<\/p>\n\n<ul>\n<li>The visitor's browser loads the challenge widget from https:\/\/challenges.cloudflare.com\/turnstile\/v0\/api.js on any page showing a protected form. Cloudflare receives whatever a browser sends when requesting a script, including the visitor's IP address and user agent.<\/li>\n<li>When the form is submitted, your server sends the challenge token, your Turnstile secret key, and the visitor's IP address to https:\/\/challenges.cloudflare.com\/turnstile\/v0\/siteverify to ask whether the challenge was passed. The request identifies your site in its user-agent string.<\/li>\n<li>The same verification endpoint is called with a dummy token when you test your keys on the Provider screen.<\/li>\n<\/ul>\n\n<p>Terms of service: https:\/\/www.cloudflare.com\/website-terms\/ \u2014 Privacy policy: https:\/\/www.cloudflare.com\/privacypolicy\/<\/p>\n\n<h4>Google reCAPTCHA (v2 and v3)<\/h4>\n\n<p>Used only when reCAPTCHA v2 or v3 is the selected challenge.<\/p>\n\n<ul>\n<li>The visitor's browser loads the challenge widget from https:\/\/www.google.com\/recaptcha\/api.js on any page showing a protected form. Google receives whatever a browser sends when requesting a script, including the visitor's IP address and user agent, and reCAPTCHA additionally observes visitor interaction in order to score the request.<\/li>\n<li>When the form is submitted, your server sends the challenge token, your reCAPTCHA secret key, and the visitor's IP address to https:\/\/www.google.com\/recaptcha\/api\/siteverify to ask whether the challenge was passed. The request identifies your site in its user-agent string.<\/li>\n<li>The same verification endpoint is called with a dummy token when you test your keys on the Provider screen.<\/li>\n<\/ul>\n\n<p>Terms of service: https:\/\/policies.google.com\/terms \u2014 Privacy policy: https:\/\/policies.google.com\/privacy<\/p>\n\n<h4>hCaptcha<\/h4>\n\n<p>Used only when hCaptcha is the selected challenge.<\/p>\n\n<ul>\n<li>The visitor's browser loads the challenge widget from https:\/\/js.hcaptcha.com\/1\/api.js on any page showing a protected form. hCaptcha receives whatever a browser sends when requesting a script, including the visitor's IP address and user agent.<\/li>\n<li>When the form is submitted, your server sends the challenge token, your hCaptcha secret key, and the visitor's IP address to https:\/\/api.hcaptcha.com\/siteverify to ask whether the challenge was passed. The request identifies your site in its user-agent string.<\/li>\n<li>The same verification endpoint is called with a dummy token when you test your keys on the Provider screen.<\/li>\n<\/ul>\n\n<p>Terms of service: https:\/\/www.hcaptcha.com\/terms \u2014 Privacy policy: https:\/\/www.hcaptcha.com\/privacy<\/p>\n\n<p>Cloudflare, Google, and hCaptcha are trademarks of their respective owners. CaptchaFlow is not affiliated with or endorsed by Cloudflare, Google, or Intuition Machines, and uses only each provider's official public API.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Install and activate CaptchaFlow from the Plugins screen.<\/li>\n<li>The setup wizard opens automatically. Choose a challenge \u2014 Cloudflare Turnstile if you want the least visitor friction, or the Math challenge if you don't want to create any account.<\/li>\n<li>Paste your site key and secret key if your challenge needs them. They are tested the moment you paste them.<\/li>\n<li>Leave \"Protect every form\" on, finish, and watch the live test pass.<\/li>\n<\/ol>\n\n<p>That is the whole setup. To fine-tune, the Forms screen lets you protect sources individually, and the Provider screen lets you switch challenges at any time.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"do%20i%20need%20a%20captcha%20account%3F\"><h3>Do I need a CAPTCHA account?<\/h3><\/dt>\n<dd><p>No. The Math and Question challenges run entirely on your own site with no signup. If you prefer Turnstile, reCAPTCHA, or hCaptcha, you create free keys with that provider and paste them in.<\/p><\/dd>\n<dt id=\"which%20captcha%20should%20i%20choose%3F\"><h3>Which CAPTCHA should I choose?<\/h3><\/dt>\n<dd><p>Cloudflare Turnstile for most sites: it is free, privacy-friendly, and most visitors never see a puzzle. Choose reCAPTCHA if you already use it elsewhere, hCaptcha if you want a privacy-focused alternative to Google, or a self-hosted challenge if you want no third-party service at all.<\/p><\/dd>\n<dt id=\"will%20it%20slow%20my%20site%20down%3F\"><h3>Will it slow my site down?<\/h3><\/dt>\n<dd><p>No. Pages without a protected form load zero CaptchaFlow assets. Pages with one load a single script under 3 KB compressed, and the provider connection is warmed up in advance. Server-side verification adds under 5 milliseconds.<\/p><\/dd>\n<dt id=\"does%20it%20work%20with%20caching%20plugins%3F\"><h3>Does it work with caching plugins?<\/h3><\/dt>\n<dd><p>Yes, by design. CaptchaFlow never puts visitor-specific data in your page HTML, so cached pages stay correct for every visitor. The challenge itself is fetched by the browser with caching disabled. The diagnostics screen detects your caching plugin and confirms the challenge endpoint is returning fresh responses through it.<\/p><\/dd>\n<dt id=\"does%20it%20work%20if%20a%20visitor%20has%20javascript%20disabled%3F\"><h3>Does it work if a visitor has JavaScript disabled?<\/h3><\/dt>\n<dd><p>Yes. Forms fall back to an accessible text challenge that works with no JavaScript at all.<\/p><\/dd>\n<dt id=\"what%20happens%20if%20my%20captcha%20provider%20goes%20down%3F\"><h3>What happens if my CAPTCHA provider goes down?<\/h3><\/dt>\n<dd><p>You decide. By default CaptchaFlow fails open: submissions are accepted rather than locking real visitors out, and the honeypot and time trap keep filtering bots. You can switch to fail closed in Settings if you prefer.<\/p><\/dd>\n<dt id=\"will%20it%20clash%20with%20the%20captcha%20built%20into%20my%20form%20plugin%3F\"><h3>Will it clash with the CAPTCHA built into my form plugin?<\/h3><\/dt>\n<dd><p>Run the built-in diagnostics: CaptchaFlow detects other CAPTCHA plugins and warns you before two challenges end up on one form. Disable the other CAPTCHA on forms CaptchaFlow protects.<\/p><\/dd>\n<dt id=\"can%20i%20protect%20a%20custom-coded%20form%3F\"><h3>Can I protect a custom-coded form?<\/h3><\/dt>\n<dd><p>Yes. Enter a CSS selector on the Forms screen and CaptchaFlow protects every matching form, including forms rendered by page builders or custom themes.<\/p><\/dd>\n<dt id=\"does%20it%20protect%20woocommerce%20checkout%3F\"><h3>Does it protect WooCommerce checkout?<\/h3><\/dt>\n<dd><p>The free plugin protects WooCommerce login, registration, and password reset. Checkout and order-related protection is part of CaptchaFlow Pro.<\/p><\/dd>\n<dt id=\"where%20do%20the%20spam%20statistics%20live%3F\"><h3>Where do the spam statistics live?<\/h3><\/dt>\n<dd><p>In your own database. The dashboard shows blocked totals for today, this week, this month, and a 30-day trend. Nothing is sent anywhere.<\/p><\/dd>\n<dt id=\"what%20data%20does%20captchaflow%20collect%20about%20my%20visitors%3F\"><h3>What data does CaptchaFlow collect about my visitors?<\/h3><\/dt>\n<dd><p>None for us, and almost none at all. Verification events are logged in your database for the retention period you choose (30 days by default), then deleted automatically. Each event records the time, which form it was, the verdict, a one-way hash of the submitter's email address, and their IP address shortened to its network. The address itself is never stored.<\/p><\/dd>\n<dt id=\"is%20it%20gdpr-friendly%3F\"><h3>Is it GDPR-friendly?<\/h3><\/dt>\n<dd><p>It is built to be. Visitor IP addresses are shortened before they are logged, email addresses are stored only as one-way hashes, and nothing is sent to us. Under Settings \u2192 Privacy you will find suggested policy wording generated from your actual configuration \u2014 a site using only the Math or Question challenge is told, correctly, that nothing leaves it; a site using an external provider gets that provider named with a link to its policy. Export and erasure requests made through Tools \u2192 Export Personal Data and Erase Personal Data include the spam log automatically.<\/p><\/dd>\n<dt id=\"what%20happens%20to%20my%20spam%20statistics%20when%20someone%20asks%20to%20be%20erased%3F\"><h3>What happens to my spam statistics when someone asks to be erased?<\/h3><\/dt>\n<dd><p>They stay accurate. Erasing removes the email hash and the IP address from the matching records but keeps the record itself, which by then identifies nobody. Deleting the rows outright would rewrite your site's history every time somebody exercised their right to erasure.<\/p><\/dd>\n<dt id=\"does%20it%20support%20multisite%3F\"><h3>Does it support multisite?<\/h3><\/dt>\n<dd><p>Yes, CaptchaFlow works on multisite networks. Each site configures its own protection.<\/p><\/dd>\n<dt id=\"is%20it%20translation-ready%3F\"><h3>Is it translation-ready?<\/h3><\/dt>\n<dd><p>Yes. Every string is translatable, a POT file ships with the plugin, and the admin fully supports RTL languages.<\/p><\/dd>\n<dt id=\"is%20it%20accessible%3F\"><h3>Is it accessible?<\/h3><\/dt>\n<dd><p>Yes. The challenges are keyboard-operable, labelled for screen readers, and respect reduced-motion preferences. The no-JavaScript fallback is plain accessible HTML.<\/p><\/dd>\n<dt id=\"how%20do%20i%20get%20help%3F\"><h3>How do I get help?<\/h3><\/dt>\n<dd><p>Open a thread in the support forum. Please attach the diagnostics report (Tools \u2192 Diagnostics \u2192 Export report) \u2014 it contains no keys or secrets and answers most environment questions in one attachment.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.1.1<\/h4>\n\n<ul>\n<li>Fixed: a site whose reCAPTCHA key was not registered for its domain could lock everyone out of the login screen, including administrators, even with \"let visitors through if the provider is unreachable\" switched on. Provider and configuration errors are now treated as the provider being unavailable, so that setting governs them. Errors that are a judgement about the submission still block.<\/li>\n<li>Fixed: challenges now appear in forms that are added to the page after it loads \u2014 popups, modals, AJAX tabs and anything loaded on scroll.<\/li>\n<li>Fixed: forms that are not HTML forms, such as React-driven checkouts, now receive the challenge fields they need.<\/li>\n<li>New: the challenge response is checked against the site it was issued for, and reCAPTCHA v3 tokens against the action they were issued for, so a token solved elsewhere with this site's public key cannot be replayed here.<\/li>\n<li>New: an occasional review request, shown only after CaptchaFlow has actually blocked something, and never more than one notice at a time.<\/li>\n<li>No changes to what is stored, or to where data is sent.<\/li>\n<\/ul>\n\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>New: a Pro screen in the admin describing what CaptchaFlow Pro adds, reachable from the menu.<\/li>\n<li>The Pro entry is hidden automatically on sites that already run Pro.<\/li>\n<li>No changes to form protection, providers, or how visitor data is handled.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release.<\/li>\n<li>Protection for WordPress core forms (login, registration, password reset, comments), WooCommerce account forms, Contact Form 7, WPForms, Fluent Forms, Forminator, Ninja Forms, Gravity Forms, Elementor Pro, and any form via CSS selector.<\/li>\n<li>Providers: Cloudflare Turnstile, Google reCAPTCHA v2\/v3, hCaptcha, self-hosted Math and Question challenges.<\/li>\n<li>Honeypot and time-trap pre-checks on every submission.<\/li>\n<li>Cache-safe challenge delivery; no visitor data in page HTML.<\/li>\n<li>Setup wizard, one-click diagnostics with text export, theme compatibility checker.<\/li>\n<li>Dashboard with blocked-spam counters and 30-day trend; daily statistics rollups.<\/li>\n<li>Encrypted provider secrets at rest; deferred log writes; automatic log retention.<\/li>\n<li>Privacy: IP addresses shortened to their network before logging, suggested privacy-policy wording generated from your configuration, and export\/erase handlers wired into the WordPress privacy tools.<\/li>\n<\/ul>","raw_excerpt":"Protect Contact Form 7, WPForms, WooCommerce, login, comments and more with Cloudflare Turnstile, reCAPTCHA, hCaptcha, or no-signup challenges.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/348447","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=348447"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/templatesell"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=348447"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=348447"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=348447"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=348447"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=348447"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=348447"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}