Protect your WordPress forms from spam, bots, and automated abuse with Arcoria FormShield — a simple and lightweight CAPTCHA solution built for WordPress.
Unlike services that require you to create a separate account and manage API keys manually, Arcoria FormShield is configured from your WordPress dashboard. The plugin connects to Arcoria-hosted services to provide CAPTCHA protection (see External services below).
Enable protection for the forms that matter most — including login, registration, password reset, comments, contact forms, and other user input areas.
Simple setup
Install and activate Arcoria FormShield, then choose which forms you want to protect from the Forms section in the plugin settings. No separate Arcoria account or external dashboard is required for day-to-day use.
Protect WordPress core forms
Secure built-in WordPress forms including:
Works with popular form plugins
Arcoria FormShield supports popular WordPress form builders and integrations, including:
User-friendly CAPTCHA protection
Add CAPTCHA protection to your forms without creating a frustrating experience for your visitors. Designed to provide a simple balance between security and usability.
Lightweight and WordPress native
Built specifically for WordPress. Arcoria FormShield runs inside your website and keeps the setup simple without unnecessary complexity.
Free to use
All Arcoria FormShield features are free. There are no premium tiers, paid upgrades, or feature limits inside the plugin.
This plugin uses FormShield Captcha, an Arcoria service, to verify users and protect WordPress forms against spam and automated submissions. It relies on external services operated by ARCONIA TECHNOLOGIES LTD (brand: Arcoria) to provide CAPTCHA protection, credential provisioning, and optional support. To perform CAPTCHA verification and bot detection, the plugin communicates with FormShield servers and may process technical and behavioral information, such as browser information and interaction signals. This data is used only for security, spam prevention, and bot mitigation purposes. By using Arcoria FormShield, data may be transmitted to these services as described below.
Used to initialize the plugin and to verify CAPTCHA submissions on your website.
Plugin initialization (/api/formshield-init)
Authorization: Bearer header containing the plugin API token configured for your site. No form-submission or visitor CAPTCHA data is sent during initialization.site_key and secret_key, which are stored in your WordPress database for CAPTCHA verification.CAPTCHA verification (/api/verify)
challenge_id token from the form submission, together with your stored site_key and secret_key.Terms of use: https://arcoria.xyz/formshield/terms
Privacy policy: https://arcoria.xyz/formshield/privacy
Used to load and display the CAPTCHA widget in visitors’ browsers.
https://widget.arcoria.xyz/1/api.js and communicates with Arcoria widget servers to render and complete the CAPTCHA. This may include technical and behavioral information needed for bot detection, such as IP address, browser user-agent, device/browser details, language settings, and CAPTCHA interaction signals. That browser-side processing is described in Arcoria’s privacy policy.Terms of use: https://arcoria.xyz/formshield/terms
Privacy policy: https://arcoria.xyz/formshield/privacy
Used only when a site administrator submits the optional support form in the plugin Help settings tab.
manage_options capability submits a support request from the WordPress admin area.Terms of use: https://arcoria.xyz/formshield/terms
Privacy policy: https://arcoria.xyz/formshield/privacy
Arcoria FormShield processes visitor and site data only as needed to provide CAPTCHA verification, plugin initialization, and optional administrator support. For full details on data collection, retention, and user rights, see Arcoria’s privacy policy at https://arcoria.xyz/privacy