Veekay Captcha Shield protects selected WordPress and WooCommerce forms using configurable CAPTCHA providers.
Choose a global default provider, then optionally use a different provider for individual forms or disable CAPTCHA for specific forms.
Supported providers
Supported WordPress forms
Supported WooCommerce forms
WooCommerce is optional. WordPress form protection remains available when WooCommerce is not active.
WooCommerce 10.1.0 or newer is required when WooCommerce protection is used.
Configuration
Veekay Captcha Shield provides one settings page under Settings Veekay Captcha Shield.
The General tab lets you:
Separate settings tabs are available for Cloudflare Turnstile, Google reCAPTCHA Enterprise, and hCaptcha.
The Status tab compares the current PHP, WordPress, and WooCommerce versions with the minimum versions supported by Veekay Captcha Shield.
Security and verification
Documentation
Detailed setup, provider configuration, form guides, and troubleshooting documentation:
https://velukuberan.github.io/veekay-captcha-shield/
Project source and technical documentation:
https://github.com/velukuberan/veekay-captcha-shield
Veekay Captcha Shield integrates with third-party CAPTCHA services. No CAPTCHA provider is contacted unless a site administrator configures that provider and selects it for a protected form.
When a configured provider is used, its browser-side CAPTCHA service may process information directly from the visitor’s browser according to that provider’s own policies.
When a protected action is submitted, Veekay Captcha Shield sends CAPTCHA verification information to the selected provider for verification.
When Cloudflare Turnstile protects a form, the Turnstile browser service is loaded so Cloudflare can perform its CAPTCHA challenge and generate a verification token.
When the protected form is submitted, Veekay Captcha Shield sends the generated token and the configured secret key to Cloudflare’s Siteverify service. The visitor’s IP address may also be included when available.
No form-field contents are intentionally included by Veekay Captcha Shield in the server-side Siteverify request.
Service:
https://www.cloudflare.com/products/turnstile/
Turnstile documentation:
https://developers.cloudflare.com/turnstile/
Turnstile Privacy Addendum:
https://www.cloudflare.com/turnstile-privacy-policy/
Cloudflare terms:
https://www.cloudflare.com/website-terms/
When Google reCAPTCHA protects a form, Google’s reCAPTCHA browser service is used to generate a CAPTCHA token.
When the protected form is submitted, Veekay Captcha Shield creates a Google reCAPTCHA Enterprise assessment.
The assessment can include:
The Google Cloud project ID and configured API key are used to authenticate the assessment request.
Service:
https://cloud.google.com/security/products/recaptcha
Documentation:
https://cloud.google.com/recaptcha/docs
Google Cloud Terms of Service:
https://cloud.google.com/terms
Google Cloud privacy information:
https://cloud.google.com/privacy
When hCaptcha protects a form, the hCaptcha browser service is loaded so hCaptcha can perform its challenge and generate a verification token.
When the protected form is submitted, Veekay Captcha Shield sends the generated token, configured site key, and configured secret key to hCaptcha’s Siteverify service. The visitor’s IP address may also be included when available.
No form-field contents are intentionally included by Veekay Captcha Shield in the server-side Siteverify request.
Service:
https://www.hcaptcha.com/
Documentation:
https://docs.hcaptcha.com/
Privacy Policy:
https://www.hcaptcha.com/privacy
Terms of Service:
https://www.hcaptcha.com/terms
Site owners are responsible for reviewing the terms, privacy requirements, and configuration requirements of the CAPTCHA provider they choose to use.
Please report bugs and technical issues at:
https://github.com/velukuberan/veekay-captcha-shield/issues
User documentation and troubleshooting guides are available at:
https://velukuberan.github.io/veekay-captcha-shield/