Descripción
The strongest CAPTCHA. Switch from reCAPTCHA and Turnstile for free.
A built-in Migration Wizard helps you move from Google reCAPTCHA or Cloudflare Turnstile to hCaptcha in just a few clicks.
hCaptcha es un reemplazo directo de reCAPTCHA que prioriza la privacidad del usuario.
¿Necesitas mantener alejados a los bots? hCaptcha protege la privacidad y ofrece una mejor protección contra el spam y el abuso. Ayuda a crear una mejor web.
hCaptcha para WP facilita la seguridad con un amplio soporte de integración, análisis detallados y una protección sólida. Comienza a proteger accesos, formularios y más en minutos.
Ventajas
- Privacy First: hCaptcha is designed to protect user privacy. It doesn’t retain or sell personal data, unlike platforms that gather, own, and monetize global behavior.
- Mejor seguridad: hCaptcha ofrece mejor protección contra bots y abusos que otros sistemas anti-abuso.
- Fácil de usar: hCaptcha es fácil de instalar y usar con WordPress y plugins populares.
- Broad Integration: hCaptcha works with WordPress Core, WooCommerce, Contact Form 7, Elementor, and over 60 other plugins and themes.
Características
Highlights
- Migration Wizard: Migrate from Google reCAPTCHA or Cloudflare Turnstile to hCaptcha in just a few clicks.
- Built-in Anti-Spam: Honeypot fields and minimum submit time catch bots before the hCaptcha challenge, reducing friction for real users.
- Detailed Analytics: Get detailed analytics on hCaptcha events and form submissions.
- AI-Ready Security: Selected security actions are exposed via the WordPress Abilities API for automation and AI-driven workflows.
- Pro and Enterprise: Supports Pro and Enterprise versions of hCaptcha.
- No Challenge Modes: 99.9% passive and passive modes in Pro and Enterprise versions reduce user friction.
- Protect Site Content: Protects selected site URLs from bots with hCaptcha. Works best with Pro 99.9% passive mode.
- Logged-in Users: Optionally turn off hCaptcha for logged-in users.
- Delayed API Loading: Load the hCaptcha API instantly or on user interaction for zero page loading impact.
- IP Access Control: Allowlist trusted IPs to skip hCaptcha and denylist abusive IPs to block form submissions.
- Country Access Control: Allowlist or denylist countries to control where hCaptcha protections apply.
- Multisite Support: Sync hCaptcha settings across a Multisite Network.
Anti-Spam
- Honeypot Protection: A hidden field catches bots before they reach the hCaptcha challenge, reducing friction for real users.
- Minimum Submit Time: Blocks instant form submissions from automated scripts.
- IP Denylist: Block abusive IPs from submitting any protected form.
- Country Blocking: Restrict form submissions by country to stop region-specific spam campaigns.
Personalización
- Language Support: Supports multiple languages.
- Custom Themes: Customize the appearance of hCaptcha to match your site.
- Custom Themes Editor: Edit custom themes directly in the plugin.
- Login Compatibility: Compatible with all major hide login, custom login, and 2FA login plugins.
- Login Attempts: Protect your site from brute force attacks.
Facilidad de uso
- Test Modes: Use hCaptcha in live and Pro/Enterprise test modes.
- Activation and Deactivation: Activate and deactivate plugins and themes with hCaptcha in one click.
- Forced Verification: Optionally force hCaptcha verification before form submission.
- Check Config: Check hCaptcha configuration before saving keys and settings.
- Auto-Verification: Automatically verify custom forms.
- Standard Sizes and Themes: Choose the size and theme of the hCaptcha widget.
Cómo funciona hCaptcha
El propósito de un CAPTCHA es distinguir entre personas y máquinas mediante una prueba de desafío-respuesta y, de este modo, aumentar el coste de los sitios web que envían spam o abusan de ellos de otro modo, manteniendo alejados a los bots.
Para utilizar este plugin, instálalo y añade tu secreto y clave de sitio en el menú Ajustes -> hCaptcha después de registrarse en hCaptcha.com.
hCaptcha Free permite a los sitios web bloquear bots y otras formas de abuso a través de desafíos de humanidad.
hCaptcha Pro va más allá del servicio hCaptcha gratuito con aprendizaje automático avanzado para reducir la tasa de desafío, brindando alta seguridad y baja fricción junto con más funciones como la personalización de la interfaz de usuario.
hCaptcha Enterprise delivers a complete advanced security platform, including site-specific risk scores, fraud protection, and more to address both human and automated abuse.
Avisos de privacidad
hCaptcha está diseñado para cumplir con las leyes de privacidad de todos los países, incluidos GDPR, LGPD, CCPA y más.
Por ejemplo, hCaptcha ha sido certificado según las normas ISO 27001 y 27701 y está inscrito en el marco de privacidad de datos UE-EE. UU., Reino Unido-EE. UU. y Suiza, EE. UU, para el cumplimiento del RGPD.
Los detalles están disponibles en www.hcaptcha.com/certifications and www.hcaptcha.com/gdpr.
Con la configuración por defecto, este plugin no:
- rastrear a los usuarios de forma sigilosa;
- escribir cualquier dato personal del usuario en la base de datos;
- enviar cualquier dato a servidores externos;
- utilizar cookies
Una vez que actives este plugin, la dirección IP del usuario que responde a hCaptcha y los datos del navegador pueden ser enviados al servicio hCaptcha en las páginas donde haya activado la protección de hCaptcha. Sin embargo, hCaptcha está diseñado para minimizar los datos utilizados, procesarlos muy cerca del usuario y descartarlos rápidamente después del análisis.
Para más detalles, consulta la política de privacidad de hCaptcha en:
Si activas la función opcional de estadísticas locales del plugin, se registrarán los siguientes datos adicionales en tu base de datos:
- recuento de verificaciones de desafío por formulario
- only if you enable this optional feature: the IP address challenged on each form
- solo si activas esta característica opcional: el agente de usuario cuestionado en cada formulario
Recomendamos dejar desactivado el registro de IP y de Agente de Usuario, lo que hará que estas estadísticas sean totalmente anónimas.
Puedes recopilar datos de forma anónima, pero aun así distinguir las fuentes. Se guardarán la dirección IP cifrada y el agente de usuario.
Si esta característica está activada, también se nos enviarán estadísticas anónimas sobre la configuración de tu plugin, sin incluir ningún dato del usuario final. Esto nos permite ver qué módulos y características se están utilizando y priorizar el desarrollo de acuerdo con ello.
Plugins, temas y formularios compatibles
- Formularios de acceso, registro, contraseña perdida, comentarios y contraseña de entrada/página de WordPress
- ACF Extended Form
- Affiliates Login and Register Forms
- Asgaros Forum New Topic and Reply Form
- Avada standard and multistep Forms
- Back In Stock Notifier Form
- bbPress New Topic, Reply, Login, Register, and Lost Password Forms
- Beaver Builder Contact and Login Forms
- Blocksy Companion Newsletter Subscribe, Waitlist, and Product Review Forms
- BuddyPress — Create Group and Registration Forms
- Classified Listing Contact, Login, Lost Password, and Listing Register Forms
- CoBlocks Form
- Colorlib Customizer Login, Lost Password, and Customizer Register Forms
- Contact Form 7
- Cookies and Content Security Policy
- Customer Reviews for WooCommerce Review and Q&A Forms
- Divi Comment, Contact, Email Optin, and Login Forms
- Divi Builder Comment, Contact, Email Optin, and Login Forms
- Download Manager Form
- Droit Dark Mode
- Easy Digital Downloads Checkout, Login, Lost Password, and Register Forms
- Elementor Pro Form and Login Form
- Essential Addons for Elementor Login and Register Forms
- Essential Blocks Form
- Events Manager Booking Form
- Extra Comment, Contact, Email Optin, and Login Forms
- Fluent Forms, including Conversational, Multi-Step, and Login Forms
- Forminator Forms
- Formidable Forms
- GiveWP Form
- Gravity Forms
- Gravity Perks Nested Forms
- Icegram Express Form
- Jetpack Forms
- Formulario y formulario avanzado de Kadence
- LearnDash Login, Lost Password, and Register Forms
- Login/Signup Popup Login and Register Forms
- Mailchimp for WP Form
- MailPoet Form
- Maintenance Login Form
- MemberPress Login and Register Forms
- Ninja Forms
- Otter Blocks Forms
- Paid Memberships Pro Checkout and Login Forms
- Passster Protection Form
- Password Protected Form
- Profile Builder Login, Recover Password, and Register Forms
- Really Simple CAPTCHA
- Quform Forms
- Sendinblue Form
- Simple Download Monitor Form
- Simple Membership Login, Lost Password, and Register Forms
- Simple Basic Contact Form
- Spectra — WordPress Gutenberg Blocks Form
- Subscriber Form
- Support Candy New Ticket Form
- Theme My Login — Login, Lost Password, and Register Form
- Tutor LMS — Checkout, Login, Lost Password, and Register Form
- Ultimate Addons for Elementor Login and Register Forms
- Ultimate Member Login, Lost Password, and Member Register Forms
- UsersWP Forgot Password, Login, and Register Forms
- WooCommerce Login, Registration, Lost Password, Checkout, and Order Tracking Forms
- WooCommerce Germanized Return Request Form
- WooCommerce Wishlist Form
- Wordfence Security Login Form
- Wordfence Login Security Login Form
- WP Dark Mode
- WP Job Openings Form
- WPForms Form
- wpDiscuz Comment and Support Forms
- wpForo New Topic and Reply Forms
Ten en cuenta
Nota: este es un plugin desarrollado por la comunidad. Tus solicitudes de incorporación de cambios son bienvenidas.
Para solicitudes de características e informes de problemas, por favor
abre una solicitud.
También sugerimos enviar un correo electrónico a los autores de los plugis que deseas que admitan hCaptcha: por lo general, solo les llevará una o dos horas añadir compatibilidad nativa. Esto simplificará el uso de hCaptcha y es la mejor solución a largo plazo.
Puedes utilizar la compatibilidad nativa con hCaptcha si está disponible para su plugin. Consulta con el autor del plugin si la compatibilidad nativa aún no está disponible.
Sin embargo, el plugin hCaptcha proporciona un conjunto más amplio de opciones y características para que puedas usarlo con cualquier formulario de tu sitio.
Instructions for popular native integrations are below:
Capturas















Instalación
Sign up at hCaptcha.com to get your sitekey and secret, then:
- Install hCaptcha either via the WordPress.org plugin repository (best) or by uploading the files to your server. (Upload instructions)
- Activate the hCaptcha plugin on the Plugins admin page
- Enter your site key and secret on the SettingshCaptchaGeneral page
- Enable desired Integrations on the SettingshCaptchaIntegrations page
FAQ
-
¿Cómo uso el plugin hCaptcha?
-
El plugin hCaptcha es compatible con el núcleo de WordPress y muchos plugins con formularios de forma automática. Debes seleccionar los formularios compatibles en la página de ajustes de integraciones de hCaptcha.
Para casos no estándar, puedes utilizar el código corto
[hcaptcha]proporcionado por el plugin.Por ejemplo, admitimos Contact Forms 7 de forma automática. Sin embargo, a veces un tema puede modificar el formulario. En este caso, puedes añadir manualmente el código abreviado
[cf7-hcaptcha]al formulario CF7.Para que hCaptcha funcione, el shortcode debe estar dentro de la etiqueta …
…
tag.
-
How do I migrate from reCAPTCHA or Turnstile?
-
Go to Settings hCaptcha Tools and use the Migration Wizard.
It scans your site for existing CAPTCHA providers, shows what can be migrated, and applies the changes in one click.
-
How do I use the new AI / Abilities features?
-
hCaptcha exposes selected security actions via the WordPress Abilities API for use with automation tools, WP-CLI, and AI agents, making it suitable for agencies managing multiple WordPress sites. Requires WordPress 6.9 or newer.
The typical workflow consists of two steps: inspect threats and block offenders.
** 1. Inspect recent threat activity **
You can request an aggregated threat snapshot for a given time window.
Using WP-CLI:
wp ability run hcaptcha/get-threat-snapshot --input='{"window":"55d"}' --user=adminUsing REST API (authenticated):
curl --globoff -u "USER:APP_PASSWORD" \ "https://example.com/wp-json/wp-abilities/v1/abilities/hcaptcha/get-threat-snapshot/run?input[window]=55d"The response includes:
* overall metrics (total requests, failure rate)
* confidence and top error vectors
* breakdown by error type and form source
* a list of top offenders (if present)Example (simplified):
{ "metrics": { "total": 353, "failed": 215, "fail_rate": "0.61" }, "signals": { "confidence": "high", "top_vectors": ["empty", "spam"] }, "breakdown": { "errors": { "empty": 160, "spam": 16 }, "offenders": [ { "offender_id": "a1376a016c4156933c4d49b0bc56fa01", "type": "ip", "count": 2 } ] } }** 2. Block abusive offenders **
If an offender appears suspicious, you can block it using its offender_id.
Using WP-CLI:
wp ability run hcaptcha/block-offenders \ --input='{"offender_ids":["a1376a016c4156933c4d49b0bc56fa01"]}' \ --user=adminUsing REST API (authenticated):
curl --globoff -u "USER:APP_PASSWORD" \ "https://example.com/wp-json/wp-abilities/v1/abilities/hcaptcha/block-offenders/run?input[offender_ids][]=a1376a016c4156933c4d49b0bc56fa01"Example response:
{ "blocked": ["a1376a016c4156933c4d49b0bc56fa01"], "effective_until": "2026-01-01T22:22:09Z" }** What is offender_id? **
offender_id is a stable hash of the IP address.Raw IP addresses are never exposed to automation clients or AI agents.
This allows privacy-safe analysis and blocking, while still enabling deterministic enforcement.
** Can AI agents use this automatically? **
Yes.
You can point an AI agent to a WordPress site with Abilities enabled and instruct it to:
* discover available abilities
* collect threat statistics
* decide whether activity looks abusive
* block the most active offendersInternally, the agent performs the same commands shown above (
wp ability list,get-threat-snapshot,block-offenders).** 3. Export plugin settings **
You can export current plugin settings as JSON (optionally including keys) for backup or migration.
Using WP-CLI:
wp ability run hcaptcha/export-settings --include_keys --user=adminUsing REST API (authenticated):
curl --globoff -u "USER:APP_PASSWORD" \ "https://example.com/wp-json/wp-abilities/v1/abilities/hcaptcha/export-settings/run?input[include_keys]=1"** 4. Import plugin settings **
Import settings from a JSON file path on the server. Use
allow_keysto apply the keys block anddry_runto validate without saving.Using WP-CLI:
wp ability run hcaptcha/import-settings --allow_keys --dry-run=false --user=igor --input_file=1.jsonUsing REST API (authenticated):
curl --globoff -u "USER:APP_PASSWORD" \ "https://example.com/wp-json/wp-abilities/v1/abilities/hcaptcha/import-settings/run?input[input_file]=%2Fpath%2Fto%2Fhcaptcha-settings.json&input[allow_keys]=1&input[dry_run]=0" -
WP-CLI commands for exporting and importing settings
-
The plugin also adds the
wp hcaptcha exportandwp hcaptcha importcommands.Export settings
`wp hcaptcha export –pretty > hcaptcha-settings.json
wp hcaptcha export –include-keys –file=./hcaptcha-settings.json
`Parameters:
*--include-keys— include thesite_keyandsecret_keyvalues.
*--pretty— pretty-print JSON for readability.
*--file=<path>— write JSON to a file instead of STDOUT.Import settings
`wp hcaptcha import ./hcaptcha-settings.json
wp hcaptcha import ./hcaptcha-settings.json –dry-run
wp hcaptcha import ./hcaptcha-settings.json –allow-keys
`Parameters:
*--dry-run— validate the JSON without saving.
*--allow-keys— allow importing keys from thekeysblock. -
No es compatible con el plugin X. ¿Cómo puedo conseguir que se añada compatibilidad para él?
-
Open a PR on GitHub: or just email the authors of plugin X. Adding hCaptcha support is typically quite a quick task for most plugins.
-
¿El shortcode [hcaptcha] tiene argumentos?
-
Full list of arguments:
[hcaptcha action="my_hcap_action" name="my_hcap_name" auto="true|false" ajax="true|false" force="true|false" theme="light|dark|auto" size="normal|compact|invisible"]The shortcode adds not only the hCaptcha div to the form but also a nonce field. You can set your own nonce action and name. For this, use arguments in the shortcode:
[hcaptcha action="my_hcap_action" name="my_hcap_name"]and in the verification:
$result = \HCaptcha\Helpers\API::verify_post( 'my_hcap_name', 'my_hcap_action' );For the explanation of the auto=»true|false» argument, see the section «How to automatically verify an arbitrary form». By default,
auto="false".The argument force=»true|false» allows forcing verification of hCaptcha widget before submitting the form. By default,
force="false".The argument size=»normal|compact|invisible» allows setting the size of hCaptcha widget. By default,
size="normal". -
Cómo añadir hCaptcha a un formulario arbitrario
-
First, add the hCaptcha snippet to the form.
If you create the form as an HTML block in the post content, insert the shortcode
[hcaptcha]inside it. It may look like this:<form method="post"> <input type="text" name="test_input"> <input type="submit" value="Send"> [hcaptcha] </form>If you create the form programmatically, insert the following statement inside it:
?> <form method="post"> <input type="text" name="test_input"> <input type="submit" value="Send"> <?php echo do_shortcode( '[hcaptcha]' ); ?> </form> <?phpSecondly, verify the result of hCaptcha challenge.
$result = \HCaptcha\Helpers\API::verify_request(); if ( null !== $result ) { echo esc_html( $result ); // Block processing of the form. } -
Cómo verificar automáticamente un formulario arbitrario
-
Arbitrary user forms can be verified easily. Just add
auto="true"orauto="1"to the shortcode:[hcaptcha auto="true"]and insert this shortcode into your form.
Auto-verification works with forms sent by POST on frontend only. It works with forms in the post content and in widgets.
You can add also
force="true"orforce="1"argument to prevent sending a form without checking the hCaptcha.[hcaptcha auto="true" force="true"]Arbitrary forms can also be verified in ajax via the
ajaxargument. There is no need to specifyauto="true"in this case, asajaximpliesauto="true".[hcaptcha ajax="true"] -
¿Cómo bloquear completamente hCaptcha en una página específica?
-
hCaptcha starts early, so you cannot use standard WP functions to determine the page. For instance, to block it on
my-accountpage, add the following code to your plugin’s (or mu-plugin’s) main file. This code won’t work being added to a theme’s functions.php file./** * Filter hCaptcha activation flag. * * @param bool|mixed $activate The activate flag. * * @return bool */ function my_hcap_activate( $activate ): bool { $status = (bool) $status; $url = isset( $_SERVER['REQUEST_URI'] ) ? filter_var( wp_unslash( $_SERVER['REQUEST_URI'] ), FILTER_SANITIZE_FULL_SPECIAL_CHARS ) : ''; if ( '/my-account/' === $url ) { return false; } return $activate; } add_filter( 'hcap_activate', 'my_hcap_activate' ); -
How do I block hCaptcha scripts everywhere except on a specific page?
-
As an example, to block hCaptcha scripts everywhere except on the
contactpage:/** * Block inline styles. * * @return void */ function hcap_block_inline_styles() { if ( is_page( 'contact' ) ) { return; } $hcaptcha = hcaptcha(); remove_action( 'wp_head', [ $hcaptcha, 'print_inline_styles' ] ); remove_filter( 'wp_resource_hints', [ $hcaptcha, 'prefetch_hcaptcha_dns' ] ); } add_action( 'wp_head', 'hcap_block_inline_styles', 0 ); -
Omitir la verificación hCaptcha en un formulario específico
-
The plugin has a filter to skip adding and verifying hCaptcha on a specific form. The filter receives three parameters: current protection status (‘true’ by default), source, and form_id.
The source is the plugin’s slug (like ‘directory/main-plugin-file.php’), the theme name (like ‘Avada’) or the WordPress core (like ‘WordPress’).
The form_id is the form_id for plugins like Gravity Forms or WPForms, the post id for comments, or a general name of the form when the form does not have an id (like WordPress core login form).
Filter arguments for some plugins/forms are listed below.
Affiliates
$source: ‘affiliates/affiliates.php’
$form_id: ‘login’ or ‘register’Back In Stock Notifier
$source: ‘back-in-stock-notifier-for-woocommerce/cwginstocknotifier.php’
$form_id: product_idBBPress
$source: ‘bbpress/bbpress.php’
$form_id: ‘new_topic’, ‘reply’, ‘login’, ‘register’ or ‘lost_password’Beaver Builder
$source: ‘bb-plugin/fl-builder.php’
$form_id: ‘contact’ or ‘login’Blocksy
$source: ‘blocksy’
$form_id: ‘newsletter-subscribe’, ‘$layer[«__id»]’, or ‘product_idBrizy
$source: ‘brizy/brizy.php’
$form_id: ‘form’BuddyPress
$source: ‘buddypress/bp-loader.php’
$form_id: ‘create_group’ or ‘register’Classified Listing
$source: ‘classified-listing/classified-listing.php’
$form_id: ‘contact’, ‘login’, ‘lost_password’ or ‘register’Divi
$source: ‘Divi’
$form_id: post_id for comment form, ‘contact’, ‘email_optin’, or ‘login’Download Manager
$source: ‘download-manager/download-manager.php’
$form_id: post_id of download item in the adminEasy Digital Downloads
$source: ‘easy-digital-downloads/easy-digital-downloads.php’
$form_id: ‘checkout’, ‘login’, ‘lost_password’ or ‘register’Elementor Pro
$source: ‘elementor-pro/elementor-pro.php’
$form_id: Form ID set for the form Content->Additional Options or ‘login’Events Manager
$source: ‘events-manager/events-manager.php’
$form_id: event_idIcegram Express
$source: ‘email-subscribers/email-subscribers.php’
$form_id: form_idCustomer Reviews for WooCommerce
$source: ‘customer-reviews-woocommerce/ivole.php’
$form_id: review or q&aJetpack
$source: ‘jetpack/jetpack.php’
$form_id: ‘contact_$form_hash’Kadence Form
$source: ‘kadence-blocks/kadence-blocks.php’
$form_id: post_idKadence Advanced Form
$source: ‘kadence-blocks/kadence-blocks.php’
$form_id: form_idLearnDash
$source: ‘sfwd-lms/sfwd_lms.php’
$form_id: ‘login’, ‘lost_password’ or ‘register’LearnPress
$source: ‘learnpress/learnpress.php’
$form_id: ‘checkout’, »login’, or ‘register’Login/Signup Popup
$source: ‘easy-login-woocommerce/xoo-el-main.php’
$form_id: ‘login’, or ‘register’MemberPress
$source: ‘memberpress/memberpress.php’
$form_id: ‘login’ or ‘register’Paid Memberships Pro
$source: ‘paid-memberships-pro/paid-memberships-pro.php’
$form_id: ‘checkout’ or ‘login’Passster
$source: ‘content-protector/content-protector.php’
$form_id: area_idPassword Protected
$source: ‘password-protected/password-protected.php’
$form_id: ‘protect’Profile Builder
$source: ‘profile-builder/index.php’
$form_id: ‘login’, ‘lost_password’ or ‘register’Simple Membership
$source: ‘simple-membership/simple-wp-membership.php’
$form_id: ‘login’, ‘lost_password’ or ‘register’Subscriber
$source: ‘subscriber/subscriber.php’
$form_id: ‘form’Support Candy
$source: ‘supportcandy/supportcandy.php’
$form_id: ‘form’Theme My Login
$source: ‘theme-my-login/theme-my-login.php’
$form_id: ‘login’, ‘lost_password’ or ‘register’Tutor LMS
$source: ‘tutor/tutor.php’
$form_id: ‘checkout’, »login’, ‘lost_password’ or ‘register’Ultimate Addons
$source: ‘ultimate-elementor/ultimate-elementor.php’
$form_id: ‘login’ or ‘register’Ultimate Member
$source: ‘ultimate-member/ultimate-member.php’
$form_id: form_id or ‘password’UsersWP
$source: ‘userswp/userswp.php’
$form_id: ‘forgot’, ‘login’ or ‘register’WooCommerce Germanized
$source: ‘woocommerce-germanized/woocommerce-germanized.php’
$form_id: ‘return_request’WooCommerce Wishlist
$source: ‘woocommerce-wishlists/woocommerce-wishlists.php’
$form_id: ‘form’wpDiscuz
$source: ‘wpdiscuz/class.WpdiscuzCore.php’
$form_id: post_idWPForms
$source: ‘wpforms-lite/wpforms.php’ or ‘wpforms/wpforms.php’
$form_id: form_idwpForo
$source: ‘wpforo/wpforo.php’
$form_id: ‘new_topic’ for a new topic form and topicid for a reply form. Topicid can be found in HTML code searching for ‘data-topicid’ in Elements.Wordfence Login Security
$source: ‘wordfence-login-security/wordfence-login-security.php’
$form_id: ‘login’Wordfence Security
$source: ‘wordfence/wordfence.php’
$form_id: ‘login’WordPress Core
$source: ‘WordPress’
$form_id: post_id for comment form, ‘login’, ‘lost_password’, ‘password_protected’, or ‘register’WooCommerce
$source: ‘woocommerce/woocommerce.php’
$form_id: ‘checkout’, ‘login’, ‘lost_password’, ‘order_tracking’, or ‘register’Below is an example of how to skip the hCaptcha widget on a Gravity Form with id = 1.
/** * Filters the protection status of a form. * * @param string|mixed $value The protection status of a form. * @param string[] $source Plugin(s) serving the form. * @param int|string $form_id Form id. * * @return bool */ function hcap_protect_form_filter( $value, $source, $form_id ): bool { $value = (bool) $value; if ( ! in_array( 'gravityforms/gravityforms.php', $source, true ) ) { // The form is not sourced by Gravity Forms plugin. return $value; } if ( 1 !== (int) $form_id ) { // The form has id !== 1. return $value; } // Turn off protection for a Gravity form with id = 1. return false; } add_filter( 'hcap_protect_form', 'hcap_protect_form_filter', 10, 3 ); -
¿Cómo puedo mostrar el widget hCaptcha instantáneamente?
-
The plugin loads the hCaptcha script with a delay until user interaction: mouseenter, click, scroll, or touch. This significantly improves Google Pagespeed Insights score.
To load the hCaptcha widget instantly, you can use the following filter:
/** * Filters delay time for hCaptcha API script. * * Any negative value will prevent the API script from loading at all, * until user interaction: mouseenter, click, scroll, or touch. * This significantly improves Google Pagespeed Insights score. * * @param int|mixed $delay Number of milliseconds to delay hCaptcha API script. * Any negative value means delay until user interaction. */ function my_hcap_delay_api( $delay ): int { return 0; } add_filter( 'hcap_delay_api', 'my_hcap_delay_api' ); -
How can I load the hCaptcha API script only when a specific element is visible?
-
To load the hCaptcha API script only when a WordPress comment form is visible, you can use the followign filter:
/** * Filters delay API selector. * * When set, the hcaptcha.js script will be loaded only when the specified element is visible. * This can improve page load performance by deferring the API script until it's necessary. * * @param string|mixed $delay_api_selector CSS selector of the element to observe. */ add_filter( 'hcap_delay_api_selector', static function ( $delay_api_selector ) { $delay_api_selector = (string) $delay_api_selector; if ( is_admin() || is_login() ) { return $delay_api_selector; } $selectors = [ '.comment-form', // WP comment form. '.elementor-form', // Elementor Pro. '.wpcf7-form', // Contact Form 7. '.fluentform, .frm-fluent-form', // Fluent Forms. '.nf-form-cont', // Ninja Forms. '.es_subscription_form, .es-form-field-container, .ig_popup', // Icegram Express Forms. '.cr-reviews-ajax-reviews, .cr-qna-block', // Customer Reviews. ]; return implode( ', ', $selectors ); } ); -
How can I delay the hCaptcha API script until a custom event?
-
Developers can use the
hcap_delay_api_eventfilter to opt into custom event-based API loading for specific integrations.When the filter returns a non-empty event name, hCaptcha waits for
hCaptchaBeforeAPI, then listens for that custom event ondocument. The default delay timer and built-in user interaction listeners are skipped. Your integration must dispatch the event when it is ready to load the hCaptcha API.Scope this filter carefully to only the pages or forms where you also dispatch the event.
/** * Filters the custom browser event name used to load the hCaptcha API script. * * @param string|mixed $delay_api_event Custom browser event name. */ add_filter( 'hcap_delay_api_event', static function ( $delay_api_event ): string { if ( ! is_singular() || ! has_block( 'jetpack/contact-form', get_queried_object() ) ) { return (string) $delay_api_event; } return 'hcap-load-api'; } ); // Later, when the form is interacted with: // document.dispatchEvent( new CustomEvent( 'hcap-load-api' ) ); -
¿Cómo configurar el idioma de hCaptcha mediante programación?
-
De forma por defecto, hCaptcha utiliza el idioma del usuario según lo informado por el navegador. Sin embargo, en sitios multilingües, puedes anular esta opción para configurar el idioma de hCaptcha de modo que coincida con el idioma de la página actual. Para ello, puede utilizar el siguiente filtro:
/** * Filters hCaptcha language. * * @param string|mixed $language Language. */ function my_hcap_language( $language ): string { $language = (string) $language; // Detect page language and return it. $page_language = 'some lang'; // Detection depends on the multilingual plugin used. return $page_language; } add_filter( 'hcap_language', 'my_hcap_language' ); -
How to denylist certain IPs
-
You can use the following filter. It should be added to your plugin’s (or mu-plugin’s) main file. This filter won’t work being added to a theme’s functions.php file.
/** * Filter the user IP to check if it is denylisted. * For denylisted IPs, any form submission fails. * * @param bool|mixed $denylisted Whether IP is denylisted. * @param string $ip IP. * * @return bool */ function my_hcap_denylist_ip( $denylisted, $ip ): bool { $denylisted = (bool) $denylisted; // Denylist some IPs. if ( '8.8.8.8' === $ip ) { return true; } return $denylisted; } add_filter( 'hcap_blacklist_ip', 'my_hcap_denylist_ip', 10, 2 ); -
How does hCaptcha determine the visitor IP address?
-
hCaptcha uses
REMOTE_ADDRby default. If your site is behind a trusted proxy or CDN, go to Settings hCaptcha Anti-Spam Access Control and select only the IP headers your edge service overwrites or strips from direct client requests.Forwarding headers such as
X-Forwarded-For,CF-Connecting-IP, andX-Real-IPcan be spoofed when they pass through from the browser unchanged. Do not enable a header unless your hosting stack makes it trustworthy before WordPress receives the request.On upgrade, custom
hcap_trusted_address_headersfilters are migrated into this setting. Otherwise the setting starts empty and an admin notice asks you to review it. -
Cómo incluir en la lista blanca determinadas direcciones IP
-
You can use the following filter. It should be added to your plugin’s (or mu-plugin’s) main file. This filter won’t work being added to a theme’s functions.php file.
/** * Filter user IP to check if it is allowlisted. * For allowlisted IPs, hCaptcha will not be shown. * * @param bool|mixed $allowlisted Whether IP is allowlisted. * @param string $ip IP. * * @return bool */ function my_hcap_allowlist_ip( $allowlisted, $ip ): bool { $allowlisted = (bool) $allowlisted; // Allowlist local IPs. if ( false === $ip ) { return true; } // Allowlist some other IPs. if ( '1.1.1.1' === $ip ) { return true; } return $allowlisted; } add_filter( 'hcap_whitelist_ip', 'my_hcap_allowlist_ip', 10, 2 ); -
Starting from 4.1.0, the admin menu was moved to the top level with subpages.
You can customize this by returning it to the previous location in the admin Settings section or tweaking its appearance.
To do this, use the following filter to your plugin’s (or mu-plugin’s) main file. This code won’t work being added to a theme’s functions.php file.
/** * Filter the settings system initialization arguments. * * @param array|mixed $args Settings system initialization arguments. */ function hcap_settings_init_args_filter( $args ): array { $args = (array) $args; $args['mode'] = 'tabs'; return $args; } add_filter( 'hcap_settings_init_args', 'hcap_settings_init_args_filter' ); $args array has the following fields: mode: 'pages' or 'tabs' (default 'pages') — the appearance of the admin menu; parent: a string — the parent menu item. Default '' for 'pages' mode and 'options-general.php' for 'tabs' mode; position: a number — the position of the menu item. Default 58.990225 for 'pages' mode. It Has no effect on 'tabs' mode; -
Where do I report security bugs found in this plugin?
-
Please report security vulnerabilities by email to:
security@hcaptcha.com
When reporting a vulnerability, please include as much information as possible to help us reproduce and investigate the issue, such as:
- A clear description of the vulnerability
- Steps to reproduce
- Proof-of-concept or exploit code (if available)
- Affected versions
We will review your report and respond as quickly as possible.
-
¿Dónde puedo obtener más información sobre hCaptcha?
-
Please see our website.
-
How can I rerun the setup wizard?
-
Use the plugin-generated «Restart wizard» onboarding link from the admin area. Onboarding setup URLs are nonce-protected and should not be crafted manually.
Reseñas
Colaboradores y desarrolladores
«hCaptcha for WP» es un software de código abierto. Las siguientes personas han colaborado con este plugin.
Colaboradores«hCaptcha for WP» está traducido en 11 idiomas. Gracias a los traductores por sus contribuciones.
Traduce «hCaptcha for WP» a tu idioma.
¿Interesado en el desarrollo?
Revisa el código , echa un vistazo al repositorio SVN o suscríbete al registro de desarrollo por RSS.
Registro de cambios
5.1.0
- Added version switching to the What’s New popup.
- Added a Help button on hCaptcha admin pages to generate support reports for GitHub or WordPress.org, with optional System Info included.
- Added hcap_delay_api_event filter for delayed loading of the hCaptcha API upon user interaction.
- Hardened form verification for 22 integrations.
- Fixed hcap_delay_api_selector filter for delayed loading of hCaptcha in the Jetpack contact forms.
- Fixed hCaptcha auto-insertion for Jetpack block contact forms that render the Submit button with core Button block markup.
- Fixed hCaptcha auto-insertion for WooCommerce Checkout blocks when the Return to Cart link is enabled.
- Fixed manually added hCaptcha shortcodes inside Jetpack contact forms to use the proper form signature.
- Fixed Events statistics table indexes for MariaDB/MyISAM databases with a 1000-byte key length limit.
- Fixed System Info migration entries to show that older migrations were not required instead of displaying the Unix epoch date.
- Fixed hCaptcha token refresh for Blocksy newsletter and waitlist forms after failed submissions.
- Fixed ACF Extended Forms integration to prevent reCAPTCHA from loading when hCaptcha is used to avoid submission errors.
- Fixed hCaptcha verification for upgraded GiveWP donation forms.
- Fixed FST token replay errors after submitting GiveWP forms without completing hCaptcha.
5.0.1
- Fixed Elementor Pro Forms validation when the optional Form ID is empty or differs from the Elementor widget ID.
- Fixed Events statistics table handling to avoid runtime table-existence checks and recreate the table during activation or maintenance when needed.
5.0.0
- Added Trusted IP Headers settings. hCaptcha uses REMOTE_ADDR by default; custom
hcap_trusted_address_headersfilters are migrated into the setting during upgrade. - Added Cloudflare detection to help identify when CF-Connecting-IP should be selected as a Trusted IP Header.
- Added Trash support for Forms and Events statistics, including restore/permanent delete actions, 30-day Trash cleanup, and migration for existing event tables.
- Added WooCommerce PayPal Payments integration for product, cart, mini-cart, and checkout express flows.
- Added site icon on protected content pages.
- Hardened form verification for some popular forms.
- Fixed returning unexpected results by REST API in some cases.
- Fixed Avada Forms integration so internal hCaptcha fields are excluded from
[all_fields]notification emails. - Fixed sending statistics at the plugin update in some rare cases when the switch is off.
- Fixed an issue in some custom Gravity Forms layouts.
- Fixed an issue where a What’s New modal action could scroll the current Integrations page before opening the target integration in a new tab.
- Fixed errors when resubmitting Essential Addons login and registration forms.
