Type something to search...
How to add CAPTCHA to WordPress login and forms?

How to add CAPTCHA to WordPress login and forms?

To add CAPTCHA to WordPress, pick a CAPTCHA service (Google reCAPTCHA, hCaptcha, or Cloudflare Turnstile), create a free site key and secret key in that service's dashboard, and then either install a plugin that connects it to your login, registration, and comment forms, or enable the built-in CAPTCHA integration in your form plugin. For contact forms, plugins like Contact Form 7, WPForms, and Gravity Forms support one or more of these services directly. If you'd rather avoid extra plugins, you can also add a CAPTCHA to the WordPress login form with a small amount of custom code.

CAPTCHA is one of the most effective ways to cut down on spam submissions and automated login attempts, but the right choice depends on your privacy needs, your audience, and which forms you want to protect. In this guide, you'll learn how the main CAPTCHA services compare, how to add them with plugins, how to add Turnstile to the login form with code, and how to avoid common mistakes that lock out real users.

What Is CAPTCHA and Why Use It on WordPress?

CAPTCHA stands for "Completely Automated Public Turing test to tell Computers and Humans Apart." It's a challenge that's easy for people and hard for bots. Older CAPTCHAs asked you to type distorted letters; modern ones mostly run in the background, analysing browser signals and only showing a puzzle when something looks suspicious.

On a WordPress site, CAPTCHA helps protect:

  • The login form: Slows down brute-force and credential-stuffing bots that try thousands of passwords.
  • The registration form: Stops fake account signups on sites that allow registration.
  • The lost password form: Prevents bots from flooding users with password reset emails.
  • Comment forms: Reduces automated comment spam.
  • Contact and lead forms: Cuts down junk submissions and protects your inbox.
  • WooCommerce forms: Helps prevent fake accounts and automated card-testing attempts at checkout.

CAPTCHA Is One Layer, Not the Whole Defence

CAPTCHA reduces automated attacks, but it doesn't replace strong passwords, two-factor authentication, or login rate limiting. Determined attackers can sometimes use paid CAPTCHA-solving services. Think of CAPTCHA as a filter that removes most of the noise so your other defences have less to deal with.

Choosing a CAPTCHA Service

There are three main services you'll see in WordPress plugins. All three offer a free tier that covers most small and medium sites, though limits and paid plans change over time, so check each provider's current terms.

Google reCAPTCHA

  • reCAPTCHA v2 checkbox: The familiar "I'm not a robot" checkbox, sometimes followed by an image challenge.
  • reCAPTCHA v2 invisible: Runs when the user submits the form, only showing a challenge if needed.
  • reCAPTCHA v3: Completely invisible. It returns a score between 0.0 and 1.0, and your site decides what score to accept.

reCAPTCHA is widely supported and familiar to users. The trade-offs are privacy concerns, because it sends data to Google, and the fact that v3's scoring can occasionally flag real users, especially those using privacy tools or VPNs. Google has also been moving reCAPTCHA keys into Google Cloud, so the setup screens may look different depending on when you create your keys.

hCaptcha

hCaptcha is a privacy-focused alternative that works similarly to reCAPTCHA v2, with checkbox and invisible modes. It's supported by many WordPress plugins and has an official WordPress plugin that integrates with core forms and dozens of popular plugins. Its image challenges can be a little more frequent than reCAPTCHA's for some users.

Cloudflare Turnstile

Turnstile is Cloudflare's CAPTCHA alternative. It usually runs without showing any puzzle at all, relying on background browser checks. You don't need to use Cloudflare's CDN to use it, and it's designed with privacy in mind. It's become a popular choice for WordPress sites because it's low-friction for real users.

Which One Should You Choose?

  • Best user experience: Cloudflare Turnstile, because most visitors never see a challenge.
  • Widest plugin support: Google reCAPTCHA, followed closely by hCaptcha.
  • Privacy-focused sites: Turnstile or hCaptcha, but review each provider's privacy policy and mention the service in your own privacy policy.
  • Already using a form plugin: Use whichever service your form plugin supports natively, so you don't need an extra plugin.

Step 1: Get Your Site Key and Secret Key

Every service works the same way: you register your domain and receive two keys.

  1. Site key: A public key that goes into the page so the CAPTCHA widget can load.
  2. Secret key: A private key that your server uses to verify responses. Never share it or put it in front-end code.

To create them:

  • Cloudflare Turnstile: Log in to the Cloudflare dashboard, open Turnstile, click Add widget, enter your domain, and choose the Managed widget mode.
  • hCaptcha: Sign up at hCaptcha, add a new site in the dashboard, and copy the site key and your account secret.
  • Google reCAPTCHA: Open the reCAPTCHA admin console, register your site, choose v2 or v3, and add your domain.

Add both your live domain and any staging domain you use, so the CAPTCHA works in both places.

Step 2: Add CAPTCHA to Login, Registration, and Comments With a Plugin

For the core WordPress forms, a dedicated CAPTCHA plugin is the easiest option. Here are some well-known choices:

  • Simple Cloudflare Turnstile: Adds Turnstile to the login, registration, lost password, and comment forms, plus integrations with WooCommerce and many form plugins.
  • hCaptcha for WordPress: The official hCaptcha plugin, with integrations for core forms, WooCommerce, and many popular form and membership plugins.
  • Advanced Google reCAPTCHA: Adds reCAPTCHA v2 or v3 to core forms and WooCommerce.
  • Wordfence Login Security: Includes reCAPTCHA v3 for the login and registration forms as part of its login security features.

The setup is similar in each plugin:

  1. Install the plugin: Go to Plugins > Add New Plugin, search for the plugin, then click Install Now and Activate.
  2. Open its settings: Most add a page under Settings, or a new menu item in the dashboard.
  3. Paste your keys: Enter the site key and secret key from Step 1.
  4. Choose which forms to protect: Tick login, registration, lost password, and comments as needed.
  5. Save and test: Open your login page in a private window and make sure the widget appears and you can log in.

Before you log out, test the login in a separate private window. If the keys are wrong or the domain isn't registered, the CAPTCHA may fail every time, and you want to find that out while you still have a logged-in session to fix it.

Step 3: Add CAPTCHA to Contact Forms

Most form plugins have their own CAPTCHA settings, so you usually don't need a separate plugin for contact forms.

Contact Form 7

Contact Form 7 includes a reCAPTCHA v3 integration, and recent versions also support Cloudflare Turnstile.

  1. Go to Contact > Integration.
  2. Find the reCAPTCHA or Turnstile section and click Setup Integration.
  3. Enter your site key and secret key, then save.

Once configured, the CAPTCHA is applied to all your Contact Form 7 forms automatically. Contact Form 7 also has built-in spam tools like its disallowed list and Akismet integration, which work well alongside a CAPTCHA.

WPForms

WPForms supports reCAPTCHA, hCaptcha, and Turnstile.

  1. Go to WPForms > Settings > CAPTCHA.
  2. Choose your CAPTCHA type and enter your keys, then save.
  3. Edit each form, open Settings > Spam Protection and Security, and enable the CAPTCHA for that form.

Gravity Forms

Gravity Forms has a built-in reCAPTCHA field. Add your keys under Forms > Settings > reCAPTCHA, then add the CAPTCHA field to any form. Official add-ons provide support for other services, depending on your license.

WooCommerce

The Simple Cloudflare Turnstile and hCaptcha plugins both include WooCommerce integrations for the My Account login, registration, and checkout forms. Adding CAPTCHA to checkout can help against card-testing bots, but test carefully, because anything that adds friction at checkout can affect conversions.

Step 4 (Optional): Add Turnstile to the Login Form With Code

If you only need CAPTCHA on the WordPress login form and prefer to avoid a plugin, you can add Cloudflare Turnstile with a short custom plugin. This example uses core hooks for the login form and the authenticate filter to verify the token on the server.

First, add your keys to wp-config.php, above the line that says /* That's all, stop editing! Happy publishing. */:

define( 'SAJJAD_TURNSTILE_SITE_KEY', 'your-site-key' );
define( 'SAJJAD_TURNSTILE_SECRET_KEY', 'your-secret-key' );

Then create wp-content/plugins/sajjad-login-turnstile/sajjad-login-turnstile.php:

<?php
/**
 * Plugin Name: Login Turnstile
 * Description: Adds Cloudflare Turnstile to the WordPress login form.
 * Version:     1.0.0
 * Author:      Sajjad
 */

if ( ! defined( 'ABSPATH' ) ) {
    exit;
}

/**
 * Load the Turnstile script on the login page.
 */
function sajjad_turnstile_enqueue() {
    wp_enqueue_script(
        'cf-turnstile',
        'https://challenges.cloudflare.com/turnstile/v0/api.js',
        array(),
        null,
        array( 'strategy' => 'defer' )
    );
}
add_action( 'login_enqueue_scripts', 'sajjad_turnstile_enqueue' );

/**
 * Output the Turnstile widget inside the login form.
 */
function sajjad_turnstile_widget() {
    if ( ! defined( 'SAJJAD_TURNSTILE_SITE_KEY' ) ) {
        return;
    }

    printf(
        '<div class="cf-turnstile" data-sitekey="%s" style="margin-bottom:16px;"></div>',
        esc_attr( SAJJAD_TURNSTILE_SITE_KEY )
    );
}
add_action( 'login_form', 'sajjad_turnstile_widget' );

/**
 * Verify the Turnstile token when the login form is submitted.
 */
function sajjad_turnstile_verify( $user, $username, $password ) {
    // Only check submissions from the wp-login.php form.
    // phpcs:ignore WordPress.Security.NonceVerification.Missing
    if ( ! isset( $_POST['log'] ) || ! defined( 'SAJJAD_TURNSTILE_SECRET_KEY' ) ) {
        return $user;
    }

    // Don't stack errors on top of an earlier failure.
    if ( is_wp_error( $user ) && in_array( 'empty_username', $user->get_error_codes(), true ) ) {
        return $user;
    }

    // phpcs:ignore WordPress.Security.NonceVerification.Missing
    $token = isset( $_POST['cf-turnstile-response'] )
        ? sanitize_text_field( wp_unslash( $_POST['cf-turnstile-response'] ) )
        : '';

    if ( '' === $token ) {
        return new WP_Error(
            'captcha_missing',
            __( '<strong>Error:</strong> Please complete the security check.', 'sajjad' )
        );
    }

    $response = wp_remote_post(
        'https://challenges.cloudflare.com/turnstile/v0/siteverify',
        array(
            'timeout' => 10,
            'body'    => array(
                'secret'   => SAJJAD_TURNSTILE_SECRET_KEY,
                'response' => $token,
                'remoteip' => isset( $_SERVER['REMOTE_ADDR'] )
                    ? sanitize_text_field( wp_unslash( $_SERVER['REMOTE_ADDR'] ) )
                    : '',
            ),
        )
    );

    if ( is_wp_error( $response ) ) {
        return new WP_Error(
            'captcha_unavailable',
            __( '<strong>Error:</strong> The security check could not be verified. Please try again.', 'sajjad' )
        );
    }

    $body = json_decode( wp_remote_retrieve_body( $response ), true );

    if ( empty( $body['success'] ) ) {
        return new WP_Error(
            'captcha_failed',
            __( '<strong>Error:</strong> The security check failed. Please try again.', 'sajjad' )
        );
    }

    return $user;
}
add_filter( 'authenticate', 'sajjad_turnstile_verify', 30, 3 );

A few things to note about this code:

  • Priority 30 runs the check after WordPress's own username and password checks, which run at priority 20.
  • The $_POST['log'] check means the CAPTCHA only applies to the wp-login.php form. Other login paths like application passwords and XML-RPC aren't affected, which is intentional, since they can't show a widget. If you don't use XML-RPC, consider disabling it so bots can't use it to bypass the login form.
  • Fail closed: If Cloudflare can't be reached, login is refused. That's safer, but if you'd rather allow logins during an outage, you could return $user in that branch instead.
  • Test first: Activate the plugin, then test logging in from a private window while keeping your current session open.

If you ever get locked out by this plugin, rename its folder in wp-content/plugins/ via SFTP or your file manager to deactivate it.

You can extend the same pattern to other core forms. The register_form action and registration_errors filter handle registration, and the lostpassword_form action and lostpassword_post action handle password reset requests. At that point, though, a maintained plugin is usually less work.

CAPTCHA Best Practices

  • Protect the forms that actually get abused: Login, registration, and contact forms are the usual targets. You don't need a CAPTCHA on every form on your site.
  • Don't cache pages with CAPTCHA widgets incorrectly: Some CAPTCHAs use tokens that expire. If your caching plugin serves stale form pages, submissions can fail. Check your form plugin's documentation for caching advice.
  • Consider accessibility: Invisible options like Turnstile and reCAPTCHA v3 are generally easier for users with disabilities than image puzzles.
  • Update your privacy policy: CAPTCHA services process visitor data. Mention the service you use and link to its privacy policy.
  • Check cookie consent requirements: Depending on your location and setup, you may need to consider how CAPTCHA scripts fit with your cookie consent approach.
  • Combine with rate limiting: A plugin like Limit Login Attempts Reloaded or Wordfence adds a second layer that blocks repeat offenders.
  • Monitor after enabling: Watch for a drop in legitimate form submissions or complaints from users who can't log in.

Troubleshooting CAPTCHA Problems

The widget doesn't appear: A caching or optimisation plugin may be delaying or combining the CAPTCHA script. Exclude the provider's script from JavaScript minification and delay features.

"Invalid domain" or key errors: The domain you're testing on isn't registered for that key. Add it in the provider's dashboard, including any staging or www variant.

Every submission fails: Double-check that you haven't swapped the site key and secret key, and that your server can make outbound HTTPS requests to the provider.

Real users are being blocked with reCAPTCHA v3: Lower the score threshold slightly in your plugin settings, or switch to a checkbox or Turnstile if the problem continues.

You're locked out of wp-admin: Rename the CAPTCHA plugin's folder in wp-content/plugins/ to deactivate it, log in, then fix the settings.


FAQ: Adding CAPTCHA to WordPress

It depends on your priorities. Cloudflare Turnstile offers the smoothest experience for users, reCAPTCHA has the widest plugin support, and hCaptcha is a solid privacy-focused alternative. All three work well with WordPress.

Turnstile, hCaptcha, and reCAPTCHA all offer free tiers that cover most small and medium websites. Limits and paid plans change over time, so check each provider's current terms.

It stops most automated attempts through the login form, but not all. Combine it with strong passwords, login rate limiting, and two-factor authentication for real protection.

It adds a small script to pages with protected forms. Most plugins only load it where a form appears, so the impact on the rest of your site is minimal.

Yes. You can use WordPress hooks like login_form and the authenticate filter to add a widget and verify the token on the server, as shown in this guide. For many forms, a plugin is less work to maintain.

CAPTCHA services process personal data such as IP addresses, so you should mention them in your privacy policy. Some site owners choose Turnstile or hCaptcha for their privacy-focused approach.

Rename the CAPTCHA plugin's folder in wp-content/plugins using SFTP or your hosting file manager. WordPress will deactivate it, and you can log in normally to fix the settings.


Conclusion

Adding CAPTCHA to WordPress is mostly a matter of choosing a service, creating a pair of keys, and connecting them to the forms that get abused. For login, registration, and comments, a plugin like Simple Cloudflare Turnstile or hCaptcha for WordPress does the job in a few minutes. For contact forms, Contact Form 7, WPForms, and Gravity Forms all have built-in integrations, and if you want a lean setup, a small custom plugin can add Turnstile to the login page on its own.

Whichever route you take, test in a private window before logging out, keep an eye on legitimate submissions after the change, and remember that CAPTCHA is a filter, not a lock. Paired with strong passwords, rate limiting, and two-factor authentication, it takes most of the automated pressure off your forms and your inbox.

Share :

Related Posts

What are the best WordPress security plugins?

What are the best WordPress security plugins?

The best WordPress security plugins for most sites are Wordfence, Sucuri Security, Solid Security, MalCare, All-In-One Security (AIOS), Patchstack, a

Dive Deeper
What are the most common website security threats?

What are the most common website security threats?

The most common website security threats are vulnerable or outdated software, weak and stolen passwords, malware infections, injection attacks like S

Dive Deeper
What is the difference between posts and pages in WordPress?

What is the difference between posts and pages in WordPress?

The main difference between posts and pages in WordPress is that posts are timely, dated entries that appear in your blog feed, archives, and RSS fee

Dive Deeper