SecureGate Captcha Lite

Beskrivning

SecureGate Captcha Lite is a high-performance security suite built to safeguard your WordPress site from intrusive spam, malicious bots, and brute-force attacks. Leveraging professional-grade tools like Cloudflare Turnstile alongside our unique Math and Character CAPTCHA fallback system, we ensure your site remains impenetrable while maintaining a seamless, privacy-first experience for legitimate users.

Protect Your Store – Upgrade to Pro Now

Why Choose SecureGate Captcha Lite?

Complete Protection
Secure all critical WordPress forms including admin login, user registration, password reset, and comment submissions. Each form can be individually enabled or disabled based on your needs.

Privacy-First Approach
Built with GDPR compliance in mind. Uses Cloudflare Turnstile for privacy-focused bot detection and includes a self-hosted fallback CAPTCHA that requires zero external API connections.

Lightning Fast Performance
Optimized code that loads only when needed. No bloat, no unnecessary requests, and fully compatible with all major caching plugins to ensure your site remains fast.

Smart Rate Limiting
Intelligent rate limiting prevents brute-force attacks by tracking failed login attempts and automatically locking out suspicious IP addresses temporarily.

Easy to Configure
Intuitive admin interface with clear settings for CAPTCHA providers, protected forms, and security rules. Get started in minutes with sensible defaults.

Core Features

CAPTCHA Providers

  • Cloudflare Turnstile – Modern, privacy-focused CAPTCHA with excellent UX

    • Free forever with generous limits
    • Invisible verification for most users
    • No user frustration with image puzzles
    • Privacy-compliant (no cookies or tracking)
    • Easy API key setup
  • Built-in Fallback CAPTCHA – Self-hosted protection that works always

    • Math challenges (simple arithmetic)
    • Warped text recognition challenges
    • No external dependencies or API keys
    • GDPR compliant by design
    • Perfect for restricted networks

Protected Forms

  • WordPress Login – Protect admin and frontend login forms from credential stuffing
  • User Registration – Stop spam bot registrations instantly
  • Password Reset – Prevent password reset abuse and email flooding
  • Comment Forms – Block spam comments without moderation queues

Security Features

  • Rate Limiting – Configure maximum failed attempts before temporary lockout
  • Automatic IP Blocking – Temporary bans for suspicious IPs based on behavior
  • Customizable Thresholds – Set your own limits for attempts and lockout duration
  • Admin Exemptions – Administrators are automatically exempt to prevent lockouts
  • IP Allowlisting – Bypass CAPTCHA for trusted IP addresses

Privacy & Compliance

  • GDPR Ready – Anonymized IP logging with automatic expiration
  • Data Minimization – Only essential data is stored as transients
  • 7-Day Auto-Cleanup – All logs automatically deleted after 7 days
  • No External Tracking – Built-in CAPTCHA requires no third-party services
  • User Control – Administrators can disable all logging if desired

Performance Optimizations

  • Conditional Loading – Scripts load only on protected pages
  • Zero Impact – No performance degradation on unprotected pages
  • Cache Friendly – Works seamlessly with WP Rocket, W3 Total Cache, LiteSpeed Cache
  • Lightweight Assets – Optimized CSS and JavaScript for minimal footprint
  • Database Efficiency – Uses WordPress transients instead of permanent database rows

Perfect For

  • Bloggers – Protect comments from spam without moderation
  • Membership Sites – Secure registration and login processes
  • Business Websites – Prevent fake registrations and form abuse
  • Personal Blogs – Simple setup with powerful protection
  • Portfolio Sites – Keep contact forms and comments spam-free

Technical Specifications

  • WordPress Version: 5.8 or higher
  • PHP Version: 7.4 or higher (PHP 8.0+ recommended)
  • Multisite Compatible: Yes
  • Translation Ready: Yes (with .pot file included)
  • Performance Impact: Negligible (loads only on protected forms)
  • Browser Support: All modern browsers (Chrome, Firefox, Safari, Edge)

Supported CAPTCHA Providers

Cloudflare Turnstile
Turnstile is Cloudflare’s modern, privacy-preserving alternative to traditional CAPTCHAs. It uses sophisticated browser challenges that are invisible to most legitimate users while effectively blocking bots.

Built-in Fallback CAPTCHA
Our self-hosted CAPTCHA system offers two challenge types:
Math Challenges: Simple arithmetic problems (e.g., ”What is 7 + 3?”)
Text Recognition: Warped text characters requiring human recognition

Both are effective against automated bots while remaining accessible to humans.

Comparison with Other CAPTCHA Plugins

Unlike many CAPTCHA plugins that rely solely on external services, SecureGate Captcha Lite provides:
– Multiple provider support with automatic fallback
– Self-hosted option for complete independence
– Advanced rate limiting built-in
– Modern, user-friendly admin interface
– Regular updates and active development
– Clean, well-documented code

Privacy & Data Collection

What Data Does This Plugin Collect?

SecureGate Captcha Lite is designed with privacy as a core principle:

Stored Locally (in your WordPress database as transients):
* Anonymized IP addresses (last octet removed)
* Timestamp of verification attempts
* Success/failure status of CAPTCHA verifications
* Failed attempt counters for rate limiting

NOT Stored:
* User emails or usernames
* Personal identifying information
* Browser fingerprints
* Tracking cookies (plugin-side)
* Permanent user profiles

External Service Data:
When Cloudflare Turnstile is enabled, user browser data is sent to Cloudflare for bot detection. Please review Cloudflare’s Privacy Policy for details.

When using the Built-in CAPTCHA, NO external services are contacted.

Data Retention:
All logs are stored as WordPress transients and automatically deleted after 7 days. Administrators can disable logging entirely in settings.

Right to Erasure:
No personal data is collected that would require manual erasure requests under GDPR.

Support & Documentation

Need Help?

  • Documentation: Visit the plugin page for guides and tutorials
  • Support Forum: Get help from the community at WordPress.org Support
  • Bug Reports: Report issues on the support forum
  • Feature Requests: Share your ideas on the support forum

Response Time:
We monitor the support forum regularly and aim to respond within 24-48 hours for most queries.

Credits & Acknowledgments

Developed with ❤️ by R.Sabbir

Special Thanks:
* Cloudflare team for Turnstile
* WordPress community for feedback
* Early adopters and beta testers

Third-Party Services:
When Cloudflare Turnstile is enabled, this plugin connects to Cloudflare’s servers for CAPTCHA verification. By using Turnstile, you agree to Cloudflare’s Terms of Service and Privacy Policy.

About the Developer

R.Sabbir is a WordPress security specialist focused on creating user-friendly security solutions for WordPress sites. With years of experience in web development and security, the SecureGate Captcha plugin series aims to make enterprise-grade security accessible to everyone.

Other Plugins:
* Stay tuned for more security-focused WordPress plugins!

Rate This Plugin

If SecureGate Captcha Lite has helped protect your site, please consider leaving a 5-star review. Your feedback helps us improve and motivates continued development!

Skärmdumpar

  • General Settings – Clean, modern interface for enabling protection and configuring global settings
  • CAPTCHA Providers – Easy provider selection with Turnstile and Built-in options
  • Protected Forms – Granular control over which forms to protect with visual toggles
  • Security Rules – Configure rate limiting and lockout duration.
  • Turnstile on Login – Example of Cloudflare Turnstile on WordPress Admin login page
  • Built-in Math CAPTCHA – Example of self-hosted math challenge
  • Built-in Text CAPTCHA – Example of self-hosted text recognition challenge

Installation

Automatic Installation (Recommended)

  1. Navigate to Plugins > Add New in your WordPress dashboard
  2. Search for ”SecureGate Captcha Lite”
  3. Click Install Now on the SecureGate Captcha Lite plugin
  4. Click Activate once installation completes
  5. Go to SecureGate > General Settings to configure

Manual Installation

  1. Download the plugin ZIP file from WordPress.org
  2. Navigate to Plugins > Add New in your WordPress dashboard
  3. Click Upload Plugin at the top of the page
  4. Choose the downloaded ZIP file and click Install Now
  5. Click Activate Plugin after installation
  6. Go to SecureGate > General Settings to configure

Configuration Steps

For Cloudflare Turnstile:
1. Visit Cloudflare Turnstile
2. Create a free account if you don’t have one
3. Add your site and obtain Site Key and Secret Key
4. Navigate to SecureGate > Providers in WordPress
5. Select ”Cloudflare Turnstile” as your provider
6. Enter your Site Key and Secret Key
7. Save changes

For Built-in CAPTCHA:
1. Navigate to SecureGate > Providers
2. Select ”Built-in” as your provider
3. Choose ”Math” or ”Text” challenge type
4. Save changes (no API keys needed!)

Enable Protected Forms:
1. Go to SecureGate > Protected Forms
2. Toggle on the forms you want to protect
3. Save changes

Vanliga frågor

Is this plugin completely free?

Yes! SecureGate Captcha Lite is 100% free with no hidden costs, premium upsells within the plugin interface, or feature limitations beyond what is advertised. All core features for WordPress form protection are included.

Do I need API keys to use this plugin?

It depends on your chosen provider:
Built-in CAPTCHA: No API keys required – works immediately
Cloudflare Turnstile: Free API keys required (takes 2 minutes to obtain)

Will this slow down my website?

No. The plugin is performance-optimized and only loads necessary scripts on pages with protected forms. On unprotected pages, there is zero performance impact.

Is it GDPR compliant?

Yes. The plugin is designed with privacy in mind:
– IP addresses are anonymized before storage
– All logs expire automatically after 7 days
– No user personal data is collected or stored
– Built-in CAPTCHA requires no external services

Can I use this with caching plugins?

Absolutely! SecureGate Captcha Lite is fully compatible with all major caching solutions including:
– WP Rocket
– W3 Total Cache
– LiteSpeed Cache
– WP Super Cache
– Autoptimize
– And more…

What happens if Cloudflare Turnstile is down?

The plugin includes intelligent fallback logic. If Turnstile fails to load or verify, the system automatically falls back to the built-in CAPTCHA, ensuring your forms remain protected at all times.

Will administrators be locked out?

No. Administrators (users with ’manage_options’ capability) are automatically exempt from CAPTCHA challenges to prevent accidental lockouts during configuration or emergencies.

Can I customize the appearance?

Yes! The plugin includes theme options for CAPTCHA widgets (Light/Dark mode) and uses WordPress-standard styling that inherits your theme’s design. Custom CSS can be added for advanced styling needs.

Does it work on multisite installations?

Yes. The plugin is multisite-compatible and can be network-activated or activated individually per site.

How long are blocked IPs banned?

By default, IPs are temporarily blocked for 30 minutes after exceeding the failed attempt threshold. This duration is customizable in SecureGate > Security Rules.

Can I whitelist specific IP addresses?

Yes. Navigate to SecureGate > Security Rules to add trusted IP addresses that will bypass CAPTCHA verification.

Is there a Pro version?

Yes! SecureGate Captcha Pro is the ultimate security solution for WooCommerce and WordPress stores. While the Lite version provides essential protection, the Pro version is designed for serious businesses that need advanced defense against sophisticated bot attacks and localized threats.

Get SecureGate Captcha Pro

Why SecureGate Pro is the Best Solution for Your Store:

  • Google reCAPTCHA v2 & v3 Integration: Use the world’s most trusted CAPTCHA technology. v3 offers 100% invisible protection without interrupting the user experience.
  • Enterprise-Grade hCaptcha Support: Advanced bot detection with privacy-focused hCaptcha enterprise features.
  • Comprehensive WooCommerce Protection: Secure every step of the customer journey, from account creation and login to the final checkout process.
  • Geographic (Geo-Location) Blocking: Stop attacks before they reach your server by blocking entire countries or regions known for high bot activity.
  • Advanced Analytics & Reporting: Gain deep insights into security threats with real-time charts, provider popularity data, and CSV export capabilities.
  • Smart IP Filtering: Advanced IP address blocking and allowlisting to fine-tune your security rules.
  • Priority Expert Support: Get direct access to our security experts for fast resolution of any issues.

Stop losing sales to fraudulent registrations and checkout abuse. Upgrade to SecureGate Pro Now and get the peace of mind your business deserves.

How do I report bugs or request features?

Please use the WordPress.org support forum for bug reports and feature requests. We actively monitor and respond to all threads.

Can I contribute to development?

Yes! We welcome contributions. Please visit our GitHub repository (link in plugin header) to submit pull requests or report issues.

Recensioner

Detta tillägg har inga recensioner.

Bidragsgivare och utvecklare

”SecureGate Captcha Lite” är programvara med öppen källkod. Följande personer har bidragit till detta tillägg.

Bidragande personer

Översätt ”SecureGate Captcha Lite” till ditt språk.

Intresserad av programutveckling?

Läs programkoden, kika på SVN-filförvaret eller prenumerera på utvecklarloggen via RSS.

Ändringslogg

1.0.1 – 2026-01-18

  • Improved: Plugin information and functionality refinements

1.0.0 – 2026-01-04

  • Initial Public Release
  • Added Cloudflare Turnstile support
  • Added Built-in Fallback CAPTCHA (Math & Text)
  • Implemented WordPress Core form protection (Login, Registration, Password Reset, Comments)
  • Added Rate Limiting with customizable thresholds
  • Implemented Automatic IP blocking for suspicious activity
  • Added IP Allowlist functionality
  • Included GDPR-compliant logging with auto-expiration
  • Created modern admin interface with tabbed navigation
  • Implemented real-time settings validation
  • Added comprehensive error handling
  • Included multisite compatibility
  • Added translation readiness with .pot file