LukasApps CAPTCHA tools for Contact Form 7
Protect your Contact Form 7 forms with Google reCAPTCHA V2, Google reCAPTCHA V3, hCAPTCHA, or Cloudflare Turnstile. Easy integration and supports multiple forms on a single page. Four CAPTCHA Options Choose the CAPTCHA provider that works best for you: Google reCAPTCHA V2 — Google’s classic “I’m not a robot” checkbox. Google reCAPTCHA V3 — Google’s invisible, score-based bot verification. hCAPTCHA — A privacy-first alternative that offers robust bot protection while keeping user data secure. Cloudflare Turnstile — A modern CAPTCHA that verifies users in the background, only requiring a simple click if the visitor appears suspicious. Simple Setup Sign up with your chosen CAPTCHA provider and grab your Site Key and Secret Key. Paste them into CF7 Captcha in your WordPress admin. Add protection to any CF7 form in seconds using the shortcode provided in the same settings page. Customizable Appearance Each CAPTCHA widget supports customization options directly from the shortcode: Size — Choose between normal and compact to fit your form layout. Theme — Switch between light and dark themes (or auto for Turnstile) to match your site’s design. Language — Force any CAPTCHA to render in a specific language for your audience. All options are combinable, so you can mix and match to get the exact look you need. Submission Insights (NEW in v0.1.7) Go beyond just blocking spam. Submission Insights gives you full visibility into every form submission: Sender IP — See the IP address of the person who contacted you. Source Page — Know exactly which page on your site the form was filled out on. Device & Browser — Get technical details about the sender’s setup. Want More? Upgrade to CF7 Captcha Pro This free version gives you solid CAPTCHA protection. CF7 Captcha Pro adds six extra layers of spam defense on top of what you already have here, plus a full set of tools to capture and act on every lead your forms collect. What you get with Pro 6-Layer Spam Defense — additional spam-blocking methods that work quietly in the background: – Advanced Honeypot — invisible trap fields with names that regenerate every 24 hours. – Time Limit Validation — bots submit in 0.2 seconds. Humans take 15–30. This blocks anything that moves too fast (or stays too long). – Rate Limiting — caps submissions per IP so bot networks can’t flood your inbox or burn through your email quota. – Geographic Blocking — whitelist only the countries you serve, or blacklist known spam regions. – IP Pattern Blocking — block single IPs, wildcards, CIDR ranges, or entire subnets when you know exactly where an attack is coming from. – Word Filter — scans every submission for spam keywords, phishing URLs, and known scam phrases before it reaches you. Lead Recovery — captures form data in real-time as visitors type, so you don’t lose leads from abandoned forms. Database Storage & Export — every submission is saved with full metadata (IP, browser, referrer, timestamp). Export to CSV, Excel, JSON, or PDF whenever you need it. No more lost leads if your email fails. Webhooks — send form data instantly to any URL. Connect to Zapier, Salesforce, Slack, Google Sheets, or any custom API. Multiple webhooks per form, with retry logic built in. Mailchimp Integration — submissions automatically added to your Mailchimp lists. Field mapping, tags, opt-in handling. Twilio SMS — receive instant alerts for every submission or send automated SMS replies to your clients. Comprehensive Logging — every spam block, webhook call, and integration event is logged. Debug any issue in minutes instead of hours. 👉 Get CF7 Captcha Pro External services This plugin relies on third-party CAPTCHA providers to detect and block spam submissions on your Contact Form 7 forms. Only the service(s) you configure and activate in the plugin settings are contacted. Google reCAPTCHA (v2 and v3) This plugin loads the Google reCAPTCHA script and sends the CAPTCHA response token to Google’s verification API when a protected form is submitted, in order to confirm the submission is not from a bot. The visitor’s IP address is also sent as part of this verification. This service is provided by Google: Terms of Service, Privacy Policy. hCaptcha This plugin loads the hCaptcha script and sends the CAPTCHA response token to hCaptcha’s verification API when a protected form is submitted, in order to confirm the submission is not from a bot. This service is provided by hCaptcha: Terms of Service, Privacy Policy. Cloudflare Turnstile This plugin loads the Cloudflare Turnstile script and sends the CAPTCHA response token to Cloudflare’s verification API when a protected form is submitted, in order to confirm the submission is not from a bot. This service is provided by Cloudflare: Terms of Service, Privacy Policy. These services are only contacted when the corresponding CAPTCHA type is enabled and configured with valid API keys.
Top keywords
- captcha16×2.03%
- form12×1.52%
- google11×1.40%
- submission9×1.14%
- service7×0.89%
- spam7×0.89%
- bot6×0.76%
- cloudflare6×0.76%
- google recaptcha6×0.76%
- hcaptcha6×0.76%
- ip6×0.76%
- recaptcha6×0.76%
Invisible Anti-Spam & CAPTCHA
Spam protection your visitors never see. No image grids, no “I’m not a robot” checkbox, no puzzles, nothing to click. Your visitors just hit Send — while their browser silently solves a tiny cryptographic challenge (proof-of-work) in a few milliseconds. Real humans never notice. Mass-spam bots either fail the challenge or have to burn so much computing power per message that spamming your site stops being worth it. Every form, out of the box. WordPress logins, registrations and comments, WooCommerce checkout and reviews, and virtually every form plugin — Contact Form 7, Elementor Pro Forms, WPForms, Gravity Forms, Ninja Forms, Fluent Forms, Formidable and dozens more (full list below). One plugin protects all of them, and the most popular builders are detected and configured automatically on activation. Truly universal — not a list of integrations Most anti-spam tools protect only the form plugins they ship an integration for. If your builder is not on their list — or you use a hand-coded form, a theme’s built-in form, or three different builders on one site — you are on your own. This plugin works differently: it recognizes submissions by their signature — the characteristic fields and actions of the request itself — instead of hooking into specific form plugins. That is why it covers any form: Popular builders are recognized automatically: their signatures ship with the plugin and are pre-configured on activation. Everything else — custom-coded forms, exotic builders, legacy themes — you teach the spam check yourself in under a minute: turn on direct analysis mode, submit the form once, click save. Done. No code, no waiting for the developer to add your builder. And because no integration code is involved, nothing breaks when your form builder updates. In practice that solves two everyday problems: Real sites mix. A typical site has comments, a contact form from one builder, a newsletter signup from another, WooCommerce reviews — protecting each with its own anti-spam solution means more plugins, more settings pages, more things that can conflict. Here, one plugin covers the whole site. Designers and agencies standardize. If you build sites for clients, you can install the same proven plugin on every project — no matter which form stack the client uses (or switches to later). One tool to know, one place to look when something needs attention. Why “invisible” wins Every CAPTCHA interaction costs you real visitors: an extra click here, an unreadable image there, “select all traffic lights” on a phone screen — and the contact request or sale is gone. This plugin flips the deal: instead of making humans prove themselves, it makes the device pay. The visitor’s browser proves it is a real, JavaScript-running client by doing a moment of invisible computation. Zero friction for people, real costs for bots. Self-contained and featherweight Everything runs on your own web server — there is no external service in the loop. That is not just a privacy nicety, it is an operational one: Nothing external can fail. No third-party API whose outage, rate limit or latency silently breaks your forms. Your spam protection is exactly as available as your site. Nothing external slows you down. No remote scripts, no extra DNS lookups or connections — your PageSpeed and Core Web Vitals stay untouched. Tiny footprint. A few kilobytes of JavaScript and lean server code; runs fine on shared hosting, staging environments and even intranets without internet access. Why not just use … Google reCAPTCHA, hCaptcha or Turnstile? They require an account and API keys, load scripts from external servers (hello, consent banners) and still challenge real users when in doubt. This plugin needs no keys, makes no external requests and never challenges anyone. Akismet? Sends the content of every submission to an external service for analysis, and commercial sites need a subscription. Here, everything stays on your own server. Honeypot fields and time checks? Modern bots skip honeypots routinely, and browser autofill loves to fill them by accident. Proof-of-work attacks the economics of spam instead of playing hide-and-seek. And they all share one structural limit: they protect the forms they ship an integration for. This plugin protects the forms you actually have (see “Truly universal” above). Key features Invisible — zero user interaction, ever Protects everything: logins, registrations, comments, WooCommerce, every form builder — even hand-coded custom forms No account, no API keys, no external services — install and you are done Brute-force protection for logins, with optional Fail2Ban log support Adaptive under-attack mode: the challenge automatically gets harder for everyone while a spam wave is running, and relaxes afterwards Your choice per site: block spam, deliver it flagged, or just collect it in a spam inbox and watch Teach it live: unrecognized custom form? Direct analysis mode adds it with one click, straight from the live page Lightweight: a few KB of JavaScript, no render-blocking, no layout shift Privacy-friendly by design: no cookies, no sessions, no tracking, no data leaves your server, IP addresses are only stored as hashes — GDPR/DSGVO/RGPD-friendly without a consent banner Free Setup Guide Works with WordPress: Login, Registration, Password Reset, Comments WooCommerce: Checkout, Login, Registration, Password Reset, Comments, Product Reviews Form and page builders: Elementor Pro Forms, Contact Form 7, Fluent Forms, Jetpack Forms, Divi Forms, WPForms, Forminator, Thrive Architect & Thrive Apprentice, Gravity Forms, Formidable Forms, Mailchimp for WordPress Forms, BuddyPress Registration Form, bbPress Create Topic & Reply Forms, Ultimate Member Forms, wpDiscuz Custom Comments Form, Easy Digital Downloads Forms, Paid Memberships Pro Forms, MemberPress Forms, WP-Members Forms, WP User Frontend Forms, CheckoutWC & Flux Checkout, Ninja Forms, Everest Forms, WS Forms, Quform, Otter Blocks, Typeform, NEX-Forms, Bit Form, Form Maker, Funnelforms, Mailjet, Jotform, Page Builder, Metform, Calculated Fields Form, JetFormBuilder, weForms, Responsive Contact Form Builder, Zoho Forms, Smart Forms, Kali Forms, Happyforms, ApplyOnline, Subscribe Forms, FormCraft, Advanced Forms, CRM Perks Forms, Tripetto, Formstack, BuddyForms, vcita, Easy Form Builder, SimpleForm Anything not on the list can be added in minutes with the built-in analysis modes — no code required.