Crovly – Proof of Work Captcha & Spam Protection
Crovly is a privacy-first captcha service powered by Proof of Work. Unlike traditional captchas that rely on image puzzles (easily solved by AI) or invasive tracking, Crovly makes the visitor’s browser do computational work to prove it’s not a bot. How it works: Your visitor’s browser solves a small cryptographic puzzle (Proof of Work) Browser fingerprint and environment signals are collected (as a hash — no personal data stored) Behavioral analysis detects automated patterns (mouse, keyboard, scroll) A composite score determines if the visitor is human Key features: Privacy-friendly — No cookies, no cross-site tracking No image puzzles — Invisible to legitimate users Resistant to AI vision attacks — Proof of Work cannot be solved by image recognition IP binding — Tokens are bound to the solver’s IP address Adaptive difficulty — Suspicious visitors receive harder challenges 22+ integrations — Works with major WordPress form plugins Lightweight — Widget is under 25KB gzipped, zero dependencies, 42 languages Supported integrations: WordPress login, registration, lost password, comments WooCommerce (checkout, login, register, lost password, pay for order) Contact Form 7 WPForms Gravity Forms Elementor Pro Forms Ninja Forms Fluent Forms Formidable Forms Forminator Jetpack Contact Form Divi (contact form, login) BuddyPress (registration, activity) bbPress (topics, replies) Ultimate Member (login, register, password reset) MemberPress (checkout, login) Paid Memberships Pro Easy Digital Downloads Mailchimp for WordPress GiveWP wpDiscuz wpForo WordPress Multisite signup Shortcode & PHP support: Use [crovly] shortcode in any page or post, or call crovly_render() and crovly_verify() in your theme templates. External services This plugin relies on the Crovly captcha service to function. It connects to two external endpoints: 1. Crovly Widget CDN (get.crovly.com) The plugin loads the JavaScript widget from https://get.crovly.com/widget.js on any page that contains a protected form. The widget runs Proof of Work in the visitor’s browser and collects a hashed browser fingerprint. When: Loaded on frontend pages that display a protected form (login, register, comment, checkout, etc.) What is sent: Standard HTTP request headers (IP address, user agent). No personal data. Terms of Service: https://crovly.com/terms Privacy Policy: https://crovly.com/privacy 2. Crovly Verification API (api.crovly.com) When a visitor submits a protected form, the plugin sends the generated captcha token to https://api.crovly.com/verify-token for server-side verification. When: On form submission of any form protected by Crovly. What is sent: The captcha token (opaque string), the visitor’s IP address (for IP binding), and your Secret Key (for authentication). What is received: A success/failure response indicating whether the token is valid. Terms of Service: https://crovly.com/terms Privacy Policy: https://crovly.com/privacy Both services are operated by Crovly. No data is shared with third parties. The plugin does not set cookies or track visitors across sites.
Top keywords
- crovly18×3.90%
- form9×1.95%
- com8×1.73%
- crovly com8×1.73%
- https6×1.30%
- login6×1.30%
- visitor6×1.30%
- browser5×1.08%
- forms5×1.08%
- ip5×1.08%
- widget5×1.08%
- work5×1.08%
IPIntel AI Firewall
IPIntel AI Firewall (WAF) integrates AI-powered IP reputation analysis into WordPress to help site owners detect and mitigate automated abuse, scanners, and malicious traffic. Incoming requests are evaluated using external reputation signals and risk scoring. Based on the assessed risk level, traffic may be allowed, challenged for human verification, or blocked automatically. The plugin is designed to be easy to use and does not require custom code or infrastructure management. Project website: https://ipintel.ai Features AI-powered IP reputation and risk scoring Automatic allow, challenge, or block decisions Human verification challenge for suspicious traffic Compatible with aggressive caching environments (one-time manual configuration required) Optional visual security badge Simple configuration for non-technical users Free API key available with daily request limits Data Privacy This plugin connects to the IPIntel.ai API to analyze visitor IP addresses for security and threat detection purposes. Data transmitted to the external service: – Visitor IP address – API key (used solely for request authentication) No WordPress user account data, cookies, or User-Agent information are transmitted. The external service is used exclusively to determine whether a request should be allowed, challenged, or blocked. A free API key is available with a daily request limit. Get API key: https://ipintel.ai/dashboard Higher request limits require an upgrade. Terms of Service: https://ipintel.ai/terms Privacy Policy: https://ipintel.ai/privacy Page Cache Compatibility IPIntel AI Firewall relies on per-visitor verification. When full-page caching is enabled, the cache must vary by the verification cookie in order for challenges to work correctly. For LiteSpeed Cache: – Go to LiteSpeed Cache → Cache → Vary – Add the following cookie: ipintel_human_ok – Save changes and purge the cache This is a one-time configuration step. Without cache variation, it is technically impossible for any WordPress plugin to reliably challenge unverified visitors. Optional Footer Badge The plugin includes an optional footer badge that can be enabled from the settings page. When enabled, the badge displays a small visual indicator showing that the site is protected by IPIntel.ai. The badge does not collect data, perform tracking, or load external resources. The footer badge is disabled by default and can be turned on or off at any time.
Top keywords
- ipintel9×2.49%
- ai8×2.22%
- ipintel ai8×