Crovly – Proof of Work Captcha & Spam Protection
Crovly is a privacy-first captcha service powered by Proof of Work. Unlike traditional captchas that rely on image puzzles (easily solved by AI) or invasive tracking, Crovly makes the visitor’s browser do computational work to prove it’s not a bot. How it works: Your visitor’s browser solves a small cryptographic puzzle (Proof of Work) Browser fingerprint and environment signals are collected (as a hash — no personal data stored) Behavioral analysis detects automated patterns (mouse, keyboard, scroll) A composite score determines if the visitor is human Key features: Privacy-friendly — No cookies, no cross-site tracking No image puzzles — Invisible to legitimate users Resistant to AI vision attacks — Proof of Work cannot be solved by image recognition IP binding — Tokens are bound to the solver’s IP address Adaptive difficulty — Suspicious visitors receive harder challenges 22+ integrations — Works with major WordPress form plugins Lightweight — Widget is under 25KB gzipped, zero dependencies, 42 languages Supported integrations: WordPress login, registration, lost password, comments WooCommerce (checkout, login, register, lost password, pay for order) Contact Form 7 WPForms Gravity Forms Elementor Pro Forms Ninja Forms Fluent Forms Formidable Forms Forminator Jetpack Contact Form Divi (contact form, login) BuddyPress (registration, activity) bbPress (topics, replies) Ultimate Member (login, register, password reset) MemberPress (checkout, login) Paid Memberships Pro Easy Digital Downloads Mailchimp for WordPress GiveWP wpDiscuz wpForo WordPress Multisite signup Shortcode & PHP support: Use [crovly] shortcode in any page or post, or call crovly_render() and crovly_verify() in your theme templates. External services This plugin relies on the Crovly captcha service to function. It connects to two external endpoints: 1. Crovly Widget CDN (get.crovly.com) The plugin loads the JavaScript widget from https://get.crovly.com/widget.js on any page that contains a protected form. The widget runs Proof of Work in the visitor’s browser and collects a hashed browser fingerprint. When: Loaded on frontend pages that display a protected form (login, register, comment, checkout, etc.) What is sent: Standard HTTP request headers (IP address, user agent). No personal data. Terms of Service: https://crovly.com/terms Privacy Policy: https://crovly.com/privacy 2. Crovly Verification API (api.crovly.com) When a visitor submits a protected form, the plugin sends the generated captcha token to https://api.crovly.com/verify-token for server-side verification. When: On form submission of any form protected by Crovly. What is sent: The captcha token (opaque string), the visitor’s IP address (for IP binding), and your Secret Key (for authentication). What is received: A success/failure response indicating whether the token is valid. Terms of Service: https://crovly.com/terms Privacy Policy: https://crovly.com/privacy Both services are operated by Crovly. No data is shared with third parties. The plugin does not set cookies or track visitors across sites.
Top keywords
- crovly18×3.90%
- form9×1.95%
- com8×1.73%
- crovly com8×1.73%
- https6×1.30%
- login6×1.30%
- visitor6×1.30%
- browser5×1.08%
- forms5×1.08%
- ip5×1.08%
- widget5×1.08%
- work5×1.08%
Cloud Maestro – WAF Security Suite for Cloudflare
Cloud Maestro brings centralized Cloudflare Web Application Firewall (WAF) controls directly into WordPress. Why would I use a plugin when I can create rules in Cloudflare? If you manage multiple Cloudflare-connected sites, Cloud Maestro is a productivity tool that helps oversee several domains from a central dashboard using WordPress. If you only manage one domain in Cloudflare, you wouldn’t benefit from this plugin. It’s useful for someone managing: – Their own sites and client sites – Multiple businesses – Separate Cloudflare accounts People like using Cloud Maestro because configuring security rules one domain at a time is inefficient and error-prone. It allows you to configure WAF rules once and deploy them consistently across all domains in your Cloudflare account — instantly. The free version supports one Cloudflare account with multiple domains. An optional premium version is available for managing unlimited domains across multiple Cloudflare accounts at once. 🛡️ Why Use Cloud Maestro – WAF Security Suite for Cloudflare? Managing security rules across multiple Cloudflare domains is tedious and time-consuming. This plugin streamlines the process, allowing you to: Deploy in One Click – Apply comprehensive WAF rules to multiple domains simultaneously Save Time – No more manually configuring rules on each domain, one at a time Enterprise Security – Protect against bots, aggressive crawlers, malicious IPs, and common threats Reduce Mistakes – Maintain consistent security rules across domains ✅ Free Standard Features One Cloudflare account Multiple domains One-click WAF rule deployment Centralized Cloudflare controls Secure API credential storage (AES-256-CBC encryption) Plugin updates The free plugin does not require an upgrade. 🔥 What Gets Protected The plugin deploys 3 optimized trusted security rules (prior versions used 5) that work together to protect your sites: Good Bot Allowlist – Ensures legitimate bots (Google, Bing, monitoring tools) can access your site Managed Challenges for Suspicious Traffic – Automatically challenges requests from certain ASNs and non-US traffic Aggressive Crawler Protection – Blocks unauthorized crawlers and bots (Yandex, Semrush, Ahrefs, etc.) VPN & Login Protection – Adds extra challenges for VPN traffic and WordPress login attempts Block Known Threats – Automatically blocks web hosts, malicious IPs, TOR nodes, and attack vectors ✨ Premium Upgrade (Optional) For agencies and professionals managing multiple Cloudflare accounts, a Premium version is available with expanded functionality and tech support. Check out our free trial for these features: Multi-Account Management – Automatically manage domains across ALL your Cloudflare accounts Easy Bot Whitelisting – Built-in checkboxes for 50+ trusted services across 8 categories Custom User Agents – Add your own user agent strings to the Good Bot Rule Custom IP Whitelisting – Add trusted IP addresses to the Goot Bot Rule IP Rules management – View and edit Cloudflare’s IP Rules that block or allow access even before hitting WAF rules (and we are working on connecting to fail2ban and Wordfence blocks) Bulk DNS Management – Search and manage all Cloudflare DNS record types across all domains, bulk migrate exact old/new values with confirmation modals, and convert A records to CNAME with a single action DNS Manager Reliability – Full record visibility for MX/TXT and other record types, cleaner cache warm-up modal flow, and safer bulk migration previews that only list actual matches Priority Support – Get expert help when you need it Advanced Customization – Fine-tune rules to match your exact requirements Multi-Account Management – Centrally manage unlimited domains across all your Cloudflare accounts 📋 Important Information Rule Replacement: This plugin replaces existing custom WAF rules on targeted domains. Make sure to back up any custom rules you want to keep. Compatibility: Works with Cloudflare Free, Pro, and Business plans. Not compatible with Enterprise plans managed by hosting providers. Service Monitoring: These rules might challenge some monitoring or uptime services. Check Cloudflare’s Events log if services stop connecting, and add exceptions as needed.