{"id":328965,"date":"2026-06-19T19:16:51","date_gmt":"2026-06-19T19:16:51","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/gatecha-captcha\/"},"modified":"2026-09-09T22:28:07","modified_gmt":"2026-09-09T22:28:07","slug":"gatecha-captcha","status":"publish","type":"plugin","link":"https:\/\/tw.wordpress.org\/plugins\/gatecha-captcha\/","author":23514664,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.1.0","stable_tag":"1.1.0","tested":"7.1.1","requires":"6.0","requires_php":"7.4","requires_plugins":null,"header_name":"GateCHA CAPTCHA","header_author":"GateCHA","header_description":"Self-hosted ALTCHA proof-of-work CAPTCHA via GateCHA. Protects WordPress forms without cookies, fingerprinting, or third-party services.","assets_banners_color":"709e9f","last_updated":"2026-09-09 22:28:07","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/gatecha.org\/wordpress","header_author_uri":"https:\/\/gatecha.org","rating":0,"author_block_rating":0,"active_installs":80,"downloads":503,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"gatecha","date":"2026-06-19 19:16:20","revision":3579143},"1.1.0":{"tag":"1.1.0","author":"gatecha","date":"2026-09-09 22:28:07","revision":3689075}},"upgrade_notice":{"1.1.0":"<p>Adds optional interaction signals for spam that solves the proof-of-work. Nothing changes until you enable it under Settings \u2192 GateCHA.<\/p>","1.0.0":"<p>Initial release.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3579152,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3579152,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256},"icon.svg":{"filename":"icon.svg","revision":3579143,"resolution":false,"location":"assets","locale":false}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3579152,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3579152,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.0","1.1.0"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3689075,"resolution":"1","location":"assets","locale":"","width":2880,"height":2620},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3689075,"resolution":"2","location":"assets","locale":"","width":2880,"height":1580}},"screenshots":{"1":"<p>The GateCHA server dashboard \u2014 challenges, verifications and failures are tracked centrally across all your sites and API keys.<\/p>","2":"<p>One API key per site, each with its own difficulty, challenge TTL and allowed domains, so a single GateCHA instance serves every site you run.<\/p>"}},"plugin_section":[],"plugin_tags":[267985,362,267984,34331,599],"plugin_category":[44,54],"plugin_contributors":[267986],"plugin_business_model":[],"class_list":["post-328965","plugin","type-plugin","status-publish","hentry","plugin_tags-altcha","plugin_tags-captcha","plugin_tags-gatecha","plugin_tags-proof-of-work","plugin_tags-spam","plugin_category-discussion-and-community","plugin_category-security-and-spam-protection","plugin_contributors-gatecha","plugin_committers-gatecha"],"banners":{"banner":"https:\/\/ps.w.org\/gatecha-captcha\/assets\/banner-772x250.png?rev=3579152","banner_2x":"https:\/\/ps.w.org\/gatecha-captcha\/assets\/banner-1544x500.png?rev=3579152","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":"https:\/\/ps.w.org\/gatecha-captcha\/assets\/icon.svg?rev=3579143","icon":"https:\/\/ps.w.org\/gatecha-captcha\/assets\/icon.svg?rev=3579143","icon_2x":false,"generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/gatecha-captcha\/assets\/screenshot-1.png?rev=3689075","caption":"<p>The GateCHA server dashboard \u2014 challenges, verifications and failures are tracked centrally across all your sites and API keys.<\/p>"},{"src":"https:\/\/ps.w.org\/gatecha-captcha\/assets\/screenshot-2.png?rev=3689075","caption":"<p>One API key per site, each with its own difficulty, challenge TTL and allowed domains, so a single GateCHA instance serves every site you run.<\/p>"}],"raw_content":"<!--section=description-->\n<p>GateCHA CAPTCHA connects your WordPress site to your own <a href=\"https:\/\/gatecha.org\">GateCHA<\/a> instance \u2014 a self-hosted, open-source CAPTCHA management service based on the ALTCHA proof-of-work protocol.<\/p>\n\n<p><strong>Why GateCHA?<\/strong><\/p>\n\n<ul>\n<li><strong>Privacy-first<\/strong> \u2014 No cookies, no fingerprinting, no user tracking. Fully GDPR-compliant.<\/li>\n<li><strong>Self-hosted<\/strong> \u2014 Your challenges and verifications stay on your own server. No data goes to third parties.<\/li>\n<li><strong>Proof-of-work<\/strong> \u2014 Bots must solve a computational puzzle. No annoying image puzzles for humans.<\/li>\n<li><strong>Centralized stats<\/strong> \u2014 Track challenges issued, verified, and failed across all your sites from one dashboard.<\/li>\n<li><strong>Interaction signals<\/strong> \u2014 Optional second opinion on each submission, scored from counts and durations alone. Off by default.<\/li>\n<\/ul>\n\n<p><strong>Supported forms:<\/strong><\/p>\n\n<ul>\n<li>WordPress login, registration, password reset, and comments<\/li>\n<li>WooCommerce login, registration, and password reset<\/li>\n<li>Contact Form 7<\/li>\n<li>WPForms<\/li>\n<li>Gravity Forms<\/li>\n<li>Elementor Pro Forms<\/li>\n<li>Forminator<\/li>\n<li>Formidable Forms<\/li>\n<li>HTML Forms<\/li>\n<li>Custom placement via <code>[gatecha]<\/code> shortcode<\/li>\n<\/ul>\n\n<p><strong>Setup in 2 steps:<\/strong><\/p>\n\n<ol>\n<li>Enter your GateCHA instance URL<\/li>\n<li>Enter your API key<\/li>\n<\/ol>\n\n<p>That's it. Enable CAPTCHA on the forms you want to protect.<\/p>\n\n<h3>External Services<\/h3>\n\n<p>This plugin connects to your self-hosted GateCHA instance for CAPTCHA challenge generation and verification. Two API calls are made:<\/p>\n\n<ol>\n<li><strong>GET \/api\/v1\/challenge<\/strong> \u2014 Fetched by the user's browser to obtain a proof-of-work challenge.<\/li>\n<li><strong>POST \/api\/v1\/verify<\/strong> \u2014 Called from your WordPress server to verify the solved challenge.<\/li>\n<\/ol>\n\n<p>One more request happens only when <strong>Collect Interaction Signals<\/strong> is enabled, which it is not by default:<\/p>\n\n<ol>\n<li><strong>GET \/api\/public\/his.js<\/strong> \u2014 The interaction-signal collector, loaded by the user's browser from the same instance. It measures aggregates on the pages that carry a CAPTCHA (durations, event counts, total pointer distance, typing rhythm variance) and hands them to your WordPress server with the form, which forwards them to \/api\/v1\/verify. It reads no field values, no pointer coordinates and no key contents.<\/li>\n<\/ol>\n\n<p>No data is sent to any third-party service. All communication is between your WordPress installation and your own GateCHA instance at the URL you configure in Settings \u2192 GateCHA.<\/p>\n\n<ul>\n<li>GateCHA source code: <a href=\"https:\/\/github.com\/Upellift99\/GateCHA\">https:\/\/github.com\/Upellift99\/GateCHA<\/a><\/li>\n<\/ul>\n\n<h3>Source Code<\/h3>\n\n<p>The full source of this plugin is available at <a href=\"https:\/\/github.com\/Upellift99\/GateCHA-WordPress\">https:\/\/github.com\/Upellift99\/GateCHA-WordPress<\/a>.<\/p>\n\n<p>The plugin's own JavaScript (<code>assets\/js\/gatecha.js<\/code>) and CSS (<code>assets\/css\/gatecha.css<\/code>) are shipped unminified and human-readable.<\/p>\n\n<p>The plugin bundles one third-party library in minified form:<\/p>\n\n<ul>\n<li><strong>ALTCHA widget<\/strong> \u2014 <code>assets\/js\/altcha-widget.min.js<\/code>\n\n<ul>\n<li>Version: 2.2.4<\/li>\n<li>License: MIT<\/li>\n<li>Source code: <a href=\"https:\/\/github.com\/altcha-org\/altcha\">https:\/\/github.com\/altcha-org\/altcha<\/a><\/li>\n<\/ul><\/li>\n<\/ul>\n\n<p>This is the unmodified production build distributed on npm as the <a href=\"https:\/\/www.npmjs.com\/package\/altcha\"><code>altcha<\/code><\/a> package (it corresponds to the package's <code>dist\/altcha.js<\/code> ES module build). To obtain and review the human-readable source, run <code>npm install altcha@2.2.4<\/code> and inspect the package's <code>src\/<\/code> directory on <a href=\"https:\/\/github.com\/altcha-org\/altcha\">GitHub<\/a>.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>gatecha-captcha<\/code> folder to <code>\/wp-content\/plugins\/<\/code><\/li>\n<li>Activate the plugin through the Plugins menu<\/li>\n<li>Go to <strong>Settings \u2192 GateCHA<\/strong><\/li>\n<li>Enter your GateCHA URL and API key<\/li>\n<li>Enable CAPTCHA on the forms you want to protect<\/li>\n<\/ol>\n\n<p><strong>Requirements:<\/strong><\/p>\n\n<ul>\n<li>A running <a href=\"https:\/\/gatecha.org\">GateCHA<\/a> instance<\/li>\n<li>An API key from your GateCHA dashboard (starts with <code>gk_<\/code>)<\/li>\n<\/ul>\n\n<!--section=faq-->\n<dl>\n<dt id=\"what%20is%20gatecha%3F\"><h3>What is GateCHA?<\/h3><\/dt>\n<dd><p>GateCHA is a self-hosted CAPTCHA management service that wraps the ALTCHA proof-of-work protocol. It provides API key management, multi-site support, and an analytics dashboard. See <a href=\"https:\/\/gatecha.org\">the GateCHA website<\/a> for more information.<\/p><\/dd>\n<dt id=\"how%20does%20proof-of-work%20captcha%20work%3F\"><h3>How does proof-of-work CAPTCHA work?<\/h3><\/dt>\n<dd><p>Instead of asking users to solve image puzzles, the browser solves a small computational challenge in the background. This is invisible to legitimate users but expensive for bots trying to submit forms at scale.<\/p><\/dd>\n<dt id=\"is%20my%20api%20key%20secure%3F\"><h3>Is my API key secure?<\/h3><\/dt>\n<dd><p>The API key is used in the browser to fetch challenges, similar to how reCAPTCHA and hCaptcha use site keys. You can restrict your API key to specific domains in your GateCHA dashboard for additional security.<\/p><\/dd>\n<dt id=\"does%20this%20plugin%20send%20data%20to%20external%20services%3F\"><h3>Does this plugin send data to external services?<\/h3><\/dt>\n<dd><p>Only to your own GateCHA instance. No data is sent to any third-party service. See the External Services section below.<\/p><\/dd>\n<dt id=\"what%20are%20interaction%20signals%3F\"><h3>What are interaction signals?<\/h3><\/dt>\n<dd><p>Proof-of-work proves a browser did the work. It does not prove a human filled the form in, and a headless browser solving the challenge passes it exactly like a visitor does. Interaction signals describe how the form was filled: how long the page was open, whether the pointer moved and how far, how many scrolls, touches and keystrokes there were, and how irregular the typing rhythm was. Your GateCHA instance turns those eight numbers into a score between 0 and 1, where higher means more likely automated.<\/p>\n\n<p>Only aggregates leave the browser. Never what was typed, never where the pointer was, never an IP address. Turn it on under <strong>Settings \u2192 GateCHA \u2192 Interaction Signals<\/strong>.<\/p><\/dd>\n<dt id=\"does%20enabling%20interaction%20signals%20block%20anyone%3F\"><h3>Does enabling interaction signals block anyone?<\/h3><\/dt>\n<dd><p>Not by itself. Collection only records scores, which you can watch on your GateCHA dashboard under HIS Monitor. Rejecting flagged submissions is a second, separate setting.<\/p>\n\n<p>Turn that second one on only once you have watched your own traffic, because a false positive is invisible: the visitor cannot submit and will not tell you. To see the scores in your own logs first, hook the <code>gatecha_his_result<\/code> action:<\/p>\n\n<pre><code>add_action( 'gatecha_his_result', function ( $score, $suspected ) { error_log( \"GateCHA HIS $score\" ); }, 10, 2 );\n<\/code><\/pre><\/dd>\n<dt id=\"can%20i%20use%20this%20with%20a%20custom%20form%3F\"><h3>Can I use this with a custom form?<\/h3><\/dt>\n<dd><p>Yes, use the <code>[gatecha]<\/code> shortcode to place the widget anywhere. Then verify the <code>altcha<\/code> POST field server-side.<\/p><\/dd>\n<dt id=\"how%20do%20i%20bypass%20the%20captcha%20for%20automated%20testing%20%28e.g.%20playwright%29%3F\"><h3>How do I bypass the CAPTCHA for automated testing (e.g. Playwright)?<\/h3><\/dt>\n<dd><p>Define a bypass token in your <code>wp-config.php<\/code>:<\/p>\n\n<pre><code>define( 'GATECHA_BYPASS_TOKEN', 'your-secret-test-token' );\n<\/code><\/pre>\n\n<p>Then in your tests, set the <code>altcha<\/code> hidden input to this token before submitting the form:<\/p>\n\n<pre><code>document.querySelector('input[name=\"altcha\"]').value = 'your-secret-test-token';\n<\/code><\/pre>\n\n<p>The plugin will accept the token as a valid verification without contacting the GateCHA server. <strong>Never define this constant in production.<\/strong><\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>Optional interaction signals (HIS), off by default: the collector is loaded from your own GateCHA instance and its aggregates are forwarded to \/api\/v1\/verify on every protected form.<\/li>\n<li>Optional rejection of submissions GateCHA flags as automated, a separate setting from collection.<\/li>\n<li>New <code>gatecha_his_result<\/code> action, fired with the score and the flag on every verification that carried signals, for logging your own traffic before deciding to block on it.<\/li>\n<li>Requires GateCHA 0.7.0 or later for these two settings. Older instances are unaffected and keep working as before.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release.<\/li>\n<li>WordPress login, registration, password reset, and comments integration.<\/li>\n<li>WooCommerce login, registration, and password reset integration.<\/li>\n<li>Contact Form 7, WPForms, Gravity Forms, Elementor Pro, Forminator, Formidable Forms, and HTML Forms integration.<\/li>\n<li><code>[gatecha]<\/code> shortcode for custom form placement.<\/li>\n<\/ul>","raw_excerpt":"Self-hosted ALTCHA proof-of-work CAPTCHA via GateCHA. Protects WordPress forms without cookies, fingerprinting, or third-party services.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/tw.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/328965","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/tw.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/tw.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/tw.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=328965"}],"author":[{"embeddable":true,"href":"https:\/\/tw.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/gatecha"}],"wp:attachment":[{"href":"https:\/\/tw.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=328965"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/tw.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=328965"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/tw.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=328965"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/tw.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=328965"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/tw.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=328965"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/tw.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=328965"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}