Chuyển đến phần nội dung
WordPress.org

tiếng Việt

  • Giao diện
  • Plugin
  • Tin tức
    • Tài liệu hướng dẫn
    • Diễn đàn
  • Giới thiệu
  • Facebook #WPVN
  • Tải WordPress
Tải WordPress
WordPress.org

Plugin Directory

GridXFlex Captcha Security

  • Gửi một plugin
  • Yêu thích của tôi
  • Đăng nhập
  • Gửi một plugin
  • Yêu thích của tôi
  • Đăng nhập

GridXFlex Captcha Security

Bởi Grid X Flex
Tải về
  • Chi tiết
  • Đánh giá
  • Cài đặt
  • Nhà phát triển
Hỗ trợ

Mô tả

GridXFlex Captcha Security adds a self-hosted image CAPTCHA, backed by a silent honeypot layer, to your site’s Login, Registration, Lost Password, and Comments forms.

Everything is generated on your own server using PHP’s built-in GD library. No requests are ever sent to a third-party service, no API keys are required, and no personal data is stored beyond a short-lived, one-time-use security token.

Features

  • Self-hosted image CAPTCHA (GD-generated, delivered inline as a base64 image — no extra HTTP request)
  • Silent honeypot field on every protected form, on by default
  • Per-form protection toggles: Login, Registration, Lost Password, Comments
  • Configurable character type (alphanumeric / letters / numbers), letter case, and length (3–6 characters)
  • Option to hide the comment captcha for logged-in users
  • One-time-use challenge tokens — each code can be attempted exactly once, then it’s gone
  • No PHP sessions, no cookies set by this plugin, no external requests, no tracking

Why no PHP sessions?

Older captcha plugins commonly call session_start() on every front-end request, even on pages that never show a captcha. That has a real performance cost, breaks under object-cache or load-balanced PHP-FPM pools without sticky sessions, and is incompatible with full-page caching. GridXFlex Captcha Security stores each challenge as a short-lived WordPress transient, keyed by a random token embedded in the form. The token is just a lookup key — the actual secret (a hash of the code) stays server-side — so it remains safe even on a cached page, and each challenge is deleted the instant it’s checked, pass or fail.

Ảnh màn hình

Settings screen under Settings → GridXFlex Captcha.
Settings screen under Settings → GridXFlex Captcha.
The image CAPTCHA as it appears on the login form.
The image CAPTCHA as it appears on the login form.

Cài đặt

  1. Upload the gridxflex-captcha-security folder to /wp-content/plugins/.
  2. Activate the plugin through the “Plugins” screen in WordPress.
  3. Go to Settings → GridXFlex Captcha to choose which forms are protected and adjust the captcha’s appearance.

Hỏi đáp

Does this plugin transmit any data externally?

No. Code generation, image rendering, and verification all happen on your own server using PHP’s built-in GD library. Nothing is sent to any third-party API or service.

Why doesn’t this use PHP sessions?

For compatibility with page caching and load-balanced hosting. Instead of $_SESSION, each challenge is stored as a short-lived WordPress transient keyed by a random token embedded in the form. This works identically behind full-page cache and across load-balanced PHP-FPM pools without sticky sessions, and every challenge is automatically deleted after a single use.

What is the honeypot layer?

A hidden form field that’s invisible to human visitors but often auto-filled by simple bots. If it’s filled in, the submission is rejected the same way a wrong CAPTCHA code would be — no separate “bot detected” message is ever shown, so automated scripts can’t learn which check they failed.

Does this require an API key?

No. This version doesn’t use any third-party CAPTCHA provider.

Does the plugin work if my host doesn’t have the GD PHP extension?

Yes. If GD isn’t available, the image challenge is automatically skipped — protected forms keep working normally, they just fall back to honeypot-only protection instead of erroring out. You’ll see an admin notice explaining this; it clears itself automatically as soon as GD is enabled, no need to reactivate the plugin.

Does the captcha add any visible branding to my site?

An HTML comment — <!-- Powered By GridXFlex WordPress Plugins --> — is placed next to the captcha markup wherever it renders (login, registration, lost password, comments). It isn’t visible in the page as displayed, only in page source.

What happens if someone gets the comment captcha wrong?

They’re redirected back to the same post with an inline error message, and their typed name, email, URL, and comment text are restored — nothing is lost and they don’t leave the page. Login, Registration, and Lost Password show their errors the same way, inline on the same page, using WordPress core’s own error-display mechanism for those forms.

Đánh giá

Không có đánh giá nào cho plugin này.

Người đóng góp & Lập trình viên

“GridXFlex Captcha Security” là mã nguồn mở. Những người sau đã đóng góp vào plugin này.

Những người đóng góp
  • Grid X Flex

Dịch “GridXFlex Captcha Security” sang ngôn ngữ của bạn.

Muốn tham gia phát triển?

Duyệt code, check out SVN repository, hoặc theo dõi nhật ký phát triển qua RSS.

Nhật ký thay đổi

1.0.0

  • Initial release: image CAPTCHA + honeypot for Login, Registration, Lost Password, and Comments forms.
  • Graceful fallback when the GD extension is unavailable: protected forms keep working via the honeypot layer alone instead of erroring; the admin notice re-checks live and clears itself once GD is enabled, no reactivation needed.

Meta

  • Phiên bản 1.0.0
  • Cập nhật lần cuối 4 tuần trước
  • Số lượt cài đặt Ít hơn 10
  • Phiên bản WordPress 5.7 hoặc cao hơn
  • Đã kiểm tra lên đến 7.1.2
  • Phiên bản PHP 7.4 hoặc cao hơn
  • Ngôn ngữ
    English (US)
  • Thẻ
    captchacommentsloginsecurityspam
  • Nâng cao

Đánh giá

Chưa có đánh giá nào được gửi.

Your review

Xem tất cả đánh giá

Những người đóng góp

  • Grid X Flex

Hỗ trợ

Có điều gì muốn nói? cần giúp đỡ?

Xem diễn đàn hỗ trợ

  • Giới thiệu
  • Tin tức
  • Lưu trữ
  • Quyền riêng tư
  • Trưng bày
  • Giao diện
  • Plugin
  • Mẫu khối
  • Học hỏi
  • Hỗ trợ
  • Nhà phát triển
  • WordPress.tv ↗
  • Tham gia
  • Sự kiện
  • Quyên góp ↗
  • Swag ↗
  • WordPress.com ↗
  • Matt ↗
  • bbPress ↗
  • BuddyPress ↗
WordPress.org
WordPress.org

tiếng Việt

  • Truy cập tài khoản X (trước đây là Twitter) của chúng tôi
  • Visit our Bluesky account
  • Visit our Mastodon account
  • Visit our Threads account
  • Xem trang Facebook của chúng tôi
  • Truy cập tài khoản Instagram của chúng tôi
  • Truy cập tài khoản LinkedIn của chúng tôi
  • Visit our TikTok account
  • Truy cập kênh YouTube của chúng tôi
  • Visit our Tumblr account
Viết code như làm thơ.
The WordPress® trademark is the intellectual property of the WordPress Foundation.