{"id":349837,"date":"2026-08-26T13:13:48","date_gmt":"2026-08-26T13:13:48","guid":{"rendered":"https:\/\/cn.wordpress.org\/plugins\/vaptcha-v4\/"},"modified":"2026-08-26T13:13:14","modified_gmt":"2026-08-26T13:13:14","slug":"vaptcha-human-verification","status":"publish","type":"plugin","link":"https:\/\/mai.wordpress.org\/plugins\/vaptcha-human-verification\/","author":17991531,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.3","stable_tag":"1.0.3","tested":"7.1","requires":"6.0","requires_php":"7.4","requires_plugins":null,"header_name":"VAPTCHA Human Verification","header_author":"VAPTCHA","header_description":"Adds VAPTCHA human verification to WordPress login, registration, password reset, and comments.","assets_banners_color":"","last_updated":"2026-08-26 13:13:14","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/www.vaptcha.com\/wordpress-plugin\/","header_author_uri":"https:\/\/www.vaptcha.com\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":40,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.3":{"tag":"1.0.3","author":"vaptchateam","date":"2026-08-26 13:13:14"}},"upgrade_notice":[],"ratings":[],"assets_icons":[],"assets_banners":[],"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.3"],"block_files":[],"assets_screenshots":[],"screenshots":[]},"plugin_section":[],"plugin_tags":[362,107,602,600,599],"plugin_category":[38,44,54],"plugin_contributors":[149094,277634],"plugin_business_model":[],"class_list":["post-349837","plugin","type-plugin","status-publish","hentry","plugin_tags-captcha","plugin_tags-comments","plugin_tags-login","plugin_tags-security","plugin_tags-spam","plugin_category-authentication","plugin_category-discussion-and-community","plugin_category-security-and-spam-protection","plugin_contributors-vaptcha","plugin_contributors-vaptchateam","plugin_committers-vaptchateam"],"banners":[],"icons":{"svg":false,"icon":"https:\/\/s.w.org\/plugins\/geopattern-icon\/vaptcha-human-verification.svg","icon_2x":false,"generated":true},"screenshots":[],"raw_content":"<!--section=description-->\n<p>VAPTCHA Human Verification is a completely free WordPress human verification plugin. It helps protect standard WordPress forms from automated abuse while keeping the original page layout unchanged.<\/p>\n\n<p>The plugin protects:<\/p>\n\n<ul>\n<li>WordPress login<\/li>\n<li>User registration<\/li>\n<li>Password reset<\/li>\n<li>Comments<\/li>\n<\/ul>\n\n<p>Verification opens only when a visitor submits an enabled form. The plugin does not add a visible verification button or modify the native WordPress form styling.<\/p>\n\n<h4>Free to use<\/h4>\n\n<ul>\n<li>The VAPTCHA Human Verification plugin is completely free to download and use.<\/li>\n<li>The ready-to-use shared verification unit works immediately after activation at no additional cost.<\/li>\n<li>No VAPTCHA account is required for the shared unit.<\/li>\n<li>Site owners can optionally connect their own verification unit for independent statistics and management.<\/li>\n<\/ul>\n\n<h4>Security by design<\/h4>\n\n<p>The plugin follows WordPress security practices and is designed to keep verification credentials and form data protected:<\/p>\n\n<ul>\n<li>VKEY is used only by server-side PHP and is never sent to the browser, HTML, JavaScript, REST responses, or browser developer tools.<\/li>\n<li>Protected forms use WordPress nonces, input sanitization, and escaped output.<\/li>\n<li>Missing, expired, invalid, or forged verification data is rejected.<\/li>\n<li>Verification and network failures fail closed instead of accepting the protected action.<\/li>\n<li>The plugin does not modify WordPress login or comment styles and does not add a public credit link.<\/li>\n<\/ul>\n\n<p>The plugin includes a ready-to-use shared verification unit, so protection works immediately after activation. For independent verification statistics and unit management, create a verification unit at https:\/\/www.vaptcha.com\/ and enter its VID and VKEY on the settings page.<\/p>\n\n<h3>External services<\/h3>\n\n<p>This plugin connects to the VAPTCHA human verification service to protect the WordPress forms selected by the site administrator.<\/p>\n\n<ul>\n<li>When a protected form is displayed, the browser loads the VAPTCHA SDK from <code>https:\/\/c4.vaptcha.com\/src\/v4.js<\/code>.<\/li>\n<li>When a visitor submits a protected form and verification starts, the SDK connects to VAPTCHA service endpoints to provide human verification. VAPTCHA processes the visitor's IP address, browser and device signals (including the user agent), verification-session identifiers, verification results, and the interaction data produced within the verification interface, such as operation timing and trajectory characteristics.<\/li>\n<li>The SDK may use cookies or browser local storage for limited verification-session or device-recognition identifiers. They are used only to help complete verification, reduce repeated verification, prevent abuse, and protect service security; they are not used for advertising or unrelated tracking.<\/li>\n<li>Before WordPress accepts a protected action, the WordPress server sends the VID, VKEY, verification token, verification-session identifier, and visitor IP address to <code>https:\/\/v41.vaptcha.com\/api\/verify<\/code> for server-side verification. The plugin does not send WordPress usernames, passwords, comment text, or other form contents to VAPTCHA.<\/li>\n<\/ul>\n\n<p>The VAPTCHA service is provided by VAPTCHA:<\/p>\n\n<ul>\n<li><a href=\"https:\/\/www.vaptcha.com\/legal#terms\">User Service Agreement<\/a><\/li>\n<li><a href=\"https:\/\/www.vaptcha.com\/legal#privacy\">Privacy Statement<\/a><\/li>\n<\/ul>\n\n<p>By installing and activating the plugin, the site administrator enables this external service for the selected forms and is responsible for providing any notice required for the site's visitors.<\/p>\n\n<h3>Privacy<\/h3>\n\n<p>Protected forms use the external VAPTCHA service. See the <a href=\"https:\/\/www.vaptcha.com\/legal#privacy\">VAPTCHA Privacy Statement<\/a> for the information processed for verification, including the limited use of cookies and browser local storage. No VAPTCHA-powered public credit link is added by this plugin. Site administrators should disclose this processing in their own privacy notice where required.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>vaptcha-human-verification<\/code> folder to <code>\/wp-content\/plugins\/<\/code>, or install the ZIP from the WordPress Plugins screen.<\/li>\n<li>Activate <strong>VAPTCHA Human Verification<\/strong>.<\/li>\n<li>Open <strong>Settings &gt; VAPTCHA Human Verification<\/strong>.<\/li>\n<li>Keep the ready-to-use shared unit, or configure your own VID and VKEY.<\/li>\n<li>Select the forms that should require verification and save.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"is%20this%20plugin%20free%3F\"><h3>Is this plugin free?<\/h3><\/dt>\n<dd><p>Yes. The plugin and the ready-to-use shared verification unit are completely free to use. No registration is required for the shared unit. An independent VAPTCHA unit is optional.<\/p><\/dd>\n<dt id=\"is%20registration%20required%3F\"><h3>Is registration required?<\/h3><\/dt>\n<dd><p>No. The shared verification unit works immediately after activation. Creating an independent unit is recommended when you want separate verification statistics.<\/p><\/dd>\n<dt id=\"is%20vkey%20exposed%20to%20browser%20developer%20tools%3F\"><h3>Is VKEY exposed to browser developer tools?<\/h3><\/dt>\n<dd><p>No. VKEY is used only by server-side PHP when WordPress calls the VAPTCHA verify endpoint. It is never included in HTML or JavaScript.<\/p><\/dd>\n<dt id=\"does%20the%20plugin%20change%20my%20theme%20or%20login%20page%20styles%3F\"><h3>Does the plugin change my theme or login page styles?<\/h3><\/dt>\n<dd><p>No. The plugin adds hidden fields and a submit listener to standard WordPress hooks. Verification opens only after the visitor submits a protected form.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.3<\/h4>\n\n<ul>\n<li>Add detailed external-service, data-processing, and cookie disclosures with direct links to the VAPTCHA User Service Agreement and Privacy Statement.<\/li>\n<\/ul>\n\n<h4>1.0.2<\/h4>\n\n<ul>\n<li>Show independent VID and VKEY fields only when the independent unit mode is selected.<\/li>\n<li>Require both independent credentials before saving that mode.<\/li>\n<li>Replace the standard settings notice with a compact fading success toast.<\/li>\n<\/ul>\n\n<h4>1.0.1<\/h4>\n\n<ul>\n<li>Renamed the plugin and slug to version-neutral VAPTCHA Human Verification.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial WordPress.org submission.<\/li>\n<li>Submit-triggered protection for login, registration, password reset, and comments.<\/li>\n<li>Ready-to-use shared verification unit and optional independent credentials.<\/li>\n<\/ul>","raw_excerpt":"Completely free VAPTCHA human verification for WordPress login, registration, password reset, and comments.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/mai.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/349837","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mai.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/mai.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/mai.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=349837"}],"author":[{"embeddable":true,"href":"https:\/\/mai.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/vaptchateam"}],"wp:attachment":[{"href":"https:\/\/mai.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=349837"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/mai.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=349837"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/mai.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=349837"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/mai.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=349837"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/mai.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=349837"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/mai.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=349837"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}