Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms
by Matthias Nordwig 4.8 (50 reviews)

Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms

Invisible spam protection for every form, login and checkout. No puzzles, no checkboxes, no lost visitors — a CAPTCHA your users never see.

Invisible Anti-Spam & CAPTCHA ranks #3,352 among WordPress.org plugins with 4,000+ active installations, is #120 of 1,576 in the Authentication category, a 4.8/5 rating from 50 reviews, and was last updated Aug 25, 2026. Data from WordPress.org, refreshed twice daily — see methodology.

Tested up to WP 7.0.4 (Current: 7.1)
v6.0.0 Current Version v6.0.0
Updated 3 weeks ago Last Update on 25 Aug, 2026
Refreshed 7 hours ago Last Refreshed on
#120 of 1,576 in Authentication Top 5% by installs Downloads -24.9% this week Actively maintained
View on WordPress.org
Rank
#3,352
No change
Active Installs
4K+
-12.9%
KW Avg Position
8
No change
Downloads
79.8K
+5 today
Support Resolved
91%
No change
Rating
96%
Review 4.8 out of 5
4.8 (50 reviews)

Next Milestone 5K

Total Progress 82.3%
4K+ 5K+
84
Ranks to Climb
-
Growth Needed
8,000,000
Active Installs
Pro

Unlock Exact Install Count

See the precise estimated active installs for this plugin, calculated from real-time ranking data.

  • Exact install estimates within tiers
  • Track install growth over time
  • Milestone progress predictions
Upgrade to Pro
Need 177 more installs to reach 5K+

Rank Changes

3,345 3,353 3,360 3,368 3,375 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026
3,342 3,359 3,376 3,393 3,410 01-09-2026 02-09-2026 03-09-2026 04-09-2026 05-09-2026 06-09-2026 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026
Current #3,352
Change
Best #

Upgrade to Pro

Unlock 30-day and 90-day rank history charts with a Pro subscription.

Upgrade Now

Active Installs Growth

Active Installs 0,000,000+
Growth +0.0%
Peak 0,000,000

Downloads Growth

0 50 100 150 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026
0 50 100 150 01-09-2026 02-09-2026 03-09-2026 04-09-2026 05-09-2026 06-09-2026 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026
Downloads
Growth
Peak

Upgrade to Pro

Unlock 30-day, 90-day, and yearly download history charts with a Pro subscription.

Upgrade Now

Reviews & Ratings

4.8
50 reviews
Overall 96%
5
48 (96%)
4
0 (0%)
3
0 (0%)
2
0 (0%)
1
2 (4%)

Support Threads Overview

Resolved
Unresolved
11
Total Threads
10
Resolved
1
Unresolved
91%
Resolution Rate

TL;DR

AI summary of the plugin's readme

This plugin is for WordPress site owners and agencies who want spam protection across every login, comment, checkout and form builder on a site. It solves spam without CAPTCHAs or external services by having the visitor's browser silently solve a proof-of-work challenge instead of showing puzzles or checkboxes.

  • Invisible proof-of-work challenge
  • Protects WordPress logins and comments
  • WooCommerce checkout and reviews support
  • Auto-detects popular form builders
  • Direct analysis mode for custom forms
  • Brute-force login protection
  • Adaptive under-attack mode
  • No cookies, IPs stored as hashes

Frequently Asked Questions

Common questions about Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms

Yes. For the kind of spam that plagues almost every site — automated, mass-sent — the typical experience after activation is that it simply stops: every message now costs the sender real computing power, which breaks the economics of sending thousands of them. That result has held up across years of production use. And the protection is actively maintained: when a new generation of protocol-aware bots learned to reuse a solved challenge across many submissions, version 5.0 closed that route with single-use, signed tokens. For the rare rest — targeted spam written by humans — the flag-and-inbox workflow keeps you in control instead of promising magic.
No. There is nothing to see, click or solve. The proof-of-work runs in the background while the visitor fills in the form and is typically finished in milliseconds — long before they hit Send.
No. Unlike reCAPTCHA, hCaptcha or Turnstile there is no external service involved — no keys, no registration, no third-party scripts, no rate limits.
No. The plugin ships a few kilobytes of JavaScript, loads no external resources and causes no layout shift. The computation happens on the visitor's device in the background; the server-side check is a single fast lookup.
Yes. The challenge token is fetched via Ajax at runtime, so fully cached pages stay protected. One thing to know: right after installing or updating, clear your page cache once so the plugin's JavaScript is included everywhere.
All public forms — including hand-coded and custom ones. The plugin recognizes submissions by their signature (the request's characteristic fields and actions) instead of integrating with specific form plugins, so it is not limited to a fixed list. WordPress core, WooCommerce and the several dozen builders listed above come pre-configured; any other form is added without code in under a minute via direct analysis mode: submit it once, click save.
Everything stays on your server: no cookies, no sessions, no tracking, no external requests. IP addresses are only stored as SHA-256 hashes, and password fields are never stored with saved messages. That means no consent banner is needed for the spam protection — friendly to GDPR (DSGVO, RGPD) and similar privacy laws.
Yes: checkout, login, registration, password reset, comments and product reviews are covered out of the box.
Every submission has to pay for itself with a small proof-of-work computation. This makes mass spam economically expensive and silently filters out low-effort bots — the vast majority of spam. Like any anti-spam solution (including CAPTCHAs), it cannot fully prevent targeted, low-volume spam sent by a determined human or a bot that invests real computing power per message; for those rare cases, use the flag-instead-of-block option and the spam inbox to keep an eye on what comes through. Submissions are incorrectly treated as spam Right after installation this is usually a caching issue: the proof-of-work JavaScript is not yet included in cached pages. Clear the cache on your webserver (or caching plugin) and in your browser. JavaScript might crash due to an incompatibility with another plugin. Press F12 on the affected page and check the browser console for errors — and please report the issue in the support forum; such reports are usually addressed within a day. A real message was refused as "Gibberish content" Since 6.0, gibberish detection is off unless you switch it on for individual fields, so this should no longer happen on its own. If you did switch it on for a field: open the message, look at the reason line — it names the field that triggered it — and use that field's button to stop checking it. Fields carrying tokens, licence keys or reference numbers are random by design and are not suitable for this check; message and subject fields are. Neither messages nor spam show up in the inbox Activate the Analysis mode Submit the affected form and look for the captured entry in the Analytic Box Open the entry and add it to the protection scope If the submission does not appear there either, please post in the support forum After updating, (almost) every submission is flagged as spam The protection works by having the visitor's browser silently solve a small puzzle before a form is submitted. If that puzzle is never solved, a genuine submission looks exactly like a bot, so it gets flagged. Right after an update there are three common reasons for this, all quick to rule out: Stale server code / OPcache. The update changed the database schema, but your server may still be running the previous version's PHP code from its OPcache — the two no longer match. Flush the OPcache (restart PHP-FPM, or use your host's "Flush OPcache" button), then clear any page/object cache. 5.1 also tries to do this automatically on update, but some hosts still need it done once by hand. A cached page serving the old script. If a full-page cache is serving pre-update HTML, browsers load the previous version's script against the new server. Purge your page cache (and CDN) once after updating. A reverse proxy / CDN without Trusted Proxies set. If your site sits behind Cloudflare, a load balancer or similar and the plugin sees the proxy's IP instead of the visitor's, the check cannot line up. Set your proxy's address under Settings → Trusted proxies. To confirm which one it is: open the affected page, press F12 → Console, and look for a warning from "gdpr-recaptcha"; on the Network tab, check that the get_stamp request returns clean JSON (no PHP notice/HTML before it). Sharing that in the support forum pins it down immediately. Problems with Borlabs Script Blocker
Check the browser console (F12) on the problematic page for messages Post in the support forum with as many details as possible — issues are usually fixed quickly If the protection does not work on a specific form, a short note with the form plugin's name is enough to get it looked at

Sign In / Register

You need to sign in or register to use this feature.