[WordPress] 外掛分享: GDPR Cookieless CAPTCHA for WooCommerce & Forms – captchaapi.eu

首頁外掛目錄 › GDPR Cookieless CAPTCHA for WooCommerce & Forms – captchaapi.eu
WordPress 外掛 GDPR Cookieless CAPTCHA for WooCommerce & Forms – captchaapi.eu 的封面圖片
全新外掛
安裝啟用
尚無評分
剛更新
最後更新
問題解決
WordPress 6.0+ PHP 7.4+ v2.2.1 上架:2026-06-03

內容簡介

GDPR Cookieless CAPTCHA for WooCommerce & Forms 是一款針對 WooCommerce 和各種表單的無 Cookie 驗證外掛,旨在防止垃圾郵件而不影響用戶隱私。它在背景中運行,無需用戶點擊任何驗證圖片,並且完全符合歐盟隱私法規。

【主要功能】
• 支援 WooCommerce 和多種表單外掛
• 無需 Cookie 和 Cookie 機制
• 背景運行的驗證過程
• 免費方案可供商業使用
• 符合歐盟數據保護規範

外掛標籤

開發者團隊

⬇ 下載最新版 (v2.2.1) 或搜尋安裝

① 下載 ZIP → 後台「外掛 › 安裝外掛 › 上傳外掛」
② 後台搜尋「GDPR Cookieless CAPTCHA for WooCommerce & Forms – captchaapi.eu」→ 直接安裝(推薦)
📦 歷史版本下載

原文外掛簡介

Protects WooCommerce (login, registration, lost password, checkout), Contact Form 7, WPForms, Fluent Forms, Formidable Forms, Forminator, Gravity Forms and Elementor Forms – cookieless, EU-hosted, no cookie banner required.
A privacy-first alternative to reCAPTCHA: captchaapi.eu stops form spam without making your visitors click traffic lights. A free tier with commercial use allowed gets you started. The work happens in the background: the visitor’s browser solves a small proof-of-work puzzle while they fill in the form, and a token rides along with the submission. There is nothing to solve and nothing to see.
When a form is submitted, your server confirms that token with captchaapi.eu over a single request, secured by your secret key. It is the same model every hosted CAPTCHA uses, and it keeps the secret on your server, never in the browser.
Privacy by design

No cookies, and nothing to add to a cookie banner.
No tracking and no visitor profile. The IP address is used only for rate limiting and abuse detection, then dropped; it is never written to a database.
Hosted only in the EU, in Nuremberg, Germany. No data leaves the EU.
No images and no puzzles to solve. The check runs in the background, so it works the same for every visitor, including people who find image challenges difficult or browse with a screen reader.
A free tier, with commercial use allowed.

Forms and plugins it protects
WordPress core:

Login (wp-login.php)
Registration
Lost password
Comments

WooCommerce:

Login
Registration
Lost password
Checkout

Form plugins:

Contact Form 7
WPForms
Fluent Forms
Formidable Forms
Forminator
Gravity Forms
Elementor Forms

Each form can be turned on or off from the settings screen. The WooCommerce and form-plugin options appear only when that plugin is active.
How it works

The widget loads on the pages with a protected form and solves a proof-of-work puzzle in a Web Worker.
On submit, it attaches the resulting token to the form.
The plugin confirms the token with captchaapi.eu using your secret key and rejects the submission if the service does not accept it.

Each token verifies exactly once – the service enforces single use – so the plugin keeps no local replay table and nothing to clean up on a schedule.
You need an account
This plugin connects to the captchaapi.eu service. If you have no account yet, the Connect button on the settings screen creates one and fills both keys in for you. If you already have one, create a project at https://captchaapi.eu and copy the two keys across by hand. A free tier is available.
External services
This plugin connects to captchaapi.eu, a third-party CAPTCHA service, to protect your forms from spam. It is required for the plugin to function.
On any public page that contains a protected form, the plugin loads the service’s widget script (captcha.js) from your configured captchaapi.eu endpoint. The visitor’s browser then communicates with the captchaapi.eu API to perform a proof-of-work challenge and obtain a token that is attached to the form on submit. This happens for every visitor who loads a protected form.
To issue and validate a token the service receives your public site key, the proof-of-work result, and – as with any HTTP request – the visitor’s IP address. The IP address is used for rate limiting and abuse/bot detection (including a coarse, IP-derived country) and is processed transiently: a hashed form and aggregate counters are held briefly in a cache. No raw IP address and no per-visitor record are written to a database. The service sets no cookies. Data is processed on servers in the EU (Nuremberg, Germany).
When a protected form is submitted, your server sends the token to the captchaapi.eu /verify endpoint, authenticated with your secret key, and trusts the service’s accept-or-reject answer. The secret key stays on your server and is never sent to the browser.
Your server also asks the captchaapi.eu /captcha/challenge endpoint whether it would still issue challenges for your site key. This happens in two situations: when you press “Test connection” on the settings screen, and when a protected form arrives with no token at all – which can mean either a stripped submission or a widget that never received a challenge, and the plugin has to know which before it rejects a real visitor. The request sends your public site key and your site’s address; the answer is cached for a few minutes, so a burst of submissions does not become a burst of requests. No visitor data is sent.
When you open the plugin’s settings screen, it asks the captchaapi.eu /api/v1/stats endpoint how much of your account’s monthly allowance has been used, so the Activity panel can show it. The request is authenticated with your secret key and carries nothing about your visitors. It runs only for administrators, only on that screen, and the answer is cached for twelve hours.
If you use the “Connect to captchaapi.eu” button on the settings screen, the plugin sends you to captchaapi.eu to create your free account. That link carries your site’s hostname and the address of this admin screen, so the service knows which site to protect and where to deliver the keys. Nothing is sent until you press the button, and no keys travel through your browser: once you finish signing up, your server fetches them from the captchaapi.eu /api/v1/connect/exchange endpoint over a direct server-to-server call. The button only appears while both key fields are empty – if you already have an account, sign in on captchaapi.eu and paste your keys in by hand.

Service provider: captchaapi.eu
Terms of Service: https://captchaapi.eu/legal/terms
Privacy Policy: https://captchaapi.eu/legal/privacy

延伸相關外掛

文章
Filter
Apply Filters
Mastodon