Configure CAPTCHA Protection
Configure and safely test reCAPTCHA v3, reCAPTCHA v2, Cloudflare Turnstile, or hCaptcha on protected store forms.
Blacklist Manager Premium supports one selected CAPTCHA provider at a time: Google reCAPTCHA v3, Google reCAPTCHA v2 Checkbox, Cloudflare Turnstile, or hCaptcha. The plugin renders the selected provider and verifies its response server-side on the forms you enable.
Open the feature
Go to Blacklist Manager > Settings > Integrations, choose a provider under Select CAPTCHA, enter its credentials, save, and use Test keys.
Google reCAPTCHA v3
- Create a reCAPTCHA v3 key for the production hostname in the reCAPTCHA Admin console. Use a separate key for staging when practical.
- Copy the v3 site key and secret key into the matching v3 fields. A v2 key is not interchangeable.
- Start with the default score threshold of
0.5. Review legitimate and suspicious traffic before making it stricter. - Test every enabled surface: login, registration, comments, and the applicable checkout flow.
v3 returns a risk score rather than displaying a checkbox. A lower score is more suspicious; it is not proof that a visitor is malicious.
Google reCAPTCHA v2 Checkbox
- Create a reCAPTCHA v2 Checkbox key for the required hostname.
- Save the v2 site key and secret key in the v2 fields.
- Confirm the checkbox can be completed and that the form submits successfully.
- Test keyboard navigation and the compact mobile layout used by the store.
Cloudflare Turnstile
- Create a Turnstile widget and begin with the provider-managed mode unless the store has a tested reason to choose another mode.
- Authorize the exact production hostname and use a separate widget for staging.
- Save the sitekey and secret key, then run Test keys.
- Test both a successful challenge and error/retry behavior. Cloudflare test keys belong only in test environments.
Turnstile works even when the website does not use Cloudflare DNS or proxying.
hCaptcha
- Create a sitekey for the store and obtain the account secret from hCaptcha.
- Ensure the sitekey and secret belong to the same account.
- If Domain Allowlisting is available in the account, restrict the sitekey to owned hostnames.
- Use a development hostname rather than assuming
localhostor127.0.0.1will be accepted. - Save the credentials and test successful, expired, and rejected responses.
Security and troubleshooting
- The site key is public; the secret key is not. Rotate a secret immediately if it is exposed.
- If the widget does not load, check Content Security Policy and caching/optimization plugins against the provider’s current requirements.
- If Test keys succeeds but a form fails, confirm the correct provider is selected and that the form surface is enabled.
- Do not copy provider test keys into production; they intentionally provide no real protection.
Official provider documentation
- Google reCAPTCHA v3 guide
- Google reCAPTCHA v2 guide
- Google server-side verification
- Cloudflare Turnstile getting started
- Cloudflare hostname management
- Cloudflare test keys
- hCaptcha Developer Guide
- hCaptcha configuration and allowlisting
Provider documentation and commercial terms can change. These links were verified on August 3, 2026.
Continue from Blacklist Manager Premium documentation to the complete product workflow.
Evaluate product scope on the money page, use the pillar Guide for decisions and trade-offs, and return here for exact configuration.
Did this guide answer your question?
Still stuck?
Open a support request and include this article title, your plugin version, and what you already tried.
Open Support