L
Anti-Spam Free WordPress.org

Login Security Captcha

4.9 (20 reviews)
· 10K+ active installs · By ScriptsTown
Active Installs
10K+
Rating
4.9 / 5
Version
v1.9.1
Last Updated
Jun 2026
Share

Plugin Review

AI-Researched

What is Login Security Captcha?

Login Security Captcha is a lightweight security plugin designed to add CAPTCHA validation to critical WordPress forms. It supports Cloudflare Turnstile, Google reCAPTCHA v2, and v3. The plugin targets the login, registration, lost password, and comment forms. This helps prevent spam comments and brute-force attacks.

Developed by ScriptsTown, the plugin is now 7 years old. It has been updated to version 1.9.1 as of Jun 25, 2026. The plugin maintains a 4.9/5 rating from 20 reviews, with 95% of those being 0% one-star. It currently serves 10K+ active installs.

Key Features of Login Security Captcha

  • Cloudflare Turnstile Support — Provides a privacy-focused, friction-free CAPTCHA alternative that does not require user interaction.
  • Google reCAPTCHA v2 and v3 — Offers both the classic checkbox challenge and invisible risk-scoring verification.
  • Multiple Form Protection — Secures login, registration, lost password, and comment forms in a single setup.
  • Customizable Theme and Size — Switch between light or dark themes, and adjust Turnstile size between compact and normal.
  • reCAPTCHA v3 Score Threshold — Set a custom score value to determine what qualifies as suspicious traffic.
  • Error Log Monitoring — View CAPTCHA validation failures directly in the admin panel for troubleshooting.
  • Logged-in User Exemption — Optionally disable CAPTCHA on comment forms for authenticated users to reduce friction.
  • Mixed CAPTCHA Placement — Assign different CAPTCHA versions (e.g., Turnstile on login, reCAPTCHA v2 on comments) to different forms simultaneously.

Who Should Use Login Security Captcha?

This plugin suits site owners who want to prevent brute force attacks on their login page without heavy overhead. The 7-year track record and 10K+ installs indicate it is used by small to mid-sized WordPress sites. Beginners will appreciate the simple settings panel, while developers can rely on the documented API for custom integration.

If you need to add recaptcha to wordpress login forms or want to prevent brute force wordpress login attempts, this plugin covers those needs directly. It is also a strong choice for comment-heavy blogs that want to stop spam without adding a second plugin. The free version includes all core protections, while the Pro version adds login attempt limits and WooCommerce support.

Installation & Setup

Install by uploading the zip file via Plugins > Add New > Upload in your WordPress admin panel, or by FTP upload of the login-security-recaptcha folder to /wp-content/plugins/. Setup is beginner-friendly: after activation, you generate a site key and secret key from either Cloudflare Turnstile or Google reCAPTCHA, then paste them into the plugin’s settings page. The plugin requires WordPress 5.3+ and PHP 7.0+.

Support & Community

Support data for the last 2 months shows 0 open threads and 0 resolved threads, which suggests either very low query volume or that users find the documentation sufficient. The 0% resolution rate is a neutral data point here—it likely reflects the plugin’s simple, self-explanatory nature rather than a support issue. With 95% five-star ratings from 20 total reviews and zero one-star ratings, the user community reports high satisfaction with the plugin’s reliability and performance. The FAQ page provides step-by-step guides for obtaining API keys from both Cloudflare and Google, which covers the most common setup questions.

Pros & Cons

What's Good
  • With 10K+ active installs and a 4.9 rating from 20 ratings (95% five-star), this plugin is widely trusted for adding CAPTCHA to login and comment forms.
  • It supports Cloudflare Turnstile alongside Google reCAPTCHA v2 and v3, allowing you to place different CAPTCHA types on different forms simultaneously.
  • The plugin is lightweight and fast, designed to add CAPTCHA validation with minimal footprint on standard WordPress forms like login, registration, lost password, and comments.
  • It includes an error log monitor and the option to disable CAPTCHA on comment forms for logged-in users, giving you control over user experience.
  • The plugin helps prevent brute-force attacks on login forms and spam comments, with zero support threads reported, indicating stable functionality.
Drawbacks
  • The free version lacks advanced features like limit login attempts by IP and login history tracking, which are only available in the paid Pro version.
  • It does not include any form of two-factor authentication or additional security layers beyond CAPTCHA placement.
  • The plugin only secures standard WordPress forms and does not support custom forms from page builders or third-party plugins without additional code.

Technical Details

Requires WordPress
5.3+
Requires PHP
7.0+
Tested up to WP
7.0
First Released
2019 (7+ years)
Support (last 2 months)
0 threads

Feature Tags

captcha cloudflare login recaptcha security

Frequently Asked Questions