Putting a captcha on the WordPress login

A captcha is a box the form puts in the way to tell a person from a program. On the WordPress login it does one very specific job: automated password attempts stop there and never get as far as being checked.

What a captcha does, and what it does not. It stops programs. It does not stop a person who has your password, and it is worth nothing if the password is weak. It remains true that what protects most is the password and the second step: protecting the WordPress login.

The two families, and what each one costs

Type What it gives and what it costs
The plugin’s own captcha A simple sum, a question, or a box to tick. Everything happens on your site: no keys, no account anywhere, and no visitor data leaves here. It is less effective against sophisticated programs and it is plenty for the overwhelming majority of sites.
An outside service A service that studies the visitor’s behaviour and decides. It is more effective. In exchange it needs registration and keys, and sends each visitor’s data to a third party, which has consequences for what you have to declare: personal data protection on your website and the cookie notice and consent.
Start with the simple one. If the goal is to silence the automated attempts filling your log, the plugin’s own captcha does it, with no contracts and no new privacy declarations. Only move to an outside service if the attempts carry on.

Step by step

1 Install the plugin from the official repository. Many security plugins already include a captcha, and in that case do not stack another on top.
2 In the settings, turn the captcha on for the login form only, to begin with. Only once you have confirmed it works should you add it to user registration, password recovery and comments.
3 Before signing out, open a private window and sign in from there. It is the only way to see the form as a visitor sees it. If the captcha does not appear, or appears broken, you still have time.
4 If you use an outside service, paste the two keys it gives you into the right fields, and check the domain is registered on that service’s account. A key from another domain makes the captcha refuse everybody, you included.
A badly configured captcha locks you out of the site. The way out is always the same: in cPanel’s File Manager, rename the plugin’s folder in wp-content/plugins, adding -off. The login goes back to normal.

The three usual stumbles

What happens Why
The captcha does not appear The login page is being cached. Exclude it: installing and tuning a page cache.
It always says the captcha is wrong With an outside service, it is nearly always the server clock being out of step, or a key from another domain. See what time the server is on.
The attempts carry on unchanged They are not going through the form: they are coming in through xmlrpc.php. A captcha does not touch it. Deal with it as described in protecting the WordPress login.

Where else it is worth having

The login is the first place, but not the most rewarding. An unprotected contact form fills your mailbox and can eat through the account’s sending allowance: a contact form that actually reaches your inbox.

And on our side, suspicious requests are already filtered before they reach WordPress. What runs and what we do not claim is in what we do about security.

Locked out by the captcha?

Open a request

SEE ALSO

Password generator

WordPress hosting

Privacy Policy

RECOMMENDED PRODUCT

WordPress hosting

One-click install, updates handled, and speed that holds up.

See plans
  • 0 Users Found This Useful
Was this answer helpful?