xpay✦ Commerce
Directory
WooCommerce plugins
Kitgenix CAPTCHA for Cloudflare Turnstile
Kitgenix CAPTCHA for Cloudflare Turnstile
Add Cloudflare Turnstile to WordPress, WooCommerce and popular forms with server-side verification and anti-spam controls.
5.0
(6 ratings)Will this break my store?
What the WordPress.org registry says about keeping Kitgenix CAPTCHA for Cloudflare Turnstile running.
Tested to 7.1
Tested against the WordPress branch in use today.11 days ago
At least 23.8 releases a year since launch. WordPress.org only lists versions still available for download, so the real number may be higher.8.1
Your host must be running at least this version.6.0
1
A single maintainer. Worth knowing if the plugin is load-bearing for your store.Maintenance & trust
Scored on how Kitgenix CAPTCHA for Cloudflare Turnstile is looked after — not on how many stores run it.
96
out of 100Maintenance
35 / 35WordPress compatibility
20 / 20Support responsiveness
Not enough dataMerchant satisfaction
12 / 15Listing transparency
10 / 10Ratings
5.0
6 ratingsKitgenix CAPTCHA for Cloudflare Turnstile adds Cloudflare Turnstile CAPTCHA and anti-spam protection to WordPress, WooCommerce and a wide range of form, membership, community and ecommerce plugins. Challenges are not treated as a client-side decoration: submitted Turnstile tokens are verified server-side with Cloudflare before a protected action is accepted.
The plugin is designed for site owners who want to reduce automated login attempts, fake registrations, comment spam, bot-driven checkout abuse and unwanted form submissions while using Cloudflare’s privacy-oriented Turnstile challenge rather than a traditional image CAPTCHA.
Configuration, integration controls, diagnostics and local verification metrics are managed inside WordPress. The only service required for CAPTCHA functionality is Cloudflare Turnstile itself; no Kitgenix verification proxy is used.
Learn more about Kitgenix WordPress plugins at Kitgenix.
Supported WordPress and Plugin Integrations
The codebase contains dedicated integrations for:
- WordPress login.
- WordPress registration.
- Lost-password and password-reset flows.
- WordPress comments.
- Custom login forms produced with
wp_login_form(). - WooCommerce login, registration, lost password, checkout and related account flows supported by the integration.
- Easy Digital Downloads.
- Elementor forms.
- Contact Form 7.
- WPForms.
- Gravity Forms.
- Fluent Forms.
- Formidable Forms.
- Forminator.
- Ninja Forms.
- Jetpack Forms.
- JetFormBuilder.
- Kadence Forms.
- MailPoet.
- bbPress.
- BuddyPress.
- wpDiscuz.
- Ultimate Member.
- MemberPress.
- Paid Memberships Pro.
- Kitgenix Plugin Score integration points included in the codebase.
Each integration is loaded conditionally and can use integration-specific display/validation behaviour rather than forcing one generic hook onto every form system.
Server-Side Turnstile Verification
The browser obtains a Turnstile response token from Cloudflare’s official widget. When a protected form is submitted, the plugin sends that token to Cloudflare’s official Siteverify endpoint using the WordPress HTTP API. The protected action is allowed only when the verification result satisfies the integration’s validation flow.
This server-side step is important because simply placing a widget in the browser is not sufficient protection on its own. The plugin tracks the most recent verification response, error codes and latency for diagnostics and can record aggregate verification metrics locally.
Setup Verification for Login-Sensitive Forms
Login, registration and other account-sensitive protections can be gated behind a setup-verification state. The administrator can verify the configured Site Key and Secret Key before those protections are treated as ready.
This reduces the risk of enabling a broken key pair on a login screen and accidentally locking legitimate administrators or customers out of the site.
Site and secret keys can be supplied from plugin settings or from supported environment variables/constants, allowing security-conscious deployments to keep the secret outside the normal WordPress options table.
Replay Protection
Turnstile tokens are intended to be short lived and single use. The plugin includes optional replay protection that hashes accepted tokens and temporarily remembers that hash. A token that is submitted again during the replay window can be rejected rather than being accepted repeatedly.
The replay window is filterable for developers. Stored replay information is a hash/temporary value, not the raw challenge token itself.
Honeypot and Layered Anti-Spam Controls
An optional honeypot can be rendered alongside Turnstile. This adds a second low-friction signal for simple bots that fill fields a normal visitor never sees.
The plugin also supports whitelisting logic so trusted requests can bypass the challenge where appropriate. Whitelist decisions can take account of configured rules and developer filters rather than hard-coding one bypass mechanism for every site.
Trusted Proxy and Client IP Handling
Sites may sit behind Cloudflare, another reverse proxy or a load balancer. The client-IP component can be configured to trust proxy headers only when the request path matches the trusted-proxy configuration. This avoids blindly believing spoofable forwarding headers from arbitrary visitors.
Administrators can also choose whether the resolved visitor IP is included in the Siteverify request to Cloudflare. A developer filter is available to change that behaviour when required by a site’s privacy or infrastructure policy.
Widget Appearance and Placement
The plugin supports central defaults plus integration-level overrides for Turnstile appearance. Depending on the supported integration, administrators can control options such as theme, size, appearance and language, and can choose placement behaviour where the integration exposes more than one suitable hook.
A manual shortcode is also registered:
[kitgenix_turnstile]
The shortcode is useful when the site owner needs to render the widget in a supported custom workflow. Rendering a widget alone does not automatically secure arbitrary custom PHP processing; custom form handlers must still validate the submitted token server-side.
Diagnostics, Metrics and Site Health
The plugin includes diagnostics for configuration and verification health, local counters for passed/failed checks, latency information, recent verification events and integration-level metrics. Site Health integration can surface configuration or connectivity issues to administrators.
Developer Mode adds additional troubleshooting detail without changing the fundamental requirement that live submissions be verified correctly when protection is active.
Settings Portability
Settings can be exported and imported for controlled migration between WordPress installations. The transfer system is designed for plugin configuration rather than for exporting visitor submissions or unrelated site data.
Performance and Script Loading
The public Cloudflare Turnstile script is loaded only for pages/contexts where the plugin determines that a Turnstile widget may be needed. The loader includes duplicate-script detection so multiple integrations do not intentionally enqueue several copies of the same Turnstile API script.
Public assets are kept separate from the admin interface, and admin-only diagnostics/settings code does not need to run as part of every anonymous form request.
Privacy and Data Flow
Turnstile is an external service provided by Cloudflare, so challenge rendering and server-side verification necessarily communicate with Cloudflare. The plugin itself stores configuration and limited diagnostic/aggregate verification data locally. It does not require a Kitgenix account and does not send form contents to Kitgenix for verification.
The exact Cloudflare data flow, WordPress.org Hub request and Google Fonts admin request are documented in the External Services section below.
Common Uses
- Protect a WordPress login page from automated credential attacks.
- Reduce spam registrations on WordPress or WooCommerce.
- Add anti-bot verification to WooCommerce checkout and account forms.
- Protect Elementor and popular WordPress form plugins with one central Turnstile configuration.
- Add a challenge to membership, forum and community registration/login flows.
- Replace more intrusive CAPTCHA experiences with Cloudflare Turnstile while keeping server-side validation.
Developer Notes
Shortcode
[kitgenix_turnstile]
Main settings option
kitgenix_captcha_for_cloudflare_turnstile_settings
Useful filters
Script and display:
kitgenix_captcha_for_cloudflare_turnstile_script_urlkitgenix_turnstile_freshness_mskitgenix_turnstile_inline_style
Verification:
kitgenix_turnstile_siteverify_urlkitgenix_turnstile_siteverify_timeoutkitgenix_turnstile_siteverify_sslverifykitgenix_turnstile_siteverify_http_argskitgenix_turnstile_send_remoteipkitgenix_turnstile_remote_ipkitgenix_turnstile_token_from_requestkitgenix_turnstile_error_codeskitgenix_turnstile_error_messagekitgenix_turnstile_replay_messagekitgenix_turnstile_skip_wp_login_validation
Replay protection:
kitgenix_turnstile_replay_ttl
Whitelisting and proxy handling:
kitgenix_turnstile_is_whitelistedkitgenix_turnstile_trust_headerskitgenix_turnstile_trusted_proxies
Operational alerts:
kitgenix_turnstile_alert_window_secondskitgenix_turnstile_alert_failure_spike_min_failureskitgenix_turnstile_alert_failure_spike_failure_ratekitgenix_turnstile_alert_http_error_min_failures
Developer logging action:
kitgenix_turnstile_dev_log
The plugin also exposes context-specific error-message filtering through kitgenix_captcha_for_cloudflare_turnstile_{context}_turnstile_error_message.
Privacy and Local Data
The plugin stores its configuration in the WordPress database. Depending on enabled features it also stores local operational data such as setup-verification state, aggregate integration metrics, the recent event log and replay-protection transients.
The recent event log is limited to 50 events and contains operational fields such as time, integration, success/failure, error codes and Siteverify latency. It does not store raw form submissions, the raw Turnstile response token, the visitor’s raw IP address or the request URL in that log.
Turnstile itself is an external Cloudflare service and receives data when a widget is loaded and when the server validates a token. See External Services below.
External Services
This plugin relies on third-party services for specific functionality. These connections are documented here so site owners can make an informed decision before enabling and using the plugin.
Cloudflare Turnstile
Cloudflare Turnstile is the CAPTCHA / bot-verification service that provides the plugin’s core protection. A Cloudflare account and Turnstile Site Key / Secret Key are required.
When a protected widget is rendered, the visitor’s browser loads Cloudflare Turnstile from:
https://challenges.cloudflare.com/turnstile/v0/api.js
The browser communicates with Cloudflare as part of the Turnstile challenge. As with normal web requests, Cloudflare can receive network/request information such as the visitor’s IP address and browser/request metadata, and Turnstile evaluates browser signals to generate a verification token.
When a protected form is submitted, the WordPress server sends a POST request to:
https://challenges.cloudflare.com/turnstile/v0/siteverify
By default, that request contains:
- The configured Turnstile Secret Key
- The Turnstile response token
- The visitor IP address as Cloudflare’s optional
remoteipparameter when an address is available
The remoteip value can be disabled by developers with the kitgenix_turnstile_send_remoteip filter.
Cloudflare documentation: https://developers.cloudflare.com/turnstile/
Cloudflare Terms: https://www.cloudflare.com/website-terms/
Cloudflare Privacy Policy: https://www.cloudflare.com/privacypolicy/
WordPress.org Plugin API
The shared Kitgenix Hub in wp-admin uses WordPress core’s plugins_api() functionality to request public WordPress.org plugin-directory information such as plugin details, active-install counts, ratings and media.
These requests occur on Kitgenix administration screens. The plugin supplies WordPress.org plugin slugs to WordPress core; the outbound request itself is handled by WordPress and can include normal HTTP request metadata generated by WordPress. Responses are cached locally with WordPress transients to reduce repeat requests.
WordPress.org: https://wordpress.org/
WordPress.org Privacy Policy: https://wordpress.org/about/privacy/
Google Fonts
The Kitgenix administration stylesheet imports the Inter and Manrope font families from Google Fonts. This occurs on Kitgenix plugin administration screens, not as part of the Turnstile verification request itself.
Loading those font resources causes the administrator’s browser to connect to Google-hosted domains such as fonts.googleapis.com and fonts.gstatic.com, which can receive normal request information such as IP address and browser headers.
Google Fonts: https://fonts.google.com/
Google Privacy Policy: https://policies.google.com/privacy
Google Terms: https://policies.google.com/terms
Trademark Notice
Cloudflare and Cloudflare Turnstile are trademarks or services of Cloudflare, Inc. This plugin is independently developed by Kitgenix and is not affiliated with or endorsed by Cloudflare, Inc.
WordPress and WooCommerce trademarks belong to their respective owners. References are descriptive and identify supported integrations.
Support Development
Kitgenix CAPTCHA for Cloudflare Turnstile is free software. If the plugin is useful to you, you can support continued maintenance and development through the Donate link shown on the WordPress.org plugin page.
More WordPress plugins and development resources are available from Kitgenix.
Cloudflare Turnstile is a CAPTCHA alternative that runs a challenge in the visitor’s browser and produces a token. The token must then be validated server-side before the protected action is accepted.
No. Turnstile can be used on a WordPress site even when the site’s traffic is not proxied through Cloudflare.
Yes. You need a Cloudflare account and a Turnstile Site Key / Secret Key pair.
Yes. Supported integrations validate the token with Cloudflare’s Siteverify endpoint before accepting the protected submission, unless Developer Mode or the relevant per-integration Test Mode is intentionally configured to warn rather than block.
Native WordPress login, registration, lost/reset password and comment forms are supported. The plugin also supports WooCommerce, Easy Digital Downloads, Elementor Pro Forms, Contact Form 7, WPForms, Fluent Forms, Formidable Forms, Forminator, Gravity Forms, JetFormBuilder, Jetpack Forms, Kadence Forms, Ninja Forms and several membership/community plugins.
Yes. The plugin can render Turnstile in block-based checkout and validates the token server-side during the WooCommerce Store API checkout request.
Yes. The plugin declares HPOS compatibility and uses WooCommerce order CRUD methods for its Checkout Blocks verification metadata.
Yes. Automatic placement is available for supported integrations, and many integrations include a shortcode-only placement option. The [kitgenix_turnstile] shortcode can also render a widget manually.
The shortcode can render the widget, but an unsupported custom form still needs a server-side validation integration. Rendering a widget alone is not sufficient security.
Yes. Global theme, size and language settings can be overridden per integration.
Developer Mode is warn-only. Failed verification is recorded but does not block the submission. Individual integrations can also be placed in Test Mode without putting the entire site into warn-only mode.
Replay protection helps reject a Turnstile token that has already been accepted or processed. This reduces the usefulness of captured or repeatedly submitted tokens.
Yes. The optional honeypot can reject simple automated submissions before Cloudflare Siteverify is contacted.
The plugin can whitelist logged-in users, configured IP addresses/ranges and User-Agent strings. Whitelisted visitors do not need to complete Turnstile, and the frontend Turnstile script is skipped for them.
Yes. Proxy-aware IP detection is included. For security, forwarded headers are trusted only when proxy trust is enabled and the connecting proxy matches your configured trusted proxy list.
Developers can return false from the kitgenix_turnstile_send_remoteip filter. See the External Services section for the default data flow.
Yes. The plugin supports the KITGENIX_CAPTCHA_FOR_CLOUDFLARE_TURNSTILE_SITE_KEY and KITGENIX_CAPTCHA_FOR_CLOUDFLARE_TURNSTILE_SECRET_KEY constants and matching environment variables.
Yes. Export settings to JSON and import them using Replace or Merge mode. Credentials are excluded by default unless you explicitly include them.
Check that the Site Key exists, the integration and relevant form toggle are enabled, the visitor is not whitelisted, and another plugin or optimisation rule is not blocking https://challenges.cloudflare.com. Also check the plugin’s duplicate-loader warning and Site Health test.
Turnstile tokens are short-lived and single-use. Cached forms, back-button resubmissions, double-clicks, delayed JavaScript or submitting after a token has expired can all require a fresh Turnstile challenge.
Categories
Plugin details
Tags on WordPress.org
