Home › Guides › Spam without puzzles

Using hCaptcha on a WordPress contact form

hCaptcha is a CAPTCHA service with a free plan and a privacy-focused reputation. Sign up, add your site to get a site key, copy your account's secret, and paste both into your form plugin. Visitors tick a box and occasionally solve an image challenge.

Setting it up

  1. Create an account at hCaptcha and add a site with your domain.
  2. Copy the site key for that site, and the secret from your account settings.
  3. Paste both into your form plugin's CAPTCHA settings.

How the check runs

The hCaptcha script, loaded from js.hcaptcha.com, shows the checkbox and produces a token. When the form is sent, your server passes the token and your secret to api.hcaptcha.com, which answers whether it was solved. Like every CAPTCHA, it means a third party sees your visitors' browsers — mention it in your privacy policy.

In Formsafe Contact Form

Choose hCaptcha under Formsafe → Settings → Spam and paste your keys; the secret is masked once saved. The script loads only on pages with a form.

If hCaptcha says the visitor's answer is wrong, Formsafe asks them to confirm they're human and press Send again, keeping what they typed. The same happens when they press Send without ticking the box, as long as hCaptcha is passing your other visitors. A form sent with no box at all — JavaScript off, or hCaptcha's script blocked — had nothing to tick, so it isn't sent back: while hCaptcha is passing your other visitors, it's saved under Spam with that reason and the visitor sees the normal thank-you, so look there if someone says they wrote. When hCaptcha hasn't passed anyone for about a day, both are taken in without the check, and a notice tells you. If hCaptcha can't be reached, the entry is accepted and marked unverified rather than lost. If hCaptcha rejects your secret, Formsafe doesn't blame the visitor: entries are taken in without the check, and a notice tells you to correct the key. If the widget shows the visitor an error instead of a box — most often a site key that doesn't list your domain — the entry is kept the same way as a form with no box, and a notice gives you hCaptcha's error code. After you change the site key or switch service, earlier passes no longer count, so nobody is sent back until a visitor passes with the new key. The honeypot, time trap and per-address limit run throughout.

hCaptcha, Turnstile or reCAPTCHA?

  • hCaptcha — a visible checkbox, sometimes a puzzle; independent of the big ad companies.
  • Turnstile — usually no puzzle at all; run by Cloudflare. See Turnstile.
  • reCAPTCHA v3 — invisible, gives a score instead of a yes or no. See reCAPTCHA v3.

All three are optional in Formsafe. Many sites need none of them: the built-in checks stop the everyday bots on their own.

Formsafe Contact Form is a free contact form that saves every entry before it sends anything, and shows you what happened to each email.

See what it does