Skip to main content

WordPress

Use hCaptcha for WP to protect supported WordPress forms without adding widget or verification code yourself.

Install the plugin

In WordPress, open Plugins → Add New, search for hCaptcha for WP, install it, and activate it.

Configure keys

Create an hCaptcha account. Copy your sitekey from Sites and your secret from Settings into the plugin's hCaptcha settings, then save.

Choose forms

Enable protection for the supported forms you use in the plugin's settings. Check the plugin's supported integrations for your form builder.

Some form builders provide native hCaptcha support, including WPForms and Ninja Forms. Choose one integration per form to avoid duplicate widgets or verification.

Test protection

On a staging site, check each protected form while logged out. Confirm a successful challenge permits submission and a missing or invalid token prevents it. Use test keys only in testing; restore production keys before launch.

If the widget does not load, check your Content Security Policy and whether script optimization or caching delays the SDK.