Changelog

What changed, and when

CaptchaFlow follows semantic versioning. Anything that could change behaviour on your site is called out here before it is called out in your inbox.

1.1.1

15 August 2026

A lockout fix everyone should take, and protection for forms that were quietly being missed.

  • Fixed: a site whose reCAPTCHA key was not registered for its domain could refuse every login, administrators included — even with “let visitors through if the provider is unreachable” switched on. Provider and configuration errors now count as the provider being unavailable, so that setting governs them. Errors that are a judgement about the submission still block.
  • Fixed: challenges now appear in forms added to the page after it loads — popups, modals, AJAX tabs and anything that arrives on scroll.
  • Fixed: forms that are not HTML forms, such as React-driven checkouts, now get the challenge fields they need.
  • New: the challenge response is checked against the site it was issued for, and reCAPTCHA v3 tokens against the action they were issued for — so a token solved elsewhere using this site’s public key cannot be replayed here.
  • New: an occasional review request, shown only once CaptchaFlow has actually blocked something, and never more than one notice at a time.
  • Nothing changed in what is stored, or in where data is sent.

1.1.0

14 August 2026

A place in the admin to read about Pro. Form protection was untouched.

  • A Pro screen in the admin describing what CaptchaFlow Pro adds, reachable from the menu.
  • The Pro entry hides itself automatically on sites already running Pro.
  • No changes to form protection, providers, or how visitor data is handled.

1.0.0

Initial release

The first public version. Everything below is in the free plugin unless marked otherwise.

  • Protection for WordPress core forms — login, registration, password reset and comments.
  • Adapters for Contact Form 7, WPForms, Fluent Forms, Forminator, Ninja Forms, Gravity Forms and Elementor Pro.
  • WooCommerce account forms: login, registration and password reset.
  • Any other form by CSS selector, with no code required.
  • Six challenge types: Cloudflare Turnstile, reCAPTCHA v2, reCAPTCHA v3, hCaptcha, and self-hosted Math and Question challenges.
  • Honeypot and timing pre-checks run on every submission, before the provider is contacted.
  • Cache-safe challenge delivery — no visitor-specific data is ever written into page HTML.
  • Setup wizard, one-click diagnostics with a text export, and a theme compatibility checker.
  • Dashboard with blocked-spam counters and a 30-day trend, backed by daily rollups.
  • Provider secrets encrypted at rest, log writes deferred until after the response, automatic log retention.
  • Privacy: IP addresses shortened to their network before logging, privacy-policy wording generated from your own configuration, and export and erase handlers wired into the WordPress privacy tools.

Updates arrive through WordPress in the usual way — Dashboard → Updates, or automatically if you have that enabled. Pro sites need an active licence to be offered updates; an expired licence keeps protecting the site, it just stops receiving new versions. See the FAQ or write to [email protected].