Modern, invisible CAPTCHA

CAPTCHA and bot protection for WordPress and WooCommerce.

TrueSift protects logins, registrations, comments, forms and checkouts from bots, spam and automated abuse — without classic image puzzles. The generated proof is verified server-side before WordPress executes the protected action.

Without image puzzlesSelective activationVerified server-side
Protection areasThe most important WordPress actions at a glance.
LoginRegistrationPassword resetCommentsFormsWooCommerce checkout

You decide which areas TrueSift should protect.

Protection without rebuilding

CAPTCHA protection exactly where WordPress needs it.

TrueSift is activated only for the actions you select. Existing forms and workflows remain unchanged while gaining an additional server-secured layer of protection against bots and spam.

01 / WORDPRESS

Login, registration and comments

Protect WordPress login, user registration, password reset and comments directly from the plugin settings.

02 / WOOCOMMERCE

Customer account and checkout

Enable bot protection for customer login, customer registration and both classic and block-based WooCommerce checkouts.

03 / FORMS

Contact Form 7, WPForms and Elementor

Supported form plugins can be selectively protected from spam and automated submissions.

04 / DISPLAY

Four widget layouts

Checkbox, Banner, Inline or Badge: choose the presentation that best fits each page and protected action.

05 / SERVER PROTECTION

Secret Key and proof remain server-side

The Secret Key is never sent to the browser. A protected action is allowed only after a valid server-side proof verification.

06 / DIAGNOSTICS

Traceable integration

The optional debug mode records status, timing and integration decisions without logging credentials or complete tokens.

Plugin interface

Manage connection, protection areas and diagnostics centrally.

The WordPress interface clearly separates connection, integrations and tools. Each protection area can be configured and tested independently.

Installation

Activate bot protection in four steps.

You need a WordPress installation plus a TrueSift Site Key and Secret Key. No integration is activated automatically: you decide which actions are protected.

  1. 01

    Install the plugin through WordPress

    In WordPress, open “Plugins → Add Plugin”, search for TrueSift and install the plugin directly from the official WordPress plugin directory.

  2. 02

    Create free account

    Create your TrueSift account, confirm your email address and add your website in the customer area.

  3. 03

    Connect website

    Enter the Site Key and Secret Key, save the connection and verify it with the built-in connection test.

  4. 04

    Select protection areas

    Enable the required WordPress, WooCommerce or form actions, then choose the appropriate widget layout.

Server-side proof verification

The CAPTCHA widget alone does not authorize an action.

TrueSift evaluates the interaction in the browser and generates a proof. Login, registration, form submission or checkout are executed only after that proof has been validated server-side. A manipulated frontend therefore cannot simply bypass the authoritative protection decision.

Officially on WordPress.org

Install CAPTCHA and bot protection for WordPress.

Install TrueSift directly from the official WordPress plugin directory. The direct ZIP download remains available as an alternative installation option.