Skip to content

WordPress CAPTCHA Plugin

The following tutorial will guide you on how to integrate the TrustCaptcha CAPTCHA solution into your WordPress website to protect it from bots and spam.

You should have already completed the following steps before you start to integrate TrustCaptcha into your WordPress website.

  1. Read Get-Started: Get a quick overview of the concepts behind TrustCaptcha and the integration process in get started.

  2. Existing CAPTCHA: If you don’t have a CAPTCHA yet, sign in or create a new user account. Then create a new CAPTCHA.

  3. Existing WordPress website: You need a WordPress website in which you want to integrate TrustCaptcha.


Currently, our WordPress CAPTCHA plugin for TrustCaptcha is compatible with the following WordPress plugins:


Follow the steps below to integrate the TrustCaptcha CAPTCHA plugin into your WordPress website.

Perform the following steps to install the plugin:

  1. Install our plugin from the official WordPress Plugin Directory or download our plugin file here.
  2. If you downloaded our plugin file, navigate to Plugins → Add New Plugin, upload the plugin to your WordPress website, and install it.
  3. Finally, click on Activate.

Follow these steps to configure TrustCaptcha in your WordPress website:

  1. Navigate to Settings → TrustCaptcha.
  2. Enter the site-key and the api-key of your CAPTCHA. You can find and manage these keys in your CAPTCHA settings.
  3. Optional: Adjust additional settings such as language, theme, or threshold as needed.

TrustCaptcha WordPress settings

Follow these steps to enabled TrustCaptcha for your desired WordPress plugins:

  1. Navigate to Settings → TrustCaptcha.
  2. Enable TrustCaptcha for your desired plugins.

TrustCaptcha WordPress settings

The TrustCaptcha plugin for WordPress is now successfully installed and configured. For most plugins, TrustCaptcha now automatically appears in the corresponding forms on your WordPress website. If you use Elementor Forms, Fluent Forms, Gravity Forms or Ninja Forms, add the Trustcaptcha field to your forms as described under Usage.

TrustCaptcha is displayed in WordPress login screen


For the following integrations, nothing else needs to be done. As soon as you have enabled them under Settings → TrustCaptcha, the CAPTCHA is added to the corresponding forms automatically and is verified when the form is submitted:

  • BBPress New Topic
  • BBPress Reply
  • Contact Form 7
  • Forminator
  • Mailchimp for WordPress
  • WordPress Comments
  • WordPress Login
  • WordPress Lost Password
  • WordPress Registration
  • WooCommerce Login
  • WooCommerce Registration
  • WooCommerce Checkout
  • WooCommerce Lost Password
  • WP Forms

The following plugins come with their own form editor:

  • Elementor Forms
  • Fluent Forms
  • Gravity Forms
  • Ninja Forms

For these, our plugin provides a Trustcaptcha field that you add to each form you want to protect. Enabling the integration under Settings → TrustCaptcha only makes the field available — it does not add the CAPTCHA to your existing forms.

  1. Edit the page containing your form and select the Form widget.
  2. Open Content → Form Fields and click Add Item.
  3. Set the Type of the new field to Trustcaptcha.
  4. Save your changes.
  1. Navigate to Fluent Forms → All Forms and edit the form you want to protect.
  2. In the Input Fields sidebar, expand the Advanced Fields section.
  3. Add the Trustcaptcha element to your form via drag and drop. You will find it at the end of the list — not next to the Fluent Forms captcha fields. Ideally place it directly above the submit button.
  4. Save your changes.
  1. Navigate to Forms and edit the form you want to protect.
  2. In the field sidebar, expand the Advanced Fields section.
  3. Add the Trustcaptcha field to your form.
  4. Save your changes.
  1. Navigate to Ninja Forms → All Forms and edit the form you want to protect.
  2. Click Add New Field.
  3. In the Misc Fields section, select Trustcaptcha.
  4. Save your changes.

Your form is now protected with TrustCaptcha. When the form is submitted by a user, the CAPTCHA result is verified. If the verification fails, the user will see the form again with an error message. The field has to be added once per form — existing forms are not protected retroactively.


Once you have successfully installed and configured TrustCaptcha on your website, you can use TrustCaptcha to its full extent. However, we still recommend the following additional technical and organizational measures:

  • Security rules: You can find many security settings for your CAPTCHA in the CAPTCHA settings. These include, for example, authorized websites, CAPTCHA bypass for specific IP addresses, bypass keys, IP based blocking, geoblocking, individual difficulty and duration of the CAPTCHA, and much more. Learn more about the security rules.

  • Data protection: Include a passage in your privacy policy that refers to the use of TrustCaptcha. We also recommend that you enter into a data processing agreement with us to stay GDPR-compliant. Learn more about data protection.

  • Accessibility: Customize TrustCaptcha to your website so that your website is as accessible as possible and offers the best possible user experience. More about accessibility.

  • Testing: If you use automated testing, make sure that the CAPTCHA does not block it. Learn more about testing.