CaptchaFox Plugin for Joomla

You can protect the forms of your Joomla website using the official CaptchaFox Joomla Plugin. It works through Joomla’s captcha interface and verifies every answer on the server before Joomla processes the form.

Requirements

JoomlaPHP
5.4 or later8.1 or later
6.x8.3 or later

Installation

  1. Download the plg_captcha_captchafox-<version>.zip file from the Releases.
  2. In the Joomla administrator, go to System > Install > Extensions and upload the ZIP.
  3. In the CaptchaFox Portal, copy the site key of your website (Sites) and the secret key of your organization (Organization Settings).
  4. Go to System > Manage > Plugins and open Captcha - CaptchaFox. Enter your Site Key and Secret Key, set Status to Enabled, keep Access at Public and save.
  5. Go to System > Global Configuration, tab Site, and set Default Captcha to Captcha - CaptchaFox.
  6. Everything is set. Your forms are now protected!
⚠️

Keep the access level of the plugin at Public. With any other access level, Joomla cannot use the plugin for visitors and rejects their forms.

Protected Forms

The plugin protects every form that uses Joomla’s captcha field. In Joomla itself these are:

  • Contact form
  • User registration
  • “Forgot your username?”
  • “Forgot your password?”
  • Article submission in the frontend

Forms of other extensions that use Joomla’s captcha field show CaptchaFox automatically. Form extensions that bring their own captcha integration are not covered. Joomla’s login form has no captcha.

Choose Where CaptchaFox Is Used

The Default Captcha applies to all protected forms. A component can use a different captcha or none: open the component, click Options in the toolbar and change the option. Use Global (the default) keeps the Default Captcha, None disables the captcha for this component.

ComponentTabOptionApplies to
Components > ContactsFormAllow Captcha on Contactall contact forms
Users > ManageUser OptionsCaptcharegistration, “Forgot your username?” and “Forgot your password?”
Content > ArticlesEditing LayoutAllow Captcha on submitarticle submission in the frontend

Options

OptionValuesDefault
Site Keyfrom the CaptchaFox Portal–
Secret Keyfrom the CaptchaFox Portal, only used on the server–
ModeInline, Popup, HiddenInline
ThemeLight, DarkLight
StartOn click, On form focus, AutomaticallyOn click
LanguageLanguage of the site, Language of the browser, Fixed languageLanguage of the site
If CaptchaFox Is UnreachableLet the form through and log it, Block the formLet the form through and log it

If CaptchaFox cannot be reached (network error, timeout of 5 seconds, error response), the form is let through by default and the outage is logged to plg_captcha_captchafox.php in Joomla’s log folder. Choose Block the form if protection matters more to you than availability. Answers that CaptchaFox rejects are always rejected.

Content Security Policy

If your site sends a Content Security Policy, for example with the core plugin “System - HTTP Headers”, allow the sources listed under Content Security Policy. Keep 'self' in script-src, which the plugin’s own script needs.

More details and troubleshooting are in the README of the plugin.