CaptchaFox Plugin for Joomla
You can protect the forms of your Joomla website using the official CaptchaFox Joomla Plugin. It works through Joomla’s captcha interface and verifies every answer on the server before Joomla processes the form.
Requirements
| Joomla | PHP |
|---|---|
| 5.4 or later | 8.1 or later |
| 6.x | 8.3 or later |
Installation
- Download the
plg_captcha_captchafox-<version>.zipfile from the Releases. - In the Joomla administrator, go to System > Install > Extensions and upload the ZIP.
- In the CaptchaFox Portal, copy the site key of your website (Sites) and the secret key of your organization (Organization Settings).
- Go to System > Manage > Plugins and open Captcha - CaptchaFox. Enter your Site Key and Secret Key, set Status to Enabled, keep Access at Public and save.
- Go to System > Global Configuration, tab Site, and set Default Captcha to Captcha - CaptchaFox.
- Everything is set. Your forms are now protected!
Keep the access level of the plugin at Public. With any other access level, Joomla cannot use the plugin for visitors and rejects their forms.
Protected Forms
The plugin protects every form that uses Joomla’s captcha field. In Joomla itself these are:
- Contact form
- User registration
- “Forgot your username?”
- “Forgot your password?”
- Article submission in the frontend
Forms of other extensions that use Joomla’s captcha field show CaptchaFox automatically. Form extensions that bring their own captcha integration are not covered. Joomla’s login form has no captcha.
Choose Where CaptchaFox Is Used
The Default Captcha applies to all protected forms. A component can use a different captcha or none: open the component, click Options in the toolbar and change the option. Use Global (the default) keeps the Default Captcha, None disables the captcha for this component.
| Component | Tab | Option | Applies to |
|---|---|---|---|
| Components > Contacts | Form | Allow Captcha on Contact | all contact forms |
| Users > Manage | User Options | Captcha | registration, “Forgot your username?” and “Forgot your password?” |
| Content > Articles | Editing Layout | Allow Captcha on submit | article submission in the frontend |
Options
| Option | Values | Default |
|---|---|---|
| Site Key | from the CaptchaFox Portal | – |
| Secret Key | from the CaptchaFox Portal, only used on the server | – |
| Mode | Inline, Popup, Hidden | Inline |
| Theme | Light, Dark | Light |
| Start | On click, On form focus, Automatically | On click |
| Language | Language of the site, Language of the browser, Fixed language | Language of the site |
| If CaptchaFox Is Unreachable | Let the form through and log it, Block the form | Let the form through and log it |
If CaptchaFox cannot be reached (network error, timeout of 5 seconds, error response), the form is let through by default and the outage is logged to plg_captcha_captchafox.php in Joomla’s log folder. Choose Block the form if protection matters more to you than availability. Answers that CaptchaFox rejects are always rejected.
Content Security Policy
If your site sends a Content Security Policy, for example with the core plugin “System - HTTP Headers”, allow the sources listed under Content Security Policy. Keep 'self' in script-src, which the plugin’s own script needs.
More details and troubleshooting are in the README of the plugin.