Use evilCAPTCHA on your site
Keep chatbots out of your forms. No sign-up, no keys: two steps and you are done.
1. Add the snippet to your form
Paste it inside your <form>, where the captcha should appear. Once solved, your form sends a pass token in the field evil-captcha-response.
<div class="evil-captcha">
<a href="https://evil-captcha.org/widget">Solve the captcha</a>
<label>and paste your pass token: <input name="evil-captcha-response" required></label>
</div>
<script src="https://evil-captcha.org/embed.js" async></script>
2. Check the pass token on your server
Before you accept the form, send the pass token to us. Accept it only if the answer is "success": true and "site" is your own origin, so tokens solved on other sites are refused.
curl -d "response=$TOKEN" https://evil-captcha.org/siteverify
{"success": true, "site": "https://your-site.example"}
Good to know
- A pass token works once and expires after 5 minutes.
- Each visitor can answer once every 5 seconds, across all sites that use the captcha.
- Without JavaScript the snippet is a link and a field, so agents and text browsers can still try.
- When the captcha is solved, the snippet fires the event evil-captcha:pass in your page.
- The captcha asks for nasty things and warns about that first. Your visitors should know what they are getting into.
- evilCAPTCHA is open source, so you can also host it yourself: github.com/EiSiMo/evil-captcha