Description
CAPTCHAs interrupt every visitor to catch a few bots — and modern bots solve them anyway. useHUMA takes the opposite approach: it observes how a visitor behaves (mouse rhythm, typing cadence, scroll patterns, touch physics) and scores the probability that a real human is present. Real visitors feel nothing. Bots get blocked.
What it protects:
- Comments — spam comments are rejected before they reach your moderation queue
- User registration — fake account signups are stopped at the door
- Contact Form 7 — form spam is invalidated on submission (if CF7 is installed)
Why site owners choose it:
- Invisible — no checkbox, no image puzzles, no friction for real visitors
- Privacy-first — zero PII: no keystroke contents, no names, no fingerprinting databases; only statistical aggregates of interaction patterns
- Fail-open by design — if the verification service is ever unreachable, your forms keep working
- Tells you when it was an AI agent — not just bot or human. Playwright, Puppeteer, browser extensions and computer-use agents come back with their own verdict, on every plan including the free one
- One setting — paste your API key and you’re protected
You’ll need an API key from humaverify.com. It is free and it stays free: every account starts with 14 days of the Starter plan and then settles on the Free plan, 1,000 verifications a month, for ever, no credit card. Most small sites never need more than that.
External services
This plugin connects to the useHUMA API (https://humaverify.com) to score form submissions. On each protected submission, the plugin sends: anonymous behavioral statistics collected on the page (timing variance of mouse/keyboard/scroll/touch interactions — never the contents of what was typed) and a pseudonymous identifier. When the form provides an email address it is hashed on your server first, with a salt generated once and stored only in your own WordPress database, so the address itself never leaves your site and the hash cannot be reversed or matched against any other site. No other personal data is transmitted.
This service is provided by useHUMA: terms of service, privacy policy.
Installation
- Install and activate the plugin.
- Get a free API key at humaverify.com/signup. No credit card.
- Go to Settings useHUMA, paste your API key, and choose what to protect.
- Done — protection is invisible from this point on.
FAQ
-
Will my visitors see a CAPTCHA or checkbox?
-
No. Verification is completely invisible. Visitors just use your site normally; the behavioral score happens in the background.
-
What data is collected?
-
Only statistical aggregates of interaction timing (e.g. “how much did typing rhythm vary”), never the contents of what a visitor types, and never biometric identifiers. See the External services section for the full list.
-
What happens if the useHUMA API is down?
-
The plugin fails open: submissions are allowed through. An outage will never lock real users out of your forms.
-
What is strict mode?
-
By default, submissions without behavioral signals (e.g. from visitors with JavaScript disabled) are allowed. Strict mode rejects them — which blocks direct-POST bots completely, at the cost of also blocking no-JavaScript visitors.
-
Is it really free, or is it a trial that ends?
-
Both. Every account gets 14 days on the Starter plan, then settles on the Free plan and stays there: 1,000 verifications a month, no expiry, no card, with the AI-agent verdict included. A thousand a month is enough for most personal and small business sites. If your forms see more than that, the paid plans start at $49 a month, and the same API key keeps working.
-
Does it work with caching plugins?
-
Yes. The collector runs client-side after page load, so full-page caching doesn’t affect it.
Reviews
There are no reviews for this plugin.
Contributors & Developers
“useHUMA — Invisible Bot Protection (No CAPTCHA)” adalah perisian sumber terbuka. Orang-orang berikut telah menyumbang kepada pemalam ini.
PenyumbangTranslate “useHUMA — Invisible Bot Protection (No CAPTCHA)” into your language.
Berminat dalam pembangunan?
Layari kod, periksa repositori SVN, atau langgani log pembangunan dengan RSS.
Changelog
1.0.2
- Email addresses are now hashed on your own server before anything is sent. The address itself never leaves your site, and the readme no longer claims zero PII while transmitting one.
1.0.1
- The bundled collector now reports automation tells, and the plugin forwards them instead of dropping them. Without this a headless browser that moved the cursor a little was scored as a real visitor.
1.0.0
- Initial release: comment, registration and Contact Form 7 protection, settings page, bundled behavioral collector.
