=== SecureGate Captcha Lite ===
Contributors: sabbir37
Donate link: https://profiles.wordpress.org/sabbir37/
Tags: captcha, turnstile, spam protection, login security, antispam
Requires at least: 5.8
Tested up to: 7.1
Requires PHP: 7.4
Stable tag: 1.1.1
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Complete site security with Cloudflare Turnstile, Math & Character CAPTCHA. High-performance protection for Login, Registration, and Comment forms.

== Description ==

**SecureGate Captcha Lite** is a high-performance security and anti-spam suite built to safeguard your WordPress site from intrusive spam, malicious bots, credential stuffing, and brute-force attacks. Leveraging professional-grade tools like Cloudflare Turnstile alongside our unique self-hosted Math and Character CAPTCHA fallback system, we ensure your site remains impenetrable while maintaining a seamless, privacy-first experience for legitimate users.

Protect Your Store - **[Upgrade to Pro Now](https://woocommerce.com/products/securegate-captcha/)**

= Why Choose SecureGate Captcha Lite? =

**Complete Protection**
Secure all critical WordPress forms including admin login, user registration, password reset, and comment submissions. Each form can be individually enabled or disabled based on your needs.

**Privacy-First Approach (GDPR Compliant)**
Built with GDPR compliance as a core priority. Uses Cloudflare Turnstile for privacy-focused, cookie-free bot detection and includes a self-hosted fallback CAPTCHA that requires zero external API connections and zero third-party tracking.

**Instant Protection Without API Keys**
Want immediate protection without signing up for third-party services? Our built-in Math CAPTCHA works immediately upon plugin activation with zero API keys required.

**Intelligent Auto-Fallback**
Never worry about external network outages. If Cloudflare Turnstile experiences downtime, high latency, or is blocked by an aggressive client browser extension, SecureGate automatically falls back to our self-hosted Math CAPTCHA so your forms never break.

**Lightning Fast Performance**
Optimized code that loads conditionally only where needed. No bloat, no unnecessary database queries, and fully compatible with all major caching plugins to ensure your website remains fast.

**Smart Rate Limiting & Brute-Force Defense**
Intelligent rate limiting prevents brute-force login attacks by tracking failed login attempts and automatically locking out suspicious IP addresses temporarily.

**Easy to Configure**
Intuitive admin interface with clear settings for CAPTCHA providers, protected forms, and security rules. Get started in minutes with sensible defaults.

= Core Features =

**CAPTCHA Providers**

* **Cloudflare Turnstile** - Modern, privacy-focused CAPTCHA with frictionless user experience
  - Free forever with generous limits from Cloudflare
  - Invisible verification for most legitimate human visitors
  - No user frustration with slow image puzzles (no clicking traffic lights)
  - Privacy-compliant with no tracking cookies or user profiling
  - Quick 2-minute API key setup

* **Built-in Fallback CAPTCHA** - Self-hosted protection that works always
  - Math challenges (simple arithmetic problems like 5 + 3 = 8)
  - Warped character text recognition challenges
  - Works instantly with zero external dependencies or API keys
  - GDPR compliant by design (runs 100% on your own server)
  - Perfect for restricted networks, local development, and intranet sites

**Protected Forms**

* **WordPress Login** - Protect admin and frontend login forms from credential stuffing and automated password guessing
* **User Registration** - Stop spam bot registrations and fake user account creation
* **Password Reset (Lost Password)** - Prevent automated password reset abuse and email flooding
* **Comment Forms** - Block automated comment spam without clogging moderation queues

**Security & Rate Limiting**

* **Rate Limiting** - Configure maximum allowed failed login attempts before a temporary lockout triggers
* **Automatic IP Blocking** - Automatic temporary bans for suspicious IP addresses exceeding thresholds
* **Customizable Lockout Duration** - Define your own time thresholds for attempts and lockout duration
* **Admin Exemptions** - Administrators with 'manage_options' capability are automatically exempt to prevent accidental lockouts
* **IP Allowlist** - Whitelist static office, home, or developer IP addresses to bypass verification

**Privacy & Compliance**

* **GDPR Ready** - Anonymized IP logging (last octet stripped) with automatic expiration
* **Data Minimization** - Only essential security attempt data is stored temporarily as WordPress transients
* **7-Day Auto-Cleanup** - All transient security logs are automatically deleted after 7 days
* **No External Tracking** - Self-hosted Math CAPTCHA requires zero third-party connections
* **User Control** - Administrators can disable logging entirely from plugin settings

**Performance Optimizations**

* **Conditional Loading** - Scripts and styles load strictly on pages displaying protected forms
* **Zero Impact** - Unprotected public pages experience zero performance overhead
* **Cache Friendly** - Works seamlessly with WP Rocket, LiteSpeed Cache, W3 Total Cache, WP Super Cache, and Cloudflare APO
* **Lightweight Assets** - Clean, minified CSS and JavaScript for minimal page weight
* **Database Efficiency** - Uses WordPress transients instead of creating permanent database tables

= Perfect For =

* **Bloggers** - Protect comments from spam without tedious moderation
* **Membership Sites** - Secure member registration and login processes from bots
* **Business Websites** - Prevent fake lead registrations, spam inquiries, and brute force login attempts
* **Personal Blogs** - Simple setup with powerful, hands-off protection
* **Portfolio Sites** - Keep contact forms, logins, and comments spam-free

= Technical Specifications =

* **WordPress Version**: 5.8 or higher (Fully tested and verified up to WordPress 7.1)
* **PHP Version**: 7.4 or higher (PHP 8.0, 8.1, and 8.2 compatible)
* **Multisite Compatible**: Yes (Network-activatable)
* **Translation Ready**: Yes (Includes .pot template file)
* **Performance Impact**: Negligible (Conditional asset loading only on protected forms)
* **Browser Support**: All modern browsers (Chrome, Firefox, Safari, Edge, Opera)

= Supported CAPTCHA Providers =

**Cloudflare Turnstile**
Turnstile is Cloudflare's modern, privacy-preserving alternative to traditional CAPTCHAs. It uses sophisticated browser challenges that are invisible to most legitimate users while effectively blocking automated bots.

**Built-in Fallback CAPTCHA**
Our self-hosted CAPTCHA system offers two challenge types:
- **Math Challenges**: Simple arithmetic problems (e.g., "What is 7 + 3?")
- **Text Recognition**: Warped text characters requiring human recognition

Both are effective against automated bots while remaining accessible to humans and requiring zero API keys.

= Comparison with Other CAPTCHA Plugins =

Unlike many CAPTCHA plugins that rely solely on external services or lack fallback mechanisms, SecureGate Captcha Lite provides:
- Multiple provider support with automatic fallback to prevent broken forms
- Self-hosted Math CAPTCHA option for complete independence with zero API keys
- Built-in brute force protection and IP rate limiting (no extra plugins required)
- Modern, clean admin interface with tabbed settings
- Regular updates and active maintenance tested against latest WordPress releases
- Clean, secure, well-documented code

== Installation ==

= Automatic Installation (Recommended) =

1. Navigate to **Plugins > Add New** in your WordPress dashboard
2. Search for **SecureGate Captcha Lite**
3. Click **Install Now** on the SecureGate Captcha Lite plugin
4. Click **Activate** once installation completes
5. Go to **SecureGate > General Settings** to configure

= Manual Installation =

1. Download the plugin ZIP file from WordPress.org
2. Navigate to **Plugins > Add New** in your WordPress dashboard
3. Click **Upload Plugin** at the top of the page
4. Choose the downloaded ZIP file and click **Install Now**
5. Click **Activate Plugin** after installation
6. Go to **SecureGate > General Settings** to configure

= Configuration Steps =

**For Cloudflare Turnstile:**
1. Visit [Cloudflare Turnstile](https://dash.cloudflare.com/turnstile)
2. Create a free account if you don't have one
3. Add your site and obtain Site Key and Secret Key
4. Navigate to **SecureGate > Providers** in WordPress
5. Select "Cloudflare Turnstile" as your provider
6. Enter your Site Key and Secret Key
7. Save changes

**For Built-in CAPTCHA:**
1. Navigate to **SecureGate > Providers**
2. Select "Built-in" as your provider
3. Choose "Math" or "Text" challenge type
4. Save changes (no API keys needed!)

**Enable Protected Forms:**
1. Go to **SecureGate > Protected Forms**
2. Toggle on the forms you want to protect
3. Save changes

== Frequently Asked Questions ==

= Is this plugin completely free? =

Yes! SecureGate Captcha Lite is 100% free with no hidden costs, premium upsells within the plugin interface, or feature limitations beyond what is advertised. All core features for WordPress form protection are included.

= Do I need API keys to use this plugin? =

It depends on your chosen provider:
- **Built-in CAPTCHA**: No API keys required - works immediately upon activation
- **Cloudflare Turnstile**: Free API keys required (takes 2 minutes to obtain from Cloudflare)

= Will this slow down my website? =

No. The plugin is performance-optimized and only loads necessary scripts on pages with protected forms. On unprotected pages, there is zero performance impact.

= Is it GDPR compliant? =

Yes. The plugin is designed with privacy in mind:
- IP addresses are anonymized before storage (last octet stripped)
- All logs expire automatically after 7 days
- No user personal data is collected or stored
- Built-in CAPTCHA requires no external services or third-party connections

= Can I use this with caching plugins? =

Absolutely! SecureGate Captcha Lite is fully compatible with all major caching solutions including:
- WP Rocket
- W3 Total Cache
- LiteSpeed Cache
- WP Super Cache
- Autoptimize
- Cloudflare APO and other page caching engines

= What happens if Cloudflare Turnstile is down? =

The plugin includes intelligent fallback logic. If Turnstile fails to load or verify, the system automatically falls back to the built-in CAPTCHA, ensuring your forms remain protected and operational at all times.

= Will administrators be locked out? =

No. Administrators (users with 'manage_options' capability) are automatically exempt from CAPTCHA challenges to prevent accidental lockouts during configuration or emergencies.

= Can I customize the appearance? =

Yes! The plugin includes theme options for CAPTCHA widgets (Light/Dark mode) and uses WordPress-standard styling that inherits your theme's design. Custom CSS can be added for advanced styling needs.

= Does it work on multisite installations? =

Yes. The plugin is multisite-compatible and can be network-activated or activated individually per site.

= How long are blocked IPs banned? =

By default, IPs are temporarily blocked for 30 minutes after exceeding the failed attempt threshold. This duration is customizable in **SecureGate > Security Rules**.

= Can I whitelist specific IP addresses? =

Yes. Navigate to **SecureGate > Security Rules** to add trusted IP addresses that will bypass CAPTCHA verification.

= Is there a Pro version? =

Yes! **SecureGate Captcha Pro** is the ultimate security solution for WooCommerce and WordPress stores. While the Lite version provides essential protection, the Pro version is designed for serious businesses that need advanced defense against sophisticated bot attacks and localized threats.

**[Get SecureGate Captcha Pro](https://woocommerce.com/products/securegate-captcha/)**

**Why SecureGate Pro is the Best Solution for Your Store:**
* **Google reCAPTCHA v2 & v3 Integration**: Use the world's most trusted CAPTCHA technology. v3 offers 100% invisible protection without interrupting the user experience.
* **Enterprise-Grade hCaptcha Support**: Advanced bot detection with privacy-focused hCaptcha enterprise features.
* **Comprehensive WooCommerce Protection**: Secure every step of the customer journey, from account creation and login to the final checkout process.
* **Geographic (Geo-Location) Blocking**: Stop attacks before they reach your server by blocking entire countries or regions known for high bot activity.
* **Advanced Analytics & Reporting**: Gain deep insights into security threats with real-time charts, provider popularity data, and CSV export capabilities.
* **Smart IP Filtering**: Advanced IP address blocking and allowlisting to fine-tune your security rules.
* **Priority Expert Support**: Get direct access to our security experts for fast resolution of any issues.

Stop losing sales to fraudulent registrations and checkout abuse. **[Upgrade to SecureGate Pro Now](https://woocommerce.com/products/securegate-captcha/)** and get the peace of mind your business deserves.

= How do I report bugs or request features? =

Please use the [WordPress.org support forum](https://wordpress.org/support/plugin/securegate-captcha-lite/) for bug reports and feature requests. We actively monitor and respond to all threads.

= Can I contribute to development? =

Yes! We welcome contributions. Please visit our GitHub repository to submit pull requests or report issues.

== Screenshots ==

1. **General Settings** - Clean, modern interface for enabling protection and configuring global settings
2. **CAPTCHA Providers** - Easy provider selection with Turnstile and Built-in options
3. **Protected Forms** - Granular control over which forms to protect with visual toggles
4. **Security Rules** - Configure rate limiting thresholds and lockout duration
5. **Turnstile on Login** - Example of Cloudflare Turnstile on WordPress Admin login page
6. **Built-in Math CAPTCHA** - Example of self-hosted math challenge protecting registration
7. **Built-in Text CAPTCHA** - Example of self-hosted text recognition challenge

== Changelog ==

= 1.1.1 =
* **Improved**: Enhanced plugin security hardening and verified full compatibility with WordPress 7.1.
* **Optimized**: Streamlined CAPTCHA verification routines for Cloudflare Turnstile and the built-in Math CAPTCHA engine.
* **Updated**: Form protection handlers, brute-force rate-limiting accuracy, and documentation.

= 1.1.0 =
* **Improved**: Enhanced administrative dashboard UI and optimized core asset loading for better performance and security management.

= 1.0.1 =
* **Improved**: Plugin information and functionality refinements

= 1.0.0 =
* **Initial Public Release**
* Added Cloudflare Turnstile support
* Added Built-in Fallback CAPTCHA (Math & Text)
* Implemented WordPress Core form protection (Login, Registration, Password Reset, Comments)
* Added Rate Limiting with customizable thresholds
* Implemented Automatic IP blocking for suspicious activity
* Added IP Allowlist functionality
* Included GDPR-compliant logging with auto-expiration
* Created modern admin interface with tabbed navigation
* Implemented real-time settings validation
* Added comprehensive error handling
* Included multisite compatibility
* Added translation readiness with .pot file

== Upgrade Notice ==

= 1.1.1 =
Updated for WordPress 7.1 compatibility, improved security hardening, and faster CAPTCHA verification routines.

== Privacy & Data Collection ==

**What Data Does This Plugin Collect?**

SecureGate Captcha Lite is designed with privacy as a core principle:

**Stored Locally (in your WordPress database as transients):**
* Anonymized IP addresses (last octet removed)
* Timestamp of verification attempts
* Success/failure status of CAPTCHA verifications
* Failed attempt counters for rate limiting

**NOT Stored:**
* User emails or usernames
* Personal identifying information
* Browser fingerprints
* Tracking cookies (plugin-side)
* Permanent user profiles

**External Service Data:**
When Cloudflare Turnstile is enabled, user browser data is sent to Cloudflare for bot detection. Please review [Cloudflare's Privacy Policy](https://www.cloudflare.com/privacypolicy/) for details.

When using the Built-in CAPTCHA, NO external services are contacted.

**Data Retention:**
All logs are stored as WordPress transients and automatically deleted after 7 days. Administrators can disable logging entirely in settings.

**Right to Erasure:**
No personal data is collected that would require manual erasure requests under GDPR.

== Support & Documentation ==

**Need Help?**

* **Documentation**: Visit the [plugin page](https://wordpress.org/plugins/securegate-captcha-lite/) for guides and tutorials
* **Support Forum**: Get help from the community at [WordPress.org Support](https://wordpress.org/support/plugin/securegate-captcha-lite/)
* **Bug Reports**: Report issues on the support forum
* **Feature Requests**: Share your ideas on the support forum

**Response Time:**
We monitor the support forum regularly and aim to respond within 24-48 hours for most queries.

== Credits & Acknowledgments ==

**Developed with ❤️ by R.Sabbir**

**Third-Party Services:**
When Cloudflare Turnstile is enabled, this plugin connects to Cloudflare's servers for CAPTCHA verification. By using Turnstile, you agree to Cloudflare's [Terms of Service](https://www.cloudflare.com/website-terms/) and [Privacy Policy](https://www.cloudflare.com/privacypolicy/).
