If your contact form inbox is full of “SEO services” and crypto offers, you’re not being singled out. Bots find forms by the thousands and fill them in automatically. They don’t care how big your business is. They just need a form that accepts input.
Forms are the most common target, but they aren’t the only one. Comments, login pages, registration forms and shopping carts get hit too. The good news is that stopping most of it takes about an hour of setup, and both tools covered here are free for typical small business use.
What spam bots actually do on your site
A spam bot is a script that loads your page, finds anything that looks like a form field, fills it in and hits submit. No browser window, no human. Some are crude and easy to catch. Others run inside real browsers and act a lot like a visitor.
Here’s where they cause the most trouble:
Contact and quote forms. Junk leads, phishing links, and fake enquiries that waste your team’s time.
Comment sections. Link spam aimed at borrowing your site’s authority for someone else’s SEO.
Login and registration pages. Fake accounts, and password guessing against real ones.
WooCommerce carts and checkouts. Card testing, where criminals run small transactions to find out which stolen card numbers still work. It can leave you with chargebacks, payment gateway fees and sometimes a suspended merchant account.
Newsletter signups. Fake addresses that wreck your list quality and email reputation.
Beyond the annoyance, spam costs you server resources, buries genuine enquiries, and can hurt your email deliverability if your site is sending confirmation emails to junk addresses.
What reCAPTCHA and Turnstile do
Both tools sit between a visitor and your form and answer one question: is this a person or a script?
They work in three steps.
- A small script loads on your page. It watches how the visitor’s browser behaves and gathers signals like how the page is being interacted with, browser characteristics and network reputation.
- The tool issues a token. If the visitor looks legitimate, the browser gets a one-time token, which gets submitted along with the form.
- Your server checks the token. Before your site accepts the form, it sends the token to Google or Cloudflare and asks whether it’s valid. Only a “yes” lets the submission through.
Step three matters most. A bot can ignore the visible widget entirely, but it can’t fake a valid token, and a form that requires one will reject anything without it. This is why the plugin or code has to verify the token server-side. A widget that only displays on the page and never gets checked is decoration.
How Google reCAPTCHA works
reCAPTCHA comes in two versions you’ll see in practice.
reCAPTCHA v2 is the familiar one. Visitors tick an “I’m not a robot” box, and if the system isn’t sure, it shows a picture puzzle (traffic lights, crosswalks, buses). There’s also an invisible variant that only shows a challenge when something looks off.
reCAPTCHA v3 has no challenge at all. It scores every visitor between 0.0 (probably a bot) and 1.0 (probably human) based on behaviour across your site. You decide what to do with the score. Many setups block anything under 0.5, or flag it for review instead.
The upside is reliability and a long track record. Almost every WordPress form plugin supports it. The downsides are real, though. The picture puzzles annoy people and cost you conversions on forms where every lead counts. v3 can throw false positives at real users on VPNs or privacy-focused browsers. And it’s a Google service, which some site owners have privacy concerns about, particularly if you serve European visitors and need to think about GDPR and cookie consent.
How Cloudflare Turnstile works
Turnstile is Cloudflare’s answer to the same problem, built to skip the puzzles altogether.
When a page loads, Turnstile runs a batch of small, non-interactive checks in the background. These look at things like browser behaviour, proof-of-work challenges and signals Cloudflare sees across its network. Most visitors pass without seeing anything. Some get a quick checkbox. Very few get anything more than that.
It’s designed with privacy in mind. Cloudflare says it doesn’t use the data for ad targeting, and it doesn’t rely on the kind of tracking cookies reCAPTCHA is known for. You also don’t need a Cloudflare account on your DNS to use it. It works on any site, including ones hosted elsewhere.
The tradeoff is that it’s newer. It has fewer years of bot data behind it than Google’s system, and some smaller form plugins are slower to add support. That gap has been closing quickly, and for most WordPress sites it’s no longer a real obstacle.
reCAPTCHA vs Turnstile at a glance
| reCAPTCHA v2 | reCAPTCHA v3 | Turnstile | |
|---|---|---|---|
| Visitor sees a puzzle | Often | Never | Rarely |
| Scoring or pass/fail | Pass/fail | Score 0.0 to 1.0 | Pass/fail |
| Privacy | Google tracking | Google tracking | Privacy-focused |
| Cost | Free for standard use | Free for standard use | Free |
| Plugin support | Nearly universal | Very wide | Growing fast |
| Best for | Maximum compatibility | Invisible protection sitewide | Best visitor experience |
If you don’t have a strong reason to pick reCAPTCHA, Turnstile is a good default for a new setup. If a plugin you depend on only supports reCAPTCHA, use that. Either one is far better than no protection.
Where to put it on a WordPress site
Don’t just slap it on every page. Protect the places bots actually target.
- Contact forms and quote request forms. The obvious first stop.
- Comment forms. Or turn comments off entirely if you’re not using them.
- Login, registration and password reset. Cuts down brute force and fake signups.
- WooCommerce checkout and add-to-cart actions. Especially if you’ve seen odd small orders or failed payment spikes, which usually means card testing.
- Newsletter and lead-magnet forms. Keeps your mailing list clean.
Most setups use either a dedicated plugin for the tool you choose, or the built-in integration in form builders like Gravity Forms, WPForms, Fluent Forms and Contact Form 7. WooCommerce protection usually comes from a separate plugin or a security suite that hooks into checkout.
Setup, roughly
The steps are similar for both.
- Register your site with Google (reCAPTCHA admin console) or Cloudflare (Turnstile section of the dashboard). You’ll get a site key and a secret key.
- Install the relevant plugin, or open your form plugin’s settings.
- Paste in both keys. The site key is public. The secret key is not, so never put it in front-end code.
- Switch it on for each form or location you want protected.
- Test it. Submit a form yourself, then check what happens when the token is missing. If a submission goes through with no token, server-side verification isn’t working.
Things that go wrong
It’s added to the form but not enforced. Make sure the plugin verifies tokens on the server, not just displays the widget.
Caching breaks tokens. Tokens expire quickly. If a caching layer serves a stale copy of a page, visitors submit expired tokens and get errors. Exclude form pages from full-page caching or use the plugin’s recommended cache settings.
False positives. Real people on VPNs or older browsers occasionally get blocked. Keep an eye on failed submissions in the first few weeks, and always give people another way to reach you, like a phone number.
It’s not a silver bullet. Some bots and human-run spam farms will get through any CAPTCHA. Pair it with a honeypot field, rate limiting, a web application firewall, and updated plugins. Layers beat any single tool.
Accessibility. Puzzle-based challenges are hard for some visitors. Invisible or checkbox-style options like v3 and Turnstile are better here.
The bottom line
Spam isn’t going away, and it’s only getting more automated. Adding reCAPTCHA or Turnstile to your forms, comments, logins and checkout is one of the cheapest fixes you can make. It keeps junk out of your inbox, protects your payment setup, and means your team spends time on real leads.
If you’d like this set up properly, tested, and running alongside server-level protection, get in touch and we’ll sort it out.
Frequently Asked Questions
Is Cloudflare Turnstile really free? Yes, Turnstile is free for standard use, with no cap on the number of verifications in its free tier as of writing. Check Cloudflare’s current terms before relying on that, since pricing can change.
Do I need to move my site to Cloudflare to use Turnstile? No. Turnstile works as a standalone widget on any site. You just need a Cloudflare account to generate the keys.
Is reCAPTCHA still free? Standard reCAPTCHA remains free for typical small site volumes, though Google has moved parts of the service under Google Cloud, and heavy usage can fall under paid tiers. For most small business sites this isn’t an issue.
Will a CAPTCHA reduce my form conversions? Puzzle-based challenges can. Invisible and low-friction options like reCAPTCHA v3 and Turnstile have a much smaller effect because most visitors never notice them.
Can I use both on the same site? You can, but there’s little reason to. Pick one per form to avoid conflicts and slower page loads.
Does this protect against card testing on WooCommerce? It helps a lot, especially when applied to checkout and add-to-cart actions. Combine it with rate limiting and your payment gateway’s fraud tools for better coverage.
Do I still need a firewall if I use a CAPTCHA? Yes. A CAPTCHA protects specific forms. A web application firewall protects the whole site, including things a CAPTCHA never touches, like direct requests to your login file or API endpoints.
How do I know if it’s working? Watch your spam volume for a couple of weeks. You should see a sharp drop. Also test a submission with the token stripped out. If the site rejects it, verification is working.
