login.php
ALTCHA protection for the WordPress login form.
Table of Contents
Functions
- creationell_captcha_login_enabled() : bool
- Whether login protection is enabled.
- creationell_captcha_login_render() : void
- Renders the widget inside the login form.
- creationell_captcha_login_form_middle() : string
- Renders the widget inside `wp_login_form()`-based forms.
- creationell_captcha_login_is_interactive() : bool
- Whether the current request is an interactive, browser-submitted login attempt — as opposed to XML-RPC, REST/Application-Passwords, AJAX or a programmatic `wp_signon()` call made by other code.
- creationell_captcha_login_verify() : WP_User|WP_Error|null
- Verifies the captcha during an interactive login.
Functions
creationell_captcha_login_enabled()
Whether login protection is enabled.
creationell_captcha_login_enabled() : bool
Return values
boolcreationell_captcha_login_render()
Renders the widget inside the login form.
creationell_captcha_login_render() : void
creationell_captcha_login_form_middle()
Renders the widget inside `wp_login_form()`-based forms.
creationell_captcha_login_form_middle(string $content) : string
wp_login_form() — used by themes, widgets and shortcodes to embed a
login form outside wp-login.php — never fires the login_form action
above; it runs the login_form_top/login_form_middle/login_form_bottom
filters instead. Without this, such a form posted the same log/pwd/
wp-submit fields as wp-login.php's own form but never got a widget to
solve, so creationell_captcha_login_verify() below rejected even correct
credentials (IN-6).
Parameters
- $content : string
-
Existing middle-of-form markup.
Return values
stringcreationell_captcha_login_is_interactive()
Whether the current request is an interactive, browser-submitted login attempt — as opposed to XML-RPC, REST/Application-Passwords, AJAX or a programmatic `wp_signon()` call made by other code.
creationell_captcha_login_is_interactive() : bool
Deliberately does NOT use isset( $_POST['wp-submit'] ) as the signal
(IN-1): wp-login.php's own login handler calls wp_signon()
unconditionally, regardless of whether "wp-submit" was posted, so an
attacker posting directly to wp-login.php could simply omit it and skip
the captcha entirely. The log/pwd field pair is what both
wp-login.php's own form and wp_login_form()-based theme forms actually
send. WooCommerce's My-Account login form uses different field names
(username/password) and is intentionally NOT matched here — it has
its own toggle/verification pair (protect_wc_login, see IN-7).
Return values
boolcreationell_captcha_login_verify()
Verifies the captcha during an interactive login.
creationell_captcha_login_verify(WP_User|WP_Error|null $user, string $username, string $password) : WP_User|WP_Error|null
Parameters
- $user : WP_User|WP_Error|null
-
Authenticated user or error.
- $username : string
-
Submitted username.
- $password : string
-
Submitted password.