CreaCaptcha

login.php

ALTCHA protection for the WordPress login form.

Table of Contents

Functions

creationell_captcha_login_enabled()  : bool
Whether login protection is enabled.
creationell_captcha_login_render()  : void
Renders the widget inside the login form.
creationell_captcha_login_form_middle()  : string
Renders the widget inside `wp_login_form()`-based forms.
creationell_captcha_login_is_interactive()  : bool
Whether the current request is an interactive, browser-submitted login attempt — as opposed to XML-RPC, REST/Application-Passwords, AJAX or a programmatic `wp_signon()` call made by other code.
creationell_captcha_login_verify()  : WP_User|WP_Error|null
Verifies the captcha during an interactive login.

Functions

creationell_captcha_login_enabled()

Whether login protection is enabled.

creationell_captcha_login_enabled() : bool
Return values
bool

creationell_captcha_login_render()

Renders the widget inside the login form.

creationell_captcha_login_render() : void

creationell_captcha_login_form_middle()

Renders the widget inside `wp_login_form()`-based forms.

creationell_captcha_login_form_middle(string $content) : string

wp_login_form() — used by themes, widgets and shortcodes to embed a login form outside wp-login.php — never fires the login_form action above; it runs the login_form_top/login_form_middle/login_form_bottom filters instead. Without this, such a form posted the same log/pwd/ wp-submit fields as wp-login.php's own form but never got a widget to solve, so creationell_captcha_login_verify() below rejected even correct credentials (IN-6).

Parameters
$content : string

Existing middle-of-form markup.

Return values
string

creationell_captcha_login_is_interactive()

Whether the current request is an interactive, browser-submitted login attempt — as opposed to XML-RPC, REST/Application-Passwords, AJAX or a programmatic `wp_signon()` call made by other code.

creationell_captcha_login_is_interactive() : bool

Deliberately does NOT use isset( $_POST['wp-submit'] ) as the signal (IN-1): wp-login.php's own login handler calls wp_signon() unconditionally, regardless of whether "wp-submit" was posted, so an attacker posting directly to wp-login.php could simply omit it and skip the captcha entirely. The log/pwd field pair is what both wp-login.php's own form and wp_login_form()-based theme forms actually send. WooCommerce's My-Account login form uses different field names (username/password) and is intentionally NOT matched here — it has its own toggle/verification pair (protect_wc_login, see IN-7).

Return values
bool

creationell_captcha_login_verify()

Verifies the captcha during an interactive login.

creationell_captcha_login_verify(WP_User|WP_Error|null $user, string $username, string $password) : WP_User|WP_Error|null
Parameters
$user : WP_User|WP_Error|null

Authenticated user or error.

$username : string

Submitted username.

$password : string

Submitted password.

Return values
WP_User|WP_Error|null

        
On this page

Search results