{"id":245569,"date":"2025-08-11T08:17:58","date_gmt":"2025-08-11T08:17:58","guid":{"rendered":"https:\/\/en-gb.wordpress.org\/plugins\/kitgenix-turnstile\/"},"modified":"2026-08-31T19:23:49","modified_gmt":"2026-08-31T19:23:49","slug":"kitgenix-captcha-for-cloudflare-turnstile","status":"publish","type":"plugin","link":"https:\/\/srd.wordpress.org\/plugins\/kitgenix-captcha-for-cloudflare-turnstile\/","author":23310025,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"2.0.0","stable_tag":"2.0.0","tested":"7.1","requires":"6.0","requires_php":"8.1","requires_plugins":null,"header_name":"Kitgenix CAPTCHA for Cloudflare Turnstile","header_author":"Kitgenix","header_description":"Seamlessly integrate Cloudflare Turnstile with WordPress, WooCommerce, and Elementor forms.","assets_banners_color":"343965","last_updated":"2026-08-31 19:23:49","external_support_url":"","external_repository_url":"","donate_link":"https:\/\/www.paypal.com\/donate\/?hosted_button_id=KALF36K6JJ9B2","header_plugin_uri":"https:\/\/wordpress.org\/plugins\/kitgenix-captcha-for-cloudflare-turnstile\/","header_author_uri":"https:\/\/kitgenix.com\/","rating":5,"author_block_rating":0,"active_installs":600,"downloads":5011,"num_ratings":6,"support_threads":1,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"kitgenix","date":"2025-08-11 08:20:37","revision":3342710},"1.0.1":{"tag":"1.0.1","author":"kitgenix","date":"2025-08-11 12:07:42","revision":3342842},"1.0.10":{"tag":"1.0.10","author":"kitgenix","date":"2025-10-16 08:57:43","revision":3379321},"1.0.11":{"tag":"1.0.11","author":"kitgenix","date":"2025-10-19 11:50:21","revision":3380798},"1.0.12":{"tag":"1.0.12","author":"kitgenix","date":"2025-11-21 18:19:55","revision":3400649},"1.0.12.1":{"tag":"1.0.12.1","author":"kitgenix","date":"2025-11-21 21:50:49","revision":3400706},"1.0.13":{"tag":"1.0.13","author":"kitgenix","date":"2025-11-22 10:56:05","revision":3400879},"1.0.14":{"tag":"1.0.14","author":"kitgenix","date":"2025-12-09 12:52:03","revision":3415415},"1.0.15":{"tag":"1.0.15","author":"kitgenix","date":"2026-01-01 19:20:11","revision":3430715},"1.0.16":{"tag":"1.0.16","author":"kitgenix","date":"2026-01-27 19:10:13","revision":3448141},"1.0.17":{"tag":"1.0.17","author":"kitgenix","date":"2026-02-19 22:09:58","revision":3465407},"1.0.18":{"tag":"1.0.18","author":"kitgenix","date":"2026-03-19 10:11:29","revision":3486323},"1.0.2":{"tag":"1.0.2","author":"kitgenix","date":"2025-08-12 07:25:49","revision":3343330},"1.0.3":{"tag":"1.0.3","author":"kitgenix","date":"2025-08-12 20:40:05","revision":3343805},"1.0.4":{"tag":"1.0.4","author":"kitgenix","date":"2025-08-17 13:50:18","revision":3345909},"1.0.5":{"tag":"1.0.5","author":"kitgenix","date":"2025-09-09 08:32:29","revision":3358418},"1.0.6":{"tag":"1.0.6","author":"kitgenix","date":"2025-09-10 19:02:56","revision":3359406},"1.0.7":{"tag":"1.0.7","author":"kitgenix","date":"2025-10-14 20:24:47","revision":3378425},"1.0.8":{"tag":"1.0.8","author":"kitgenix","date":"2025-10-15 08:19:30","revision":3378699},"1.0.9":{"tag":"1.0.9","author":"kitgenix","date":"2025-10-15 12:54:38","revision":3378897},"1.1.0":{"tag":"1.1.0","author":"kitgenix","date":"2026-05-07 13:15:33","revision":3525568},"1.1.3":{"tag":"1.1.3","author":"kitgenix","date":"2026-05-26 19:51:12","revision":3549706},"2.0.0":{"tag":"2.0.0","author":"kitgenix","date":"2026-08-31 19:23:49","revision":3674861}},"upgrade_notice":{"2.0.0":"<p>Version 2.0.0 adds the redesigned Kitgenix admin experience, Ninja Forms support, per-integration display and test-mode controls, honeypot protection and protection-health diagnostics, while also including important server-side enforcement fixes across several integrations.<\/p>"},"ratings":{"1":0,"2":0,"3":0,"4":0,"5":6},"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3674861,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3674861,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3674861,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3674861,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.0","1.0.1","1.0.10","1.0.11","1.0.12","1.0.12.1","1.0.13","1.0.14","1.0.15","1.0.16","1.0.17","1.0.18","1.0.2","1.0.3","1.0.4","1.0.5","1.0.6","1.0.7","1.0.8","1.0.9","1.1.0","1.1.3","2.0.0"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3674861,"resolution":"1","location":"assets","locale":"","width":640,"height":1170},"screenshot-10.png":{"filename":"screenshot-10.png","revision":3674861,"resolution":"10","location":"assets","locale":"","width":1920,"height":716},"screenshot-11.png":{"filename":"screenshot-11.png","revision":3525568,"resolution":"11","location":"assets","locale":"","width":2700,"height":1462},"screenshot-12.png":{"filename":"screenshot-12.png","revision":3525568,"resolution":"12","location":"assets","locale":"","width":2700,"height":1462},"screenshot-13.png":{"filename":"screenshot-13.png","revision":3525568,"resolution":"13","location":"assets","locale":"","width":2700,"height":1462},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3674861,"resolution":"2","location":"assets","locale":"","width":3026,"height":1198},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3674861,"resolution":"3","location":"assets","locale":"","width":2400,"height":2144},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3674861,"resolution":"4","location":"assets","locale":"","width":2403,"height":2166},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3674861,"resolution":"5","location":"assets","locale":"","width":2400,"height":1044},"screenshot-6.png":{"filename":"screenshot-6.png","revision":3674861,"resolution":"6","location":"assets","locale":"","width":2402,"height":1430},"screenshot-7.png":{"filename":"screenshot-7.png","revision":3674861,"resolution":"7","location":"assets","locale":"","width":2400,"height":1096},"screenshot-8.png":{"filename":"screenshot-8.png","revision":3674861,"resolution":"8","location":"assets","locale":"","width":3024,"height":830},"screenshot-9.png":{"filename":"screenshot-9.png","revision":3674861,"resolution":"9","location":"assets","locale":"","width":1920,"height":1486}},"screenshots":{"1":"WordPress login protected with Cloudflare Turnstile.","2":"WordPress registration protected with Cloudflare Turnstile.","3":"Cloudflare Turnstile on WooCommerce Classic Checkout.","4":"Cloudflare Turnstile on WooCommerce Checkout Blocks \/ Store API checkout.","5":"WooCommerce My Account login protection.","6":"Turnstile protection on a contact form.","7":"WPForms protected with Cloudflare Turnstile.","8":"Elementor Pro Forms protected with Cloudflare Turnstile.","9":"Site Key, Secret Key and setup-verification settings.","10":"Security controls."}},"plugin_section":[],"plugin_tags":[2656,362,214689,92828,286],"plugin_category":[44,45],"plugin_contributors":[246171],"plugin_business_model":[],"class_list":["post-245569","plugin","type-plugin","status-publish","hentry","plugin_tags-anti-spam","plugin_tags-captcha","plugin_tags-cloudflare-turnstile","plugin_tags-form-security","plugin_tags-woocommerce","plugin_category-discussion-and-community","plugin_category-ecommerce","plugin_contributors-kitgenix","plugin_committers-kitgenix","plugin_support_reps-carlfromkitgenix"],"banners":{"banner":"https:\/\/ps.w.org\/kitgenix-captcha-for-cloudflare-turnstile\/assets\/banner-772x250.png?rev=3674861","banner_2x":"https:\/\/ps.w.org\/kitgenix-captcha-for-cloudflare-turnstile\/assets\/banner-1544x500.png?rev=3674861","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/kitgenix-captcha-for-cloudflare-turnstile\/assets\/icon-128x128.png?rev=3674861","icon_2x":"https:\/\/ps.w.org\/kitgenix-captcha-for-cloudflare-turnstile\/assets\/icon-256x256.png?rev=3674861","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/kitgenix-captcha-for-cloudflare-turnstile\/assets\/screenshot-1.png?rev=3674861","caption":"WordPress login protected with Cloudflare Turnstile."},{"src":"https:\/\/ps.w.org\/kitgenix-captcha-for-cloudflare-turnstile\/assets\/screenshot-2.png?rev=3674861","caption":"WordPress registration protected with Cloudflare Turnstile."},{"src":"https:\/\/ps.w.org\/kitgenix-captcha-for-cloudflare-turnstile\/assets\/screenshot-3.png?rev=3674861","caption":"Cloudflare Turnstile on WooCommerce Classic Checkout."},{"src":"https:\/\/ps.w.org\/kitgenix-captcha-for-cloudflare-turnstile\/assets\/screenshot-4.png?rev=3674861","caption":"Cloudflare Turnstile on WooCommerce Checkout Blocks \/ Store API checkout."},{"src":"https:\/\/ps.w.org\/kitgenix-captcha-for-cloudflare-turnstile\/assets\/screenshot-5.png?rev=3674861","caption":"WooCommerce My Account login protection."},{"src":"https:\/\/ps.w.org\/kitgenix-captcha-for-cloudflare-turnstile\/assets\/screenshot-6.png?rev=3674861","caption":"Turnstile protection on a contact form."},{"src":"https:\/\/ps.w.org\/kitgenix-captcha-for-cloudflare-turnstile\/assets\/screenshot-7.png?rev=3674861","caption":"WPForms protected with Cloudflare Turnstile."},{"src":"https:\/\/ps.w.org\/kitgenix-captcha-for-cloudflare-turnstile\/assets\/screenshot-8.png?rev=3674861","caption":"Elementor Pro Forms protected with Cloudflare Turnstile."},{"src":"https:\/\/ps.w.org\/kitgenix-captcha-for-cloudflare-turnstile\/assets\/screenshot-9.png?rev=3674861","caption":"Site Key, Secret Key and setup-verification settings."},{"src":"https:\/\/ps.w.org\/kitgenix-captcha-for-cloudflare-turnstile\/assets\/screenshot-10.png?rev=3674861","caption":"Security controls."},{"src":"https:\/\/ps.w.org\/kitgenix-captcha-for-cloudflare-turnstile\/assets\/screenshot-11.png?rev=3525568","caption":""},{"src":"https:\/\/ps.w.org\/kitgenix-captcha-for-cloudflare-turnstile\/assets\/screenshot-12.png?rev=3525568","caption":""},{"src":"https:\/\/ps.w.org\/kitgenix-captcha-for-cloudflare-turnstile\/assets\/screenshot-13.png?rev=3525568","caption":""}],"raw_content":"<!--section=description-->\n<p><strong>Kitgenix CAPTCHA for Cloudflare Turnstile<\/strong> adds Cloudflare Turnstile CAPTCHA and anti-spam protection to WordPress, WooCommerce and a wide range of form, membership, community and ecommerce plugins. Challenges are not treated as a client-side decoration: submitted Turnstile tokens are verified server-side with Cloudflare before a protected action is accepted.<\/p>\n\n<p>The plugin is designed for site owners who want to reduce automated login attempts, fake registrations, comment spam, bot-driven checkout abuse and unwanted form submissions while using Cloudflare's privacy-oriented Turnstile challenge rather than a traditional image CAPTCHA.<\/p>\n\n<p>Configuration, integration controls, diagnostics and local verification metrics are managed inside WordPress. The only service required for CAPTCHA functionality is Cloudflare Turnstile itself; no Kitgenix verification proxy is used.<\/p>\n\n<p>Learn more about Kitgenix WordPress plugins at <a href=\"https:\/\/kitgenix.com\/\">Kitgenix<\/a>.<\/p>\n\n<h4>Supported WordPress and Plugin Integrations<\/h4>\n\n<p>The codebase contains dedicated integrations for:<\/p>\n\n<ul>\n<li>WordPress login.<\/li>\n<li>WordPress registration.<\/li>\n<li>Lost-password and password-reset flows.<\/li>\n<li>WordPress comments.<\/li>\n<li>Custom login forms produced with <code>wp_login_form()<\/code>.<\/li>\n<li>WooCommerce login, registration, lost password, checkout and related account flows supported by the integration.<\/li>\n<li>Easy Digital Downloads.<\/li>\n<li>Elementor forms.<\/li>\n<li>Contact Form 7.<\/li>\n<li>WPForms.<\/li>\n<li>Gravity Forms.<\/li>\n<li>Fluent Forms.<\/li>\n<li>Formidable Forms.<\/li>\n<li>Forminator.<\/li>\n<li>Ninja Forms.<\/li>\n<li>Jetpack Forms.<\/li>\n<li>JetFormBuilder.<\/li>\n<li>Kadence Forms.<\/li>\n<li>MailPoet.<\/li>\n<li>bbPress.<\/li>\n<li>BuddyPress.<\/li>\n<li>wpDiscuz.<\/li>\n<li>Ultimate Member.<\/li>\n<li>MemberPress.<\/li>\n<li>Paid Memberships Pro.<\/li>\n<li>Kitgenix Plugin Score integration points included in the codebase.<\/li>\n<\/ul>\n\n<p>Each integration is loaded conditionally and can use integration-specific display\/validation behaviour rather than forcing one generic hook onto every form system.<\/p>\n\n<h4>Server-Side Turnstile Verification<\/h4>\n\n<p>The browser obtains a Turnstile response token from Cloudflare's official widget. When a protected form is submitted, the plugin sends that token to Cloudflare's official Siteverify endpoint using the WordPress HTTP API. The protected action is allowed only when the verification result satisfies the integration's validation flow.<\/p>\n\n<p>This server-side step is important because simply placing a widget in the browser is not sufficient protection on its own. The plugin tracks the most recent verification response, error codes and latency for diagnostics and can record aggregate verification metrics locally.<\/p>\n\n<h4>Setup Verification for Login-Sensitive Forms<\/h4>\n\n<p>Login, registration and other account-sensitive protections can be gated behind a setup-verification state. The administrator can verify the configured Site Key and Secret Key before those protections are treated as ready.<\/p>\n\n<p>This reduces the risk of enabling a broken key pair on a login screen and accidentally locking legitimate administrators or customers out of the site.<\/p>\n\n<p>Site and secret keys can be supplied from plugin settings or from supported environment variables\/constants, allowing security-conscious deployments to keep the secret outside the normal WordPress options table.<\/p>\n\n<h4>Replay Protection<\/h4>\n\n<p>Turnstile tokens are intended to be short lived and single use. The plugin includes optional replay protection that hashes accepted tokens and temporarily remembers that hash. A token that is submitted again during the replay window can be rejected rather than being accepted repeatedly.<\/p>\n\n<p>The replay window is filterable for developers. Stored replay information is a hash\/temporary value, not the raw challenge token itself.<\/p>\n\n<h4>Honeypot and Layered Anti-Spam Controls<\/h4>\n\n<p>An optional honeypot can be rendered alongside Turnstile. This adds a second low-friction signal for simple bots that fill fields a normal visitor never sees.<\/p>\n\n<p>The plugin also supports whitelisting logic so trusted requests can bypass the challenge where appropriate. Whitelist decisions can take account of configured rules and developer filters rather than hard-coding one bypass mechanism for every site.<\/p>\n\n<h4>Trusted Proxy and Client IP Handling<\/h4>\n\n<p>Sites may sit behind Cloudflare, another reverse proxy or a load balancer. The client-IP component can be configured to trust proxy headers only when the request path matches the trusted-proxy configuration. This avoids blindly believing spoofable forwarding headers from arbitrary visitors.<\/p>\n\n<p>Administrators can also choose whether the resolved visitor IP is included in the Siteverify request to Cloudflare. A developer filter is available to change that behaviour when required by a site's privacy or infrastructure policy.<\/p>\n\n<h4>Widget Appearance and Placement<\/h4>\n\n<p>The plugin supports central defaults plus integration-level overrides for Turnstile appearance. Depending on the supported integration, administrators can control options such as theme, size, appearance and language, and can choose placement behaviour where the integration exposes more than one suitable hook.<\/p>\n\n<p>A manual shortcode is also registered:<\/p>\n\n<pre><code>[kitgenix_turnstile]\n<\/code><\/pre>\n\n<p>The shortcode is useful when the site owner needs to render the widget in a supported custom workflow. Rendering a widget alone does not automatically secure arbitrary custom PHP processing; custom form handlers must still validate the submitted token server-side.<\/p>\n\n<h4>Diagnostics, Metrics and Site Health<\/h4>\n\n<p>The plugin includes diagnostics for configuration and verification health, local counters for passed\/failed checks, latency information, recent verification events and integration-level metrics. Site Health integration can surface configuration or connectivity issues to administrators.<\/p>\n\n<p>Developer Mode adds additional troubleshooting detail without changing the fundamental requirement that live submissions be verified correctly when protection is active.<\/p>\n\n<h4>Settings Portability<\/h4>\n\n<p>Settings can be exported and imported for controlled migration between WordPress installations. The transfer system is designed for plugin configuration rather than for exporting visitor submissions or unrelated site data.<\/p>\n\n<h4>Performance and Script Loading<\/h4>\n\n<p>The public Cloudflare Turnstile script is loaded only for pages\/contexts where the plugin determines that a Turnstile widget may be needed. The loader includes duplicate-script detection so multiple integrations do not intentionally enqueue several copies of the same Turnstile API script.<\/p>\n\n<p>Public assets are kept separate from the admin interface, and admin-only diagnostics\/settings code does not need to run as part of every anonymous form request.<\/p>\n\n<h4>Privacy and Data Flow<\/h4>\n\n<p>Turnstile is an external service provided by Cloudflare, so challenge rendering and server-side verification necessarily communicate with Cloudflare. The plugin itself stores configuration and limited diagnostic\/aggregate verification data locally. It does not require a Kitgenix account and does not send form contents to Kitgenix for verification.<\/p>\n\n<p>The exact Cloudflare data flow, WordPress.org Hub request and Google Fonts admin request are documented in the <strong>External Services<\/strong> section below.<\/p>\n\n<h4>Common Uses<\/h4>\n\n<ul>\n<li>Protect a WordPress login page from automated credential attacks.<\/li>\n<li>Reduce spam registrations on WordPress or WooCommerce.<\/li>\n<li>Add anti-bot verification to WooCommerce checkout and account forms.<\/li>\n<li>Protect Elementor and popular WordPress form plugins with one central Turnstile configuration.<\/li>\n<li>Add a challenge to membership, forum and community registration\/login flows.<\/li>\n<li>Replace more intrusive CAPTCHA experiences with Cloudflare Turnstile while keeping server-side validation.<\/li>\n<\/ul>\n\n<h3>Developer Notes<\/h3>\n\n<h4>Shortcode<\/h4>\n\n<pre><code>[kitgenix_turnstile]\n<\/code><\/pre>\n\n<h4>Main settings option<\/h4>\n\n<pre><code>kitgenix_captcha_for_cloudflare_turnstile_settings\n<\/code><\/pre>\n\n<h4>Useful filters<\/h4>\n\n<p>Script and display:<\/p>\n\n<ul>\n<li><code>kitgenix_captcha_for_cloudflare_turnstile_script_url<\/code><\/li>\n<li><code>kitgenix_turnstile_freshness_ms<\/code><\/li>\n<li><code>kitgenix_turnstile_inline_style<\/code><\/li>\n<\/ul>\n\n<p>Verification:<\/p>\n\n<ul>\n<li><code>kitgenix_turnstile_siteverify_url<\/code><\/li>\n<li><code>kitgenix_turnstile_siteverify_timeout<\/code><\/li>\n<li><code>kitgenix_turnstile_siteverify_sslverify<\/code><\/li>\n<li><code>kitgenix_turnstile_siteverify_http_args<\/code><\/li>\n<li><code>kitgenix_turnstile_send_remoteip<\/code><\/li>\n<li><code>kitgenix_turnstile_remote_ip<\/code><\/li>\n<li><code>kitgenix_turnstile_token_from_request<\/code><\/li>\n<li><code>kitgenix_turnstile_error_codes<\/code><\/li>\n<li><code>kitgenix_turnstile_error_message<\/code><\/li>\n<li><code>kitgenix_turnstile_replay_message<\/code><\/li>\n<li><code>kitgenix_turnstile_skip_wp_login_validation<\/code><\/li>\n<\/ul>\n\n<p>Replay protection:<\/p>\n\n<ul>\n<li><code>kitgenix_turnstile_replay_ttl<\/code><\/li>\n<\/ul>\n\n<p>Whitelisting and proxy handling:<\/p>\n\n<ul>\n<li><code>kitgenix_turnstile_is_whitelisted<\/code><\/li>\n<li><code>kitgenix_turnstile_trust_headers<\/code><\/li>\n<li><code>kitgenix_turnstile_trusted_proxies<\/code><\/li>\n<\/ul>\n\n<p>Operational alerts:<\/p>\n\n<ul>\n<li><code>kitgenix_turnstile_alert_window_seconds<\/code><\/li>\n<li><code>kitgenix_turnstile_alert_failure_spike_min_failures<\/code><\/li>\n<li><code>kitgenix_turnstile_alert_failure_spike_failure_rate<\/code><\/li>\n<li><code>kitgenix_turnstile_alert_http_error_min_failures<\/code><\/li>\n<\/ul>\n\n<p>Developer logging action:<\/p>\n\n<ul>\n<li><code>kitgenix_turnstile_dev_log<\/code><\/li>\n<\/ul>\n\n<p>The plugin also exposes context-specific error-message filtering through <code>kitgenix_captcha_for_cloudflare_turnstile_{context}_turnstile_error_message<\/code>.<\/p>\n\n<h3>Privacy and Local Data<\/h3>\n\n<p>The plugin stores its configuration in the WordPress database. Depending on enabled features it also stores local operational data such as setup-verification state, aggregate integration metrics, the recent event log and replay-protection transients.<\/p>\n\n<p>The recent event log is limited to 50 events and contains operational fields such as time, integration, success\/failure, error codes and Siteverify latency. It does not store raw form submissions, the raw Turnstile response token, the visitor's raw IP address or the request URL in that log.<\/p>\n\n<p>Turnstile itself is an external Cloudflare service and receives data when a widget is loaded and when the server validates a token. See <strong>External Services<\/strong> below.<\/p>\n\n<h3>External Services<\/h3>\n\n<p>This plugin relies on third-party services for specific functionality. These connections are documented here so site owners can make an informed decision before enabling and using the plugin.<\/p>\n\n<h4>Cloudflare Turnstile<\/h4>\n\n<p>Cloudflare Turnstile is the CAPTCHA \/ bot-verification service that provides the plugin's core protection. A Cloudflare account and Turnstile Site Key \/ Secret Key are required.<\/p>\n\n<p>When a protected widget is rendered, the visitor's browser loads Cloudflare Turnstile from:<\/p>\n\n<pre><code>https:\/\/challenges.cloudflare.com\/turnstile\/v0\/api.js\n<\/code><\/pre>\n\n<p>The browser communicates with Cloudflare as part of the Turnstile challenge. As with normal web requests, Cloudflare can receive network\/request information such as the visitor's IP address and browser\/request metadata, and Turnstile evaluates browser signals to generate a verification token.<\/p>\n\n<p>When a protected form is submitted, the WordPress server sends a POST request to:<\/p>\n\n<pre><code>https:\/\/challenges.cloudflare.com\/turnstile\/v0\/siteverify\n<\/code><\/pre>\n\n<p>By default, that request contains:<\/p>\n\n<ul>\n<li>The configured Turnstile Secret Key<\/li>\n<li>The Turnstile response token<\/li>\n<li>The visitor IP address as Cloudflare's optional <code>remoteip<\/code> parameter when an address is available<\/li>\n<\/ul>\n\n<p>The <code>remoteip<\/code> value can be disabled by developers with the <code>kitgenix_turnstile_send_remoteip<\/code> filter.<\/p>\n\n<p>Cloudflare documentation: https:\/\/developers.cloudflare.com\/turnstile\/\nCloudflare Terms: https:\/\/www.cloudflare.com\/website-terms\/\nCloudflare Privacy Policy: https:\/\/www.cloudflare.com\/privacypolicy\/<\/p>\n\n<h4>WordPress.org Plugin API<\/h4>\n\n<p>The shared Kitgenix Hub in wp-admin uses WordPress core's <code>plugins_api()<\/code> functionality to request public WordPress.org plugin-directory information such as plugin details, active-install counts, ratings and media.<\/p>\n\n<p>These requests occur on Kitgenix administration screens. The plugin supplies WordPress.org plugin slugs to WordPress core; the outbound request itself is handled by WordPress and can include normal HTTP request metadata generated by WordPress. Responses are cached locally with WordPress transients to reduce repeat requests.<\/p>\n\n<p>WordPress.org: https:\/\/wordpress.org\/\nWordPress.org Privacy Policy: https:\/\/wordpress.org\/about\/privacy\/<\/p>\n\n<h4>Google Fonts<\/h4>\n\n<p>The Kitgenix administration stylesheet imports the Inter and Manrope font families from Google Fonts. This occurs on Kitgenix plugin administration screens, not as part of the Turnstile verification request itself.<\/p>\n\n<p>Loading those font resources causes the administrator's browser to connect to Google-hosted domains such as <code>fonts.googleapis.com<\/code> and <code>fonts.gstatic.com<\/code>, which can receive normal request information such as IP address and browser headers.<\/p>\n\n<p>Google Fonts: https:\/\/fonts.google.com\/\nGoogle Privacy Policy: https:\/\/policies.google.com\/privacy\nGoogle Terms: https:\/\/policies.google.com\/terms<\/p>\n\n<h3>Trademark Notice<\/h3>\n\n<p>Cloudflare and Cloudflare Turnstile are trademarks or services of Cloudflare, Inc. This plugin is independently developed by Kitgenix and is not affiliated with or endorsed by Cloudflare, Inc.<\/p>\n\n<p>WordPress and WooCommerce trademarks belong to their respective owners. References are descriptive and identify supported integrations.<\/p>\n\n<h3>Support Development<\/h3>\n\n<p>Kitgenix CAPTCHA for Cloudflare Turnstile is free software. If the plugin is useful to you, you can support continued maintenance and development through the Donate link shown on the WordPress.org plugin page.<\/p>\n\n<p>More WordPress plugins and development resources are available from <a href=\"https:\/\/kitgenix.com\/\">Kitgenix<\/a>.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin through <strong>Plugins \u2192 Add New \u2192 Upload Plugin<\/strong>, or install it from the WordPress.org Plugin Directory.<\/li>\n<li>Activate <strong>Kitgenix CAPTCHA for Cloudflare Turnstile<\/strong>.<\/li>\n<li>Create a Turnstile widget in your Cloudflare account and copy its Site Key and Secret Key.<\/li>\n<li>Open the plugin settings from the Kitgenix menu in wp-admin.<\/li>\n<li>Enter the Site Key and Secret Key and run the setup verification test.<\/li>\n<li>Enable only the integrations and forms you want to protect.<\/li>\n<li>Test the protected forms while logged out and, where relevant, through checkout\/account flows.<\/li>\n<\/ol>\n\n<p>A Cloudflare account and Turnstile key pair are required. Your website does not need to use Cloudflare's CDN or proxy service to use Turnstile.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"what%20is%20cloudflare%20turnstile%3F\"><h3>What is Cloudflare Turnstile?<\/h3><\/dt>\n<dd><p>Cloudflare Turnstile is a CAPTCHA alternative that runs a challenge in the visitor's browser and produces a token. The token must then be validated server-side before the protected action is accepted.<\/p><\/dd>\n<dt id=\"do%20i%20need%20to%20use%20cloudflare%20dns%20or%20the%20cloudflare%20cdn%3F\"><h3>Do I need to use Cloudflare DNS or the Cloudflare CDN?<\/h3><\/dt>\n<dd><p>No. Turnstile can be used on a WordPress site even when the site's traffic is not proxied through Cloudflare.<\/p><\/dd>\n<dt id=\"do%20i%20need%20a%20cloudflare%20account%3F\"><h3>Do I need a Cloudflare account?<\/h3><\/dt>\n<dd><p>Yes. You need a Cloudflare account and a Turnstile Site Key \/ Secret Key pair.<\/p><\/dd>\n<dt id=\"does%20the%20plugin%20verify%20turnstile%20on%20the%20server%3F\"><h3>Does the plugin verify Turnstile on the server?<\/h3><\/dt>\n<dd><p>Yes. Supported integrations validate the token with Cloudflare's Siteverify endpoint before accepting the protected submission, unless Developer Mode or the relevant per-integration Test Mode is intentionally configured to warn rather than block.<\/p><\/dd>\n<dt id=\"which%20wordpress%20forms%20can%20it%20protect%3F\"><h3>Which WordPress forms can it protect?<\/h3><\/dt>\n<dd><p>Native WordPress login, registration, lost\/reset password and comment forms are supported. The plugin also supports WooCommerce, Easy Digital Downloads, Elementor Pro Forms, Contact Form 7, WPForms, Fluent Forms, Formidable Forms, Forminator, Gravity Forms, JetFormBuilder, Jetpack Forms, Kadence Forms, Ninja Forms and several membership\/community plugins.<\/p><\/dd>\n<dt id=\"does%20it%20support%20woocommerce%20checkout%20blocks%3F\"><h3>Does it support WooCommerce Checkout Blocks?<\/h3><\/dt>\n<dd><p>Yes. The plugin can render Turnstile in block-based checkout and validates the token server-side during the WooCommerce Store API checkout request.<\/p><\/dd>\n<dt id=\"does%20it%20support%20woocommerce%20hpos%3F\"><h3>Does it support WooCommerce HPOS?<\/h3><\/dt>\n<dd><p>Yes. The plugin declares HPOS compatibility and uses WooCommerce order CRUD methods for its Checkout Blocks verification metadata.<\/p><\/dd>\n<dt id=\"can%20i%20choose%20where%20the%20turnstile%20widget%20appears%3F\"><h3>Can I choose where the Turnstile widget appears?<\/h3><\/dt>\n<dd><p>Yes. Automatic placement is available for supported integrations, and many integrations include a shortcode-only placement option. The <code>[kitgenix_turnstile]<\/code> shortcode can also render a widget manually.<\/p><\/dd>\n<dt id=\"can%20i%20use%20the%20shortcode%20on%20any%20custom%20form%3F\"><h3>Can I use the shortcode on any custom form?<\/h3><\/dt>\n<dd><p>The shortcode can render the widget, but an unsupported custom form still needs a server-side validation integration. Rendering a widget alone is not sufficient security.<\/p><\/dd>\n<dt id=\"can%20different%20forms%20use%20different%20turnstile%20themes%20or%20sizes%3F\"><h3>Can different forms use different Turnstile themes or sizes?<\/h3><\/dt>\n<dd><p>Yes. Global theme, size and language settings can be overridden per integration.<\/p><\/dd>\n<dt id=\"what%20does%20developer%20mode%20do%3F\"><h3>What does Developer Mode do?<\/h3><\/dt>\n<dd><p>Developer Mode is warn-only. Failed verification is recorded but does not block the submission. Individual integrations can also be placed in Test Mode without putting the entire site into warn-only mode.<\/p><\/dd>\n<dt id=\"what%20is%20replay%20protection%3F\"><h3>What is replay protection?<\/h3><\/dt>\n<dd><p>Replay protection helps reject a Turnstile token that has already been accepted or processed. This reduces the usefulness of captured or repeatedly submitted tokens.<\/p><\/dd>\n<dt id=\"does%20the%20plugin%20include%20a%20honeypot%3F\"><h3>Does the plugin include a honeypot?<\/h3><\/dt>\n<dd><p>Yes. The optional honeypot can reject simple automated submissions before Cloudflare Siteverify is contacted.<\/p><\/dd>\n<dt id=\"can%20i%20whitelist%20administrators%20or%20trusted%20visitors%3F\"><h3>Can I whitelist administrators or trusted visitors?<\/h3><\/dt>\n<dd><p>The plugin can whitelist logged-in users, configured IP addresses\/ranges and User-Agent strings. Whitelisted visitors do not need to complete Turnstile, and the frontend Turnstile script is skipped for them.<\/p><\/dd>\n<dt id=\"does%20it%20work%20behind%20cloudflare%20or%20another%20reverse%20proxy%3F\"><h3>Does it work behind Cloudflare or another reverse proxy?<\/h3><\/dt>\n<dd><p>Yes. Proxy-aware IP detection is included. For security, forwarded headers are trusted only when proxy trust is enabled and the connecting proxy matches your configured trusted proxy list.<\/p><\/dd>\n<dt id=\"can%20i%20stop%20the%20visitor%20ip%20address%20being%20sent%20to%20cloudflare%20siteverify%3F\"><h3>Can I stop the visitor IP address being sent to Cloudflare Siteverify?<\/h3><\/dt>\n<dd><p>Developers can return <code>false<\/code> from the <code>kitgenix_turnstile_send_remoteip<\/code> filter. See the External Services section for the default data flow.<\/p><\/dd>\n<dt id=\"can%20i%20store%20the%20site%20key%20and%20secret%20key%20outside%20the%20wordpress%20database%3F\"><h3>Can I store the Site Key and Secret Key outside the WordPress database?<\/h3><\/dt>\n<dd><p>Yes. The plugin supports the <code>KITGENIX_CAPTCHA_FOR_CLOUDFLARE_TURNSTILE_SITE_KEY<\/code> and <code>KITGENIX_CAPTCHA_FOR_CLOUDFLARE_TURNSTILE_SECRET_KEY<\/code> constants and matching environment variables.<\/p><\/dd>\n<dt id=\"can%20i%20move%20settings%20between%20sites%3F\"><h3>Can I move settings between sites?<\/h3><\/dt>\n<dd><p>Yes. Export settings to JSON and import them using Replace or Merge mode. Credentials are excluded by default unless you explicitly include them.<\/p><\/dd>\n<dt id=\"why%20is%20the%20widget%20not%20appearing%3F\"><h3>Why is the widget not appearing?<\/h3><\/dt>\n<dd><p>Check that the Site Key exists, the integration and relevant form toggle are enabled, the visitor is not whitelisted, and another plugin or optimisation rule is not blocking <code>https:\/\/challenges.cloudflare.com<\/code>. Also check the plugin's duplicate-loader warning and Site Health test.<\/p><\/dd>\n<dt id=\"why%20do%20i%20see%20expired%2C%20missing%20or%20replayed-token%20errors%3F\"><h3>Why do I see expired, missing or replayed-token errors?<\/h3><\/dt>\n<dd><p>Turnstile tokens are short-lived and single-use. Cached forms, back-button resubmissions, double-clicks, delayed JavaScript or submitting after a token has expired can all require a fresh Turnstile challenge.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>2.0.0 (31 August 2026)<\/h4>\n\n<ul>\n<li>New: Redesigned the admin settings interface around the shared Kitgenix design system with a sticky topbar, cross-plugin branding, grouped navigation, an Advanced dropdown for Security, Advanced, and Portability, and a light\/dark theme toggle that remembers the selected preference.<\/li>\n<li>New: Added in-page settings search with \"\/\" and Cmd\/Ctrl+K keyboard shortcuts, filtering the active tab's cards and rows as you type and displaying a dedicated no-results state when nothing matches.<\/li>\n<li>New: Added a central Kitgenix Hub page for discovering, installing, activating, and reviewing Kitgenix plugins from one screen, integrated into the same topbar and navigation shell as the plugin settings.<\/li>\n<li>New: Added a shared Kitgenix component library providing reusable modals, collapsible sections, copy-to-clipboard controls, sortable\/searchable tables, and toast notifications.<\/li>\n<li>New: Added a dedicated Log tab containing active alerts, site-impact statistics, per-integration analytics, and the recent diagnostic log, moving diagnostics out of the Support tab.<\/li>\n<li>New: Added Ninja Forms integration with Turnstile tokens delivered through a request header rather than a hidden field, matching Ninja Forms' JSON-based submission architecture.<\/li>\n<li>New: Documented and re-verified the existing Kitgenix Plugin Score integration for login, registration, and forgotten-password protection.<\/li>\n<li>New: Added per-integration widget overrides for Theme, Widget Size, and Language, allowing individual integrations to override the global display settings or inherit them unchanged.<\/li>\n<li>New: Added an optional honeypot fallback under Settings \u2192 Security that rejects bots which blindly populate hidden fields before any request is sent to Cloudflare's <code>siteverify<\/code> endpoint.<\/li>\n<li>New: Added Test Mode per Integration under Settings \u2192 Developer Mode, allowing individual integrations to operate in warn-only mode while the rest of the site remains fully enforced.<\/li>\n<li>New: Diagnostic log entries now record Cloudflare <code>siteverify<\/code> round-trip latency so slow successful responses can be distinguished from failures and timeouts.<\/li>\n<li>New: Added a Protection Health card to the Log tab with actionable states including Healthy, No recent traffic, High failure rate, Cloudflare unavailable, Duplicate Turnstile loader, and Configuration problem.<\/li>\n<li>New: Added Integration, Result, Category, and Time Period filters to the recent diagnostic log alongside the existing free-text search.<\/li>\n<li>New: Renamed the per-integration analytics table to \"Integration health matrix\" and added each integration's Enabled\/Disabled state and Auto\/Shortcode injection mode.<\/li>\n<li>New: Settings imports now provide a client-side preview showing setting-key count, export date, whether Site\/Secret keys are included, included settings groups, and plugin-identifier mismatch warnings before Replace or Merge is committed.<\/li>\n<li>New: On WordPress 7.1 and later, the Kitgenix brand icon is registered with the WordPress Icon Registration API as <code>kitgenix\/mark<\/code> for discovery through <code>wp_get_icon()<\/code> and the icons REST endpoint.<\/li>\n<li>Improved: All settings areas \u2013 Site Keys, Display, Integrations, Security, Advanced, and Portability \u2013 now use consistent cards, labelled rows, toggle switches, and unified alert components.<\/li>\n<li>Improved: Refreshed the admin and public-facing Turnstile widget colours from the previous purple palette to the updated Kitgenix blue palette, including light and dark mode variants.<\/li>\n<li>Improved: The plugin-specific admin stylesheet now builds on the shared Kitgenix admin UI stylesheet for consistent spacing, typography, and component styling.<\/li>\n<li>Improved: The recent diagnostic log is now displayed as a searchable, paginated table with time, integration, outcome, and a plain-English note instead of a read-only text block.<\/li>\n<li>Improved: Retained the \"Copy recent log\" action for quickly copying the raw diagnostic log for troubleshooting or support.<\/li>\n<li>Improved: Per-integration analytics now supports live search and pagination.<\/li>\n<li>Improved: The Support tab is now three focused cards \u2013 a donate card with a collapsible monthly-amount picker, a \"what your support funds\" summary, and a \"get involved\" panel for reviews and plugin links.<\/li>\n<li>Improved: Stale WordPress security tokens are no longer counted as blocked attempts or included in the failure-spike alert threshold because they represent recoverable session or caching friction rather than genuine security rejections.<\/li>\n<li>Improved: The replayed-token diagnostic message now explains that the event can result from legitimate actions such as double-clicks or back-button resubmissions as well as malicious replay attempts.<\/li>\n<li>Improved: Both Turnstile validation entry points now consistently respect site-wide Developer Mode and the new per-integration Test Mode.<\/li>\n<li>Fix: WooCommerce lost\/reset-password protection is now self-contained. Enabling only the WooCommerce lost-password integration now validates its own My Account reset-request form without depending on the separate WordPress Core integration.<\/li>\n<li>Fix: WooCommerce lost-password validation is scoped to WooCommerce's own form and does not interfere with the native <code>wp-login.php<\/code> lost-password flow.<\/li>\n<li>Fix: WooCommerce login verification now runs only once per request when both modern and legacy WooCommerce login-error filters fire, preventing legitimate submissions from being incorrectly rejected as replayed or expired.<\/li>\n<li>Fix: bbPress forum creation now validates Turnstile exactly once on the correct pre-insert action instead of running a second redundant validation through <code>bbp_new_forum_pre_insert<\/code>.<\/li>\n<li>Fix: Removed incorrect handling that could replace bbPress forum post data with an unexpected validation return value.<\/li>\n<li>Fix: WPForms Turnstile errors now render the actual error message instead of the literal text \"Array\".<\/li>\n<li>Fix: The admin language allow-list is now sourced from <code>Script_Handler::get_allowed_languages()<\/code> so global and per-integration language settings cannot drift apart.<\/li>\n<li>Fix: Elementor AJAX handling is now scoped to the form that actually submitted a solved Turnstile token instead of affecting every Elementor form on the page.<\/li>\n<li>Fix: Elementor widgets are now hidden or cleared only after a confirmed successful form submission, preserving the widget after validation failures so visitors can retry.<\/li>\n<li>Security: Completed a full hook-by-hook enforcement audit of every supported integration to verify that a failed Turnstile check in enforcement mode actually blocks the protected action rather than merely being logged.<\/li>\n<li>Security: Fixed Contact Form 7 shortcode-only mode so the <code>wpcf7_validate<\/code> validation filter is always registered. Previously shortcode-only placement could render the widget while allowing submissions to bypass validation completely.<\/li>\n<li>Security: Contact Form 7 shortcode mode now correctly respects the integration's enable\/disable setting.<\/li>\n<li>Security: Removed request-method fail-open checks from Contact Form 7 and Elementor validation. Validation now runs whenever the host plugin invokes the relevant validation hook rather than trusting <code>$_SERVER['REQUEST_METHOD']<\/code> as a security boundary.<\/li>\n<li>Security: Fixed Easy Digital Downloads login protection by replacing the nonexistent <code>edd_process_login_form<\/code> hook with WordPress's real <code>authenticate<\/code> filter, scoped to EDD login submissions through EDD's own nonce field.<\/li>\n<li>Security: Fixed Fluent Forms enforcement by replacing the nonexistent <code>fluentform_submit_validation<\/code> hook with Fluent Forms' actual <code>fluentform\/validation_errors<\/code> validation filter.<\/li>\n<li>Security: Rebuilt Kadence Forms protection against the current Kadence Blocks \"Form (Adv)\" implementation using <code>kadence_blocks_advanced_form_submission_reject<\/code>, replacing dead hooks and an invalid class check that meant validation previously never ran.<\/li>\n<li>Security: Kadence Advanced Form widget injection now uses an appropriate frontend script bridge because the block does not expose a suitable PHP render filter.<\/li>\n<li>Security: Fixed Ninja Forms token delivery by attaching the token to the relevant AJAX request header rather than inserting a hidden DOM field that Ninja Forms never included in its JSON submission payload.<\/li>\n<li>Security: Ninja Forms failed Turnstile checks now terminate the submission request directly instead of writing to an error-array structure that Ninja Forms does not consult.<\/li>\n<li>Security: <code>Turnstile_Validator::validate_token()<\/code> now respects site-wide Developer Mode and per-integration Test Mode consistently with <code>is_valid_submission()<\/code>.<\/li>\n<li>Security: Confirmed diagnostic and analytics CSV exports do not introduce spreadsheet formula\/DDE injection because they contain plugin-generated labels and counters rather than raw user-submitted form values.<\/li>\n<li>Security: Confirmed settings exports continue to exclude the Site Key and Secret Key unless an administrator explicitly opts to include them.<\/li>\n<li>Security: Re-verified trusted-proxy client IP resolution against spoofed proxy headers and out-of-range CIDRs.<\/li>\n<li>Security: Proxy headers including <code>CF-Connecting-IP<\/code>, <code>True-Client-IP<\/code>, <code>X-Forwarded-For<\/code>, and <code>X-Real-IP<\/code> are only trusted when <code>REMOTE_ADDR<\/code> matches an administrator-configured trusted proxy address or CIDR.<\/li>\n<li>Security: Client IP values extracted from trusted proxy headers must be valid public addresses; private and reserved addresses are rejected.<\/li>\n<li>Performance: Frontend Turnstile script loading remains unchanged. Cloudflare <code>api.js<\/code> continues to load once and only when a widget will actually render for the current visitor.<\/li>\n<li>Performance: Whitelisted requests continue to skip Turnstile frontend script loading entirely.<\/li>\n<li>Performance: The existing duplicate Turnstile loader detector remains unchanged.<\/li>\n<li>Compatibility: Confirmed compatibility with WordPress 7.1.<\/li>\n<li>Compatibility: Declared WooCommerce High-Performance Order Storage (HPOS \/ <code>custom_order_tables<\/code>) compatibility.<\/li>\n<li>Compatibility: Re-verified that Checkout Blocks order verification metadata uses WooCommerce's <code>WC_Order<\/code> CRUD API through <code>update_meta_data()<\/code> and <code>save()<\/code> rather than direct database access.<\/li>\n<li>Compatibility: Verified WooCommerce 11.x compatibility across Classic Checkout, Checkout Blocks\/Store API, and WooCommerce My Account login, registration, and lost-password flows against current WooCommerce source.<\/li>\n<li>Dev: Added <code>Turnstile_Validator::get_all_integration_keys()<\/code> as the canonical list of integrations eligible for Test Mode and per-integration settings, sourced consistently with <code>get_integration_label()<\/code>.<\/li>\n<li>Dev: Updated Kitgenix logo and favicon filenames and references throughout the plugin and Kitgenix Hub to use the shared brand asset set.<\/li>\n<li>Dev: Refreshed the Kitgenix Hub plugin directory listing, including the renamed MultiStore for WooCommerce entry and the new Image Optimizer listing.<\/li>\n<li>Dev: Added automated tests covering enforcement regressions discovered during the integration audit.<\/li>\n<li>Dev: Added automated tests covering spoofed trusted-proxy headers and out-of-range CIDR scenarios.<\/li>\n<li>Documentation: Documented the Kitgenix Plugin Score integration in the readme for the first time.<\/li>\n<li>Documentation: Expanded the changelog to distinguish security-sensitive enforcement fixes from general bug fixes.<\/li>\n<li>Documentation: Documented the previously undocumented <code>kitgenix_turnstile_skip_wp_login_validation<\/code> filter under Developers \u2192 Filters.<\/li>\n<\/ul>","raw_excerpt":"Add Cloudflare Turnstile to WordPress, WooCommerce and popular forms with server-side verification and anti-spam controls.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/srd.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/245569","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/srd.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/srd.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/srd.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=245569"}],"author":[{"embeddable":true,"href":"https:\/\/srd.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/kitgenix"}],"wp:attachment":[{"href":"https:\/\/srd.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=245569"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/srd.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=245569"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/srd.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=245569"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/srd.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=245569"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/srd.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=245569"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/srd.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=245569"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}