Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Cloudflare Turnstile is a CAPTCHA alternative that can protect WordPress logins, registrations, comments, contact forms, WooCommerce checkout and other actions without requiring the traditional image puzzle. The most practical setup is to create a Turnstile widget, copy its site and secret keys, then connect it through either a maintained WordPress plugin or your form builder’s native integration. Turnstile works even when your site does not use Cloudflare DNS or proxying, but every protected form must validate the token on the server before accepting the submission.
What you need before starting
- WordPress administrator access
- A Cloudflare account and access to your real website hostnames
- The form, membership or WooCommerce plugin you want to protect
- A backup and a recovery route through hosting or the filesystem, especially before protecting login or checkout
- A staging site or maintenance window for testing dynamic forms
Turnstile is Cloudflare’s bot-verification service, not the Cloudflare CDN, WAF or Challenge Pages. It can be added to a site hosted elsewhere. Cloudflare describes the service as a less intrusive CAPTCHA alternative that may run in the background or show a simple checkbox when necessary (Cloudflare overview). It is one layer of protection, not a complete WordPress security or spam-filtering system.
Create your Cloudflare Turnstile widget and keys
- Sign in to Cloudflare and open Turnstile.
- Choose the option to add or create a widget.
- Name it clearly, such as
example.com production formsorexample.com staging. - Choose Managed unless you have a specific reason to use Non-interactive or Invisible mode. Managed lets Turnstile decide whether interaction is needed.
- Add the exact production hostnames, such as
example.com,www.example.comorshop.example.com. A hostname mismatch can invalidate the widget. - Choose Auto, light or dark appearance and an appropriate language.
- Create the widget and copy both credentials.
| Credential | Purpose | Where it may appear |
|---|---|---|
| Site key | Public identifier used by the browser widget | Plugin settings or page markup |
| Secret key | Private credential used for server-side token verification | Protected server configuration only |
Never place the secret key in JavaScript, page source, a public repository, a screenshot or a custom HTML block. Keep the two keys from the same widget. Cloudflare’s setup and validation requirements are documented at developers.cloudflare.com/turnstile/get-started/.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Cloudflare’s Free plan currently allows up to 20 widgets, unlimited challenges or verification requests, up to 10 hostnames per widget and seven days of analytics lookback. Enterprise limits and features differ; enterprise pricing is contact-sales based (current plan limits). A paid WordPress plugin or form builder may still cost money even though Turnstile itself is available on the Free plan.
#1 Best Overall
- Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
- Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
- Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
- Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
- For the driver download and user guide, please visit TrustKey Solutions Home support page.
Method 1: Use a WordPress Turnstile plugin
For a site containing several kinds of forms, a generic plugin is usually the quickest route. Simple CAPTCHA with Cloudflare Turnstile is a free, third-party plugin—not an official Cloudflare product—and its directory listing claims support for WordPress authentication and comments, WooCommerce and many builders, including WPForms, Contact Form 7, Gravity Forms, Forminator, Fluent Forms and Elementor Pro (plugin listing).
Install and configure it
- In WordPress, open Plugins → Add New Plugin.
- Search for Simple CAPTCHA with Cloudflare Turnstile, verify the plugin identity, install it and activate it.
- Open Settings → Cloudflare Turnstile (the label can vary by version or translation).
- Paste the public site key into the site-key field and the private secret key into the secret-key field.
- Select only the forms you need initially: login, registration, password reset, comments, contact forms, membership forms, WooCommerce account or checkout, or newsletter signup.
- Save the settings and use Test API Response when that control is available.
The API test checks communication using the secret key; it does not prove that every selected form works. Submit each important form separately. Optional controls such as disabling the submit button until verification, custom failure messages, logged-in-user or IP allowlists, failsafe behavior and debug logging should be chosen for your site’s risk and usability requirements rather than enabled indiscriminately.
Store keys in protected configuration when appropriate
The plugin documents constants that can be placed in wp-config.php, above WordPress’s “stop editing” line:
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Rank #2
- Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
- USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
- FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
- Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
- Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.
define( 'CF_TURNSTILE_SITE_KEY', 'your-site-key' );
define( 'CF_TURNSTILE_SECRET_KEY', 'your-secret-key' );
Replace the example values, protect the file and do not commit it to a public repository. This approach is useful for deployment scripts and separate staging credentials (plugin documentation).
Method 2: Use your form builder’s native integration
Use a native integration when one form builder handles most of your site. It understands that builder’s validation, AJAX, multi-page and entry-processing lifecycle and is often easier to support than broad generic hooks.
WPForms example
- Install and activate WPForms.
- Create Turnstile keys in Cloudflare.
- Open the WPForms CAPTCHA settings.
- Select Cloudflare Turnstile and paste the site and secret keys.
- Choose the widget mode.
- Open each form, enable Turnstile, save and test it.
WPForms documents Turnstile for both WPForms Lite and paid versions (setup guide; CAPTCHA settings). Do not enable WPForms’ integration and a generic Turnstile plugin on the same form. Loading the Turnstile script twice—from a builder, theme or second plugin—can produce duplicate widgets and failed submissions.
Rank #3
- USB-C or tap via NFC for easy authentication on any compatible device. No drivers needed; optional Kensington software available for advanced management features.
- Works across Windows, macOS, iOS, Android, ChromeOS, and supports Passkeys and Apple ID.
- Slim, keychain-ready form for easy carry and on-the-go authentication
- IP68-rated for dependable performance
- FIDO CTAP 2.1 for enhanced security features (e.g. resident credentials, Passkey support) and backwards compatibility with CTAP 2. FIDO2 L2 certified security for phishing resistant protection against identity theft and unauthorized access.
Method 3: Manually protect a custom form
Manual integration is for developers maintaining a custom form, AJAX endpoint or unsupported workflow. Displaying a widget alone does not secure anything: the server must verify the token before running the form action.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteBrowser-side widget
<script src="https://challenges.cloudflare.com/turnstile/v0/api.js" async defer></script>
<form method="post">
<!-- Other fields and a WordPress nonce -->
<div class="cf-turnstile" data-sitekey="YOUR_SITE_KEY"></div>
<button type="submit">Submit</button>
</form>
Server-side requirements
The submitted token is normally in cf-turnstile-response. Your handler must safely read it, reject an empty value, send it with the secret key to https://challenges.cloudflare.com/turnstile/v0/siteverify, check the returned success value and then continue with nonce, authorization, validation, rate-limit and form-processing checks. Tokens can expire or be redeemed only once, so reject expired, reused or invalid tokens and return a useful non-sensitive error. Cloudflare’s required flow is described in the Turnstile documentation. Do not treat this snippet as a drop-in WordPress handler without wiring it into the endpoint’s existing security and error flow.
Test every protected workflow
- Open a private browser window while logged out and load the form.
- Confirm the widget loads once and complete any required interaction.
- Submit valid data and verify the normal success message, redirect and stored entry.
- Test required-field errors and a deliberately invalid, expired or blocked token on staging.
- Test mobile browsers.
- Open modal, popup and AJAX forms dynamically, not only on an initial page load.
- Test login and password reset without risking your only administrator session.
- Run a real WooCommerce checkout test, including shipping, payment and any AJAX updates or express-payment buttons.
- Review Turnstile analytics and hostnames. The Free plan provides a maximum seven-day analytics lookback (plan details).
“Working” means the widget loads once, a token is generated, the server validates it, missing or invalid verification is refused, and the specific form completes normally.
Rank #4
- Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T120. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
- Certified with the new FIDO2 standard, T120 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
- Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
- Fits USB-C port : Insert the T120 security key into the USB-C port of each service and log in conveniently with one touch
- For the driver download and user guide, please visit TrustKey Solutions Home support page.
Fix common Turnstile failures
| Symptom | Likely cause | First fix |
|---|---|---|
| Invalid sitekey | Typo, wrong widget or hostname mismatch | Copy the site key again, confirm the hostname and inspect console errors |
| Invalid input secret | Secret typo, keys from different widgets or stale rotated credentials | Copy both keys together, save and rerun the API test |
| Widget absent | JavaScript error, CSP, privacy extension, hidden modal, optimization or plugin conflict | Test privately, inspect the console, disable minification/defer/delay and exclude Turnstile resources |
| Widget appears twice | Generic plugin plus native builder, theme or another CAPTCHA loader | Keep one integration path per form |
| Form is blocked after verification | Expired or reused token, AJAX rerender, duplicate submit, cache or payment conflict | Refresh or rerender the widget, test without optimization and update the integration |
| Spam continues | Unprotected endpoint, failed-open integration, automated browser or no content filtering | Protect the actual endpoint and add rate limiting, honeypots and filtering |
| Login is inaccessible | Login integration conflict | Use hosting file management or SSH to rename the plugin directory and deactivate it, then restore access |
Purging page and object caches after configuration changes can remove stale scripts and markup. The plugin’s changelog shows that AJAX rerendering, disabled submit buttons, WooCommerce checkout, duplicate checks and payment-gateway compatibility require ongoing maintenance (plugin changelog). WPForms also documents duplicate loading as a failure cause (WPForms troubleshooting).
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Use Turnstile as one anti-abuse layer
Turnstile reduces automated submissions on the actions where it is correctly integrated; it does not firewall all WordPress traffic or guarantee that spam, credential stuffing, registration abuse, checkout fraud, REST/API abuse or contact-form flooding will stop. Add controls appropriate to the threat:
- Content-spam filtering such as Akismet
- Honeypots and URL or keyword rules
- Rate limiting and hosting or WAF rules
- Email confirmation and registration moderation
- Review of REST endpoints and application-password usage
- Manual moderation for comments and high-risk account actions
Choose fail-open, fail-closed or a fallback CAPTCHA deliberately. Fail-open preserves availability during a Cloudflare outage but weakens protection; fail-closed protects better but can block legitimate users. For payments, password changes, account creation and privileged access, do not enable fail-open without accepting that risk. Review your privacy notice and the selected plugin’s external-service disclosure because the browser loads Cloudflare resources and verification data is sent to Cloudflare (example disclosure).
Best Value
Which implementation should you choose?
| Situation | Best fit |
|---|---|
| Several WordPress, WooCommerce, comment and builder forms | A maintained generic Turnstile plugin |
| One builder with official Turnstile support and complex AJAX or multi-page forms | That builder’s native integration |
| Custom endpoint or bespoke workflow | Manual client- and server-side integration maintained by a developer |
| Already-loading Turnstile integration | Keep the existing path; do not add a second loader |
Use separate production and staging widgets where practical. One widget can cover multiple forms when the integration supports them, while separate widgets help isolate brands, domains, environments and analytics. The Free plan currently supports up to 20 widgets and 10 hostnames per widget.
Frequently Asked Questions
Does my WordPress site need Cloudflare DNS?
No. Turnstile can be used independently of Cloudflare nameservers, CDN proxying and WAF services.
Can I protect only the login form?
Yes. In a compatible plugin, select only Login and leave other form types disabled; test the login flow with a separate administrator recovery route.
Recommended Free Tools
Is Turnstile guaranteed to stop spam?
No. It reduces automated abuse on validated endpoints, but layered filtering, rate limiting and moderation are still needed.
Can I use Turnstile with WooCommerce?
Often yes, through a compatible plugin or WooCommerce-aware integration, but checkout payment, AJAX and express-payment flows require separate testing.
What happens if Cloudflare is unavailable?
The integration’s failsafe choice determines whether submissions are allowed, blocked or sent to another CAPTCHA. Choose that behavior according to the risk of each action.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.

