PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteSome links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
The simplest way to protect WordPress comments is to use a plugin that explicitly supports the comments form, such as BestWebSoft’s reCaptcha plugin, then connect it to matching Google keys and test a real submission. A custom integration is also possible, but it must include Google’s server-side response verification—not just a browser widget.
Choose the reCAPTCHA version first
Your choice determines what commenters see and what your site must process. Google describes v2 as interactive and v3 as score-based: compare the official modes before creating keys.
| Mode | Commenter experience | What the site must do |
|---|---|---|
| v2 checkbox | The visitor checks a box; suspicious traffic may receive an additional challenge. | Display the widget and verify the response on the server. |
| v3 | No visible challenge in the normal flow; Google returns a risk score. | Verify the token and expected action, then apply a moderation, throttling or blocking policy based on your traffic. |
| Invisible v2 | No checkbox by default; suspicious visitors can still be challenged. | Invoke the widget through your form or callback and verify the response server-side. |
For v3, Google says tokens expire after two minutes, so request one when the comment action occurs and send it to your backend immediately: v3 implementation guidance.
Route 1: install a comments-compatible plugin
A plugin avoids writing form and backend code, but compatibility still depends on your theme, caching layer and other plugins. The WordPress.org listing for reCaptcha by BestWebSoft advertises support for the comments form and v2, v3 and Invisible modes. Treat that listing as a starting point, and follow the plugin’s current documentation and compatibility notes rather than relying on old screenshots or assumed field names.
#1 Best Overall
1. Create the Google key pair
- Open Google’s reCAPTCHA Developer’s Guide and start a registration.
- Select the reCAPTCHA type that matches the mode you intend to use in WordPress.
- Register every public hostname where comments are served (for example, the production domain and any separately used subdomain).
- Copy the generated site key and secret key. The site key is used by the page; the secret key authorizes backend verification and must remain private.
Google says registered domains include their subdomains, and changes can take up to 30 minutes to take effect. Its settings documentation also explains that disabling origin verification is not a casual fix: if you do so, your server must check the returned hostname itself.
2. Install and configure the plugin
- In WordPress, go to Plugins → Add New, search for the plugin, install it, and activate it.
- Open the plugin’s settings page and select the same reCAPTCHA mode used when the keys were created.
- Enter the site key and secret key in the corresponding fields. Do not swap them, and do not expose the secret key in page source, JavaScript or a public repository.
- Enable protection for the comments form. Keep the plugin’s current labels and instructions as the authority for any additional settings.
- Save, clear any page or script cache, and load a logged-out comment page in a private browser window.
Do not assume activation alone blocks spam. The widget or token must load, the submitted response must reach Google’s verification endpoint, and WordPress must handle the verification result.
Rank #2
Route 2: build a custom integration
Use this route when you need a bespoke moderation policy or cannot use a plugin. Google’s Developer’s Guide treats setup as two parts:
- Client side: invoke reCAPTCHA with the site key. For v2, Google’s display guide shows loading the API over HTTPS and rendering the widget. For v3, obtain a token for the specific comment action.
- Server side: send the token and secret key to Google’s verification service, reject missing or invalid responses, and only then accept or moderate the comment.
With v3, verify that the returned action is the action your code requested. The response also contains a score from 0.0 to 1.0. Google presents 0.5 as a suggested starting threshold, not a universal cutoff; observe legitimate and abusive traffic first, then choose what happens below your threshold.
Test the complete comment flow
- Open a post while logged out, preferably in a private window.
- Confirm that the v2 checkbox or Invisible-v2 behavior appears as intended, or that your v3 script requests a token when the form is submitted.
- Submit a normal test comment and confirm it follows your expected WordPress status (for example, pending moderation or approved).
- Inspect the browser console and server logs only for diagnostics; never log or publish the secret key.
- Repeat after clearing your CDN, page cache and optimization cache so you test the public version of the form.
Diagnose common setup failures
A WordPress.org support thread titled “Setting Up WordPress Plugin with V3” reports the message, “An error occurred loading the captcha, please check your Captcha Site Key.” That unresolved report does not establish one cause, but it identifies useful areas to check:
- Key type mismatch: the plugin mode and Google key type must be identical.
- Hostname mismatch: confirm the exact public hostname is registered, including the host visitors actually use. Allow up to 30 minutes after changing domains in Google’s settings.
- Script or cache interference: temporarily review JavaScript minification, defer/ delay settings, consent tools, CDN caches and security plugins that could prevent the reCAPTCHA script from loading.
- Server verification: for a custom build, confirm the token is sent promptly and that your backend checks Google’s response before processing the comment.
Do not disable domain or origin checks simply to make an error disappear; use hostname validation on the server if origin verification is disabled.
Rank #4
Privacy and visible branding
Google’s FAQ says reCAPTCHA sets a necessary cookie. Where Google’s domain is inaccessible, Google documents using www.recaptcha.net instead of www.google.com. If you hide an Invisible-v2 or v3 badge, Google still requires visible reCAPTCHA branding in the user flow; follow the current v3 and v2 requirements.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

