• Resolved aledef

    (@aledef)


    Hi,
    I’m using Hcaptcha to protect login from brute force attacks.

    After a closer look I realized that captcha error is shown only if username is good, otherwise wrong username notice is shown.

    In other words captcha is verified AFTER username verification, whilst it should be verified BEFORE.

    This way its effectiveness against brute force attacks is quite low.

    I tried this on WP fresh install with Twenty Twenty-One themeand no other plugins active.

Viewing 1 replies (of 1 total)
Viewing 1 replies (of 1 total)
  • The topic ‘Captcha verified after user and password verification’ is closed to new replies.