• Resolved brianjohnsondesign

    (@brianjohnsondesign)


    A large percentage (maybe 30%?) of my real users on a site achieve a ReCaptcha score of 0.0 almost every time. Something like 40% get a 0.9.

    I have read other posts of this issue and have tested the following:
    – Asked these users to try logging in using an incognito window (same result)
    – I’ve checked for JS console errors on the login page and backend (there are none)
    – I’ve verified the ReCaptcha keys are correct
    – All versions are up-to-date

    As a result of these low scores, these users essentially have to do two-factor authentication every time which they find very annoying.

    What’s weird is that these users have this problem EVERY time. I myself have never once had to do it, so I’m not sure what the difference is.

    Is there anything I can do to fix this?

Viewing 6 replies - 1 through 6 (of 6 total)
  • Plugin Support wfpeter

    (@wfpeter)

    Hi @brianjohnsondesign, thanks for getting in touch!

    If your users are having to perform verification email checks frequently, we have been pretty successful when setting the threshold to be 1.0 (Definitely a human) ourselves. Are you already running at this level?

    Google has been known to give some people a low score to prove they aren’t a bot, but 70% of your users getting 0.9 or lower seems like a high number. We aren’t in a position to be informed as to why Google’s algorithm comes to this conclusion, though.

    Let me know if adjusting the threshold seems to help at all,

    Peter.

    Thread Starter brianjohnsondesign

    (@brianjohnsondesign)

    If your users are having to perform verification email checks frequently, we have been pretty successful when setting the threshold to be 1.0 (Definitely a human) ourselves.

    That would make it MORE strict, right? If almost nobody is scoring a 1.0, wouldn’t that mean that pretty much everyone will have to do the verification? That would be the opposite of what we want, I would think.

    Because 1.0 is definitely human and 0.0 is definitely bot.

    I currently have the threshold set to 0.2, I believe. So in theory, anyone over that shouldn’t have to do the security check.

    Plugin Support wfpeter

    (@wfpeter)

    Hi @brianjohnsondesign,

    I agree that it sounds counter-intuitive to have a stricter setting, but we have had a good success rate with this being able to pick up human-like activity more accurately with less confirmation emails sent. Did you try a period of time with this set to 1.0 with no noticeable difference?

    Thanks again,

    Peter.

    Plugin Support wfpeter

    (@wfpeter)

    Hi @brianjohnsondesign,

    I’m just messaging to say that a setting of at least 0.7 should allow most humans visiting your site through as intended. It is unusual to hear of everybody (or most) receiving the email unless there is a Javascript error on your site causing problems authenticating the reCAPTCHA input, or you’re using a non-default login page for WordPress/WooCommerce. Inspecting your Browser Console for red Javascript errors, which you could screen grab and upload to a service like Snipboard and share here would let us take a closer look.

    Thanks again,

    Peter.

    Thread Starter brianjohnsondesign

    (@brianjohnsondesign)

    Hi Peter,

    Sorry for the very late reply.

    So things have changed a bit but still aren’t working great. At this point, something like 60% of users score 0.9 or higher, with most of those exactly at 0.9.

    Something like 38% score a 0.0, with very few in between. Now, presumably many or most of these are bots. But not all.

    I have a handful of users that complain that every single time they log in, they get the message that it requires additional verification and that they have to click a link in their email. I believe these users are scoring a 0.0, every single time.

    Do you have any idea why specific users would ALWAYS have to do this?

    I have just disabled the feature entirely for now because there are many users on this site, and my client is frustrated from having to deal with clients that have this issue. Not to mention that my client actually has this issue every time, too.

    It’s just weird that real users would ever score a 0, especially EVERY time.

    Fedep

    (@federicopalumbo)

    Same problem, I’m using wordfence since 3 years in different sites, Never reCAPTCHA?worked. You should implement v2 or other mechanism because at the end I can’t use reCAPTCHA?

Viewing 6 replies - 1 through 6 (of 6 total)
  • The topic ‘Many Valid Users get ReCaptcha Score of 0.0’ is closed to new replies.