Flash Sale:75% Off Hosting + Free DomainEnds in13h47m14sView Plans
Hostvento logoHostvento

How to add CAPTCHA to protect your Magento store

This guide shows you how to turn on CAPTCHA in Magento. It helps stop spam bots from using your forms.

How-To Guides2 min read21 steps

What is CAPTCHA?

CAPTCHA is a small test that tells humans and bots apart. It may ask you to type distorted letters or tick a box. Bots fail the test, so they cannot fill in your forms.

Magento is an online store platform. Its menus differ a little between versions, so look for the names below. If you cannot find them, your version may be different.

Option 1: Built-in image CAPTCHA

This option shows letters in an image. It is available in many Magento versions.

  1. Log in to your Magento admin panel.
  2. Click Stores, then Configuration.
  3. Open Customers, then Customer Configuration.
  4. Open the CAPTCHA section.
  5. Set Enable CAPTCHA in Admin to Yes if you want it on the admin login.
  6. Set Enable CAPTCHA on Storefront to Yes.
  7. In Forms, select the forms to protect. Examples are Create user, Login and Forgot password.
  8. Choose how many characters and which symbols the image uses. Short and simple is friendlier for visitors.
  9. Click Save Config.
  10. Clear the cache. Go to System, then Cache Management, and click Flush Magento Cache.

Option 2: Google reCAPTCHA

Newer Magento 2 versions (2.4 and later) support Google reCAPTCHA. It often only asks the visitor to tick a box.

  1. Sign in to the Google reCAPTCHA website with a Google account.
  2. Register your site. Pick the type your Magento version supports, such as v3 or v2 checkbox.
  3. Add your domain name. Google gives you a site key and a secret key.
  4. In Magento, go to Stores, then Configuration, then Security.
  5. Open Google reCAPTCHA Storefront.
  6. Paste your keys into the key fields.
  7. Under Storefront, choose which forms use reCAPTCHA.
  8. Click Save Config and flush the cache.
Tip: Keep your secret key private. Do not share it or post it online.

Test it

  1. Open your store in a private browser window.
  2. Go to the login or contact form you protected.
  3. Check that the CAPTCHA shows up and works.

If it does not appear, flush the cache again. If it still fails, check for a clash with another extension. You can also open a support ticket.

Quick recap

  • CAPTCHA stops bots from filling in your forms.
  • Built-in CAPTCHA is under Stores, Configuration, Customers.
  • Google reCAPTCHA is under Stores, Configuration, Security in newer versions.
  • Always save and flush the cache.