cPFence v4 public beta is here.

Explore v4
News

Captcha WAF Is Now Live in cPFence!

CAPTCHA WAF conceptual feature illustration

We’re excited to announce that the Captcha WAF module is now officially available in cPFence.

No more hours spent manually adding CAPTCHA plugins or scripts to every login page — with cPFence, you get one-click, server-level protection that applies instantly across all your sites. This feature brings silent, offsite protection to your login pages, blocking bots before they ever reach your server — all with zero user interaction required.

Why Captcha WAF?

Most CMS-based websites, especially WordPress, are constantly hit by automated POST requests to login pages like /wp-login.php. These attacks are often slow and distributed, using different IPs and user agents to bypass traditional brute-force protections.

That’s where Captcha WAF comes in:

  • Intercepts bots offsite, before they reach your web server
  • No user interaction – real visitors pass through silently
  • Blocks automated brute-force, dictionary, and credential-stuffing bots
  • Reduces server load by handling logic offsite
  • Supports all popular CMS and custom login URLs
  • User-defined protection – apply it to any path you want
  • Working with WordPress, Joomla, Laravel, and any custom CMS or login system
  •  Powered by cPFence’s load-balanced backend for accurate, high-speed validation

It’s a smarter way to handle login protection—low impact, high effectiveness.


How It Works

  1. A visitor tries to access a protected login page
  2. The request is redirected to cPFence’s offsite Captcha WAF
  3. It’s silently analyzed in real-time
  4. Real users are passed through instantly, bots are blocked

Visual example:

Analyzing behavior in real time
No user interaction – real visitors pass through silently
Block bad bots & scripts


Built for Privacy and Performance

Captcha WAF is fully GDPR compliant, keeping user privacy intact while protecting your login pages.


Fully Integrated in the WebUI

Managing Captcha WAF is easy via:

cPFence v4+ WebUI → WAF Management. Select the intended server; support accounts need the corresponding WAF management permissions.

You’ll see:

  • Settings → CAPTCHA WAF globally to enable or disable the module server-wide. Keep cPFence WAF enabled, then Save.
  • Manage domain → Domain settings → CAPTCHA protection to enable or disable it for an individual domain, then Save.
WAF Settings on Local showing cPFence WAF and CAPTCHA WAF globally controls.
Global CAPTCHA controls for the selected server; the switches show its saved settings.
Manage domain with Domain settings expanded and a separate CAPTCHA protection switch.
CAPTCHA has its own per-domain switch; the selected domain is hidden for privacy.

After saving, check the result and try the intended login path as a legitimate visitor. Hosted WAF CAPTCHA is separate from WordPress math CAPTCHA; cookie and other exemptions can skip a challenge on some requests. See CAPTCHA controls and troubleshooting.

Prefer the CLI?

If you prefer working on the command line, run these commands as root on the intended server:

cpfence --enable-captcha-waf-domain DOMAIN
    Re-enable CAPTCHA WAF protection for a specific domain
    (e.g., cpfence --enable-captcha-waf-domain a.com)

cpfence --disable-captcha-waf-domain DOMAIN
    Disable CAPTCHA WAF protection for a specific domain
    (e.g., cpfence --disable-captcha-waf-domain a.com)

cpfence --enable-captcha-waf-global
    Re-enable CAPTCHA WAF Module globally for all domains on the server

cpfence --disable-captcha-waf-global
    Disable CAPTCHA WAF Module globally for all domains on the server

Easily Customize Protected URLs

You can now manage exactly which login pages are protected by Captcha WAF using a simple interface in the WebUI. Go to:

WebUI → Edit Configuration Files → CAPTCHA protected URLs. Choose the target server, keep a copy of its current list and briefly disable its WAF master before saving an edit.

Configuration Files editor with CAPTCHA protected URLs selected and its v4 path.
The server-level CAPTCHA path list in the current editor; private file contents are concealed.

From there, add or remove one login path per line in File content — whether it’s a WordPress login, a custom admin panel, or a third-party app. Keep the paths you still need, Save changes, then reload to check the saved list.

This gives you full flexibility to define protection at any entry point without editing files manually on the server. Or simply edit the file :

/etc/cpfcli/waf/userdata_login_pages

Re-enable WAF promptly after editing. Changes apply at the next WAF enable; check the global and domain CAPTCHA switches again. If a legitimate login breaks, restore the prior path list using the same workflow. See protected URL editing.

LiteSpeed Cache Compatibility – Handled Automatically

To ensure proper interception of login requests, WP-AutoShield can automatically disable LiteSpeed cache on WordPress login pages when cPFence WAF is enabled and the login-cache policy is on. The change applies when WP-AutoShield runs.

This behavior is enabled by default, but you can control it via config or CLI:

Config option:
autoshield_disable_ls_cache_login_page

CLI commands:

cpfence --bulk-disable-ls-cache-login-page
    Disable login page caching in LiteSpeed Cache server-wide (recommended for Captcha WAF)

cpfence --bulk-enable-ls-cache-login-page
    Re-enable login page caching in LiteSpeed Cache server-wide (if not using Captcha WAF)

For browser-based site selection and login-cache controls, see WordPress login-page caching. Review the affected sites before applying a cache-policy change.

This ensures Captcha WAF works smoothly even with aggressive caching setups, with no extra configuration needed.


Ready to enable it on your servers?

Update to the latest version of cPFence and let’s stop bots before they knock. Try cPFence v4+ and manage login protection from the WebUI.

Start free trial
← Back to all articles
KEEP EXPLORING
All articles