We’re excited to share that the new Captcha WAF module is now in final beta inside cPFence. This highly requested feature brings powerful, low-impact protection to your websites by stopping bad bots before they hit your login pages. It operates entirely offsite, requires no user interaction, and is fully GDPR compliant, ensuring privacy and transparency while enhancing security.
Designed to work seamlessly with WordPress, Joomla, Laravel, and custom CMS or app login URLs, Captcha WAF intercepts suspicious requests and sends them to our offsite verification system. The goal: block bots, reduce server load, and let legitimate users pass without even noticing.
Why Captcha WAF is a Game Changer
Traditional brute-force protection tools struggle against slow, distributed attacks that use rotating IPs. Captcha WAF handles these more effectively by:
- Intercepting bot traffic offsite, so your server doesn’t waste resources analyzing or logging fake login attempts.
- Analyzing requests in real time, using behavioral and signature-based checks to distinguish bots from humans.
- Allowing real users through without interaction – no puzzles, no pop-ups, just seamless access for verified humans.
- Reducing false positives, because decisions are made outside your server environment using specialized validation logic.
- Supporting all major CMS platforms and custom logins, not limited to just WordPress.
What It Protects
Out of the box, Captcha WAF targets login pages like:
/wp-login.php (WordPress)
/administrator/index.php (Joomla)
/login.php, /admin.php, and any other path you choose
You can easily define custom URLs to protect within your WebUI or CLI configuration.
How It Works
Requests to login pages are intercepted before reaching your server.
They’re redirected to our offsite Captcha WAF system.



- After silent analysis, valid users are passed through; bots are blocked.

Current Status: Beta Testing
We’re now in the final beta phase, with many clients already testing this in production environments. Early results show significant reduction in login-related server load, and better bot detection accuracy than traditional local methods.
If you're interested in joining the beta or want to try this on your Enhance server, please open a ticket and let us know. We'll help you get set up and provide any guidance needed.