Protect selected forms
Turnstile is applied when the plugin is active, keys are configured, and the individual CMS Max form has CAPTCHA enabled.
Native form bot protection
Add bot resistance without making every legitimate visitor solve a visual puzzle.
CMS Max integrates Cloudflare Turnstile with public forms that have CAPTCHA enabled. Teams can use the CMS Max enterprise account or their own Cloudflare site key and encrypted secret, while CMS Max renders the widget, validates the token, blocks failures, and resets expired or rejected challenges.
Current support boundary
Cloudflare states that the client token must be validated with Siteverify. CMS Max performs that validation for protected public forms, clears failed or expired tokens, blocks the submission, reports the field error, and resets the widget for a fresh attempt.
Turnstile is applied when the plugin is active, keys are configured, and the individual CMS Max form has CAPTCHA enabled.
The site key is public for browser rendering. The secret key is encrypted in CMS Max settings and belongs only in server validation.
Expired, invalid, missing, duplicate, timeout, and API-failure outcomes must let a legitimate visitor obtain a fresh token and resubmit.
Operational controls
Turnstile can work without using Cloudflare as the website CDN. High-traffic sites or teams needing their own analytics and configuration should use a merchant-owned account.
Select the shared CMS Max Enterprise Account when the standard platform configuration fits the site.
Create a Turnstile widget in Cloudflare and enter the site key and encrypted secret key in CMS Max.
CMS Max explicitly renders the widget when the form enters view and keeps one widget instance per live form component.
Enable CAPTCHA on the specific CMS Max forms that require bot protection; forms without that setting do not render the widget.
CMS Max validates the submitted token and blocks the form when the provider rejects, expires, or cannot verify it.
After a validation failure, CMS Max clears the token, requests a widget reset, preserves other useful form feedback, and supports a fresh submission.
Implementation workflow
Test both legitimate recovery and blocked automation; a green widget alone is not acceptance evidence.
Decide between the CMS Max enterprise account and a merchant-owned Cloudflare account with named owners and hostnames.
Install the plugin, select the account type, enter valid keys when required, and enable CAPTCHA on the intended forms.
Submit each protected form on desktop and mobile, confirm the submission record and notifications, and test a second attempt after a normal field error.
Exercise missing, expired, rejected, duplicate, timeout, and provider-error tokens and confirm no protected submission is accepted.
Review spam, validation failures, form completion, support contacts, key rotation, hostname changes, and new forms over time.
Clear responsibility
Treat completion rate and abuse rate as connected measures so a stricter control does not silently damage legitimate conversion.
Current references
Cloudflare identifies server-side validation as mandatory and documents five-minute, single-use tokens. CMS Max source and tests confirm validation and reset behavior.
Cloudflare Turnstile FAQ
Confirm the account, form, hostname, keys, validation, failure, monitoring, and privacy responsibilities.
Yes. The current plugin renders Turnstile on public CMS Max forms with CAPTCHA enabled and validates the response before accepting the submission.
No. Cloudflare documents Turnstile as an independent service that can run on websites not proxied through the Cloudflare network.
Yes. Select Use your own Cloudflare account and supply the widget site key and secret key. CMS Max encrypts the stored secret key.
CMS Max blocks the submission, clears the token, reports the Turnstile validation error, and resets the widget so the visitor can obtain a fresh challenge.
No. Cloudflare states that server-side Siteverify validation is mandatory. CMS Max performs server validation for the protected form path.
Security requires operations
Review the forms, spam patterns, account ownership, hostnames, privacy language, completion metrics, notifications, support path, testing, and monitoring before launch.
The world's fastest and most SEO friendly website code.