Inventory the legacy use
Identify every form, domain, environment, hCaptcha account, key, privacy reference, alert, dashboard, and support procedure.
Legacy CAPTCHA migration
Replace the retired CMS Max hCaptcha path with the form-protection integration the platform supports today.
hCaptcha is not an active CMS Max plugin in the current platform. Legacy migration logic installs Cloudflare Turnstile instead, and orphaned hCaptcha plugin settings were removed. This page preserves the migration path without implying current native hCaptcha support.
Current support boundary
The current CMS Max repository contains no active hCaptcha plugin service, settings page, rendering path, or validation provider. It contains explicit migration and cleanup logic that replaces the legacy identifier with Cloudflare Turnstile.
Identify every form, domain, environment, hCaptcha account, key, privacy reference, alert, dashboard, and support procedure.
Install Cloudflare Turnstile, choose the CMS Max enterprise or merchant-owned account, and enable CAPTCHA on the intended forms.
Test valid, missing, expired, rejected, duplicate, timeout, field-error, resubmission, notification, and record-creation outcomes.
Operational controls
A CAPTCHA migration changes account ownership, keys, hostnames, analytics, token validation, browser rendering, failure handling, privacy references, and support.
Decide who owns the Cloudflare account, widget, keys, analytics, rotation, and incident response.
Replace hCaptcha values with the Turnstile account model and never copy an old secret into an unrelated field.
Confirm CAPTCHA is enabled on each intended CMS Max form and absent where the business has approved no challenge.
Verify server-side Turnstile validation blocks missing, invalid, expired, and replayed tokens.
Test desktop, mobile, keyboard, zoom, errors, resubmission, slow completion, and legitimate visitors.
Update privacy text, documentation, alerts, support scripts, monitoring, owners, and decommission records.
Implementation workflow
Keep the old hCaptcha configuration until the replacement has passed acceptance, then remove unused keys and references under change control.
List protected forms, domains, hCaptcha credentials, account owners, privacy text, analytics, alerts, and support procedures.
Install the current plugin, choose account ownership, configure hostnames and keys, and enable CAPTCHA on selected forms.
Prove successful submissions and all meaningful challenge and form-validation failure paths in a non-production environment.
Release with completion and abuse monitoring, support coverage, a rollback decision, and a named acceptance owner.
Remove unused hCaptcha keys, account access, scripts, documentation, billing, privacy references, and alerts after the migration is accepted.
Clear responsibility
hCaptcha may remain a separate third-party service, but it is not the active native CMS Max form-protection path.
Current references
Cloudflare publishes migration guidance for other CAPTCHA services and identifies server validation as mandatory. CMS Max source records the specific hCaptcha-to-Turnstile migration.
hCaptcha migration FAQ
This page documents a legacy transition and should not be used to promise current hCaptcha support.
No. The current CMS Max platform removed the hCaptcha plugin and its orphaned settings and uses Cloudflare Turnstile as the supported native form-protection path.
Current migration logic maps the legacy hCaptcha plugin identifier to Cloudflare Turnstile and installs the Turnstile plugin instead.
No. Create or select the correct Turnstile account and use the Turnstile site key and secret key for that widget and environment.
Not before inventory and acceptance. Confirm there are no other websites or applications using the account, preserve required records, and retire it under the organization's change process.
Use the Cloudflare Turnstile plugin and enable CAPTCHA on each CMS Max form that requires protection.
Security requires operations
Bring the legacy form inventory, hCaptcha account ownership, current spam patterns, privacy references, notification flows, support needs, and acceptance criteria.
The world's fastest and most SEO friendly website code.