Legacy CAPTCHA migration

Moving from hCaptcha to Cloudflare Turnstile

Replace the retired CMS Max hCaptcha path with the form-protection integration the platform supports today.

hCaptcha is not an active CMS Max plugin in the current platform. Legacy migration logic installs Cloudflare Turnstile instead, and orphaned hCaptcha plugin settings were removed. This page preserves the migration path without implying current native hCaptcha support.

  • hCaptcha retired
  • Turnstile replacement
  • Form-by-form test
  • No silent fallback

Current support boundary

Do not treat the old plugin page as proof of current hCaptcha availability.

The current CMS Max repository contains no active hCaptcha plugin service, settings page, rendering path, or validation provider. It contains explicit migration and cleanup logic that replaces the legacy identifier with Cloudflare Turnstile.

01

Inventory the legacy use

Identify every form, domain, environment, hCaptcha account, key, privacy reference, alert, dashboard, and support procedure.

02

Configure the replacement

Install Cloudflare Turnstile, choose the CMS Max enterprise or merchant-owned account, and enable CAPTCHA on the intended forms.

03

Prove submission behavior

Test valid, missing, expired, rejected, duplicate, timeout, field-error, resubmission, notification, and record-creation outcomes.

Operational controls

Move the operating controls, not just the logo or script.

A CAPTCHA migration changes account ownership, keys, hostnames, analytics, token validation, browser rendering, failure handling, privacy references, and support.

01

Account

Decide who owns the Cloudflare account, widget, keys, analytics, rotation, and incident response.

02

Keys

Replace hCaptcha values with the Turnstile account model and never copy an old secret into an unrelated field.

03

Forms

Confirm CAPTCHA is enabled on each intended CMS Max form and absent where the business has approved no challenge.

04

Validation

Verify server-side Turnstile validation blocks missing, invalid, expired, and replayed tokens.

05

Experience

Test desktop, mobile, keyboard, zoom, errors, resubmission, slow completion, and legitimate visitors.

06

Operations

Update privacy text, documentation, alerts, support scripts, monitoring, owners, and decommission records.

Implementation workflow

Inventory, replace, validate, and retire the legacy account cleanly.

Keep the old hCaptcha configuration until the replacement has passed acceptance, then remove unused keys and references under change control.

  1. 01

    Inventory

    List protected forms, domains, hCaptcha credentials, account owners, privacy text, analytics, alerts, and support procedures.

  2. 02

    Configure Turnstile

    Install the current plugin, choose account ownership, configure hostnames and keys, and enable CAPTCHA on selected forms.

  3. 03

    Test

    Prove successful submissions and all meaningful challenge and form-validation failure paths in a non-production environment.

  4. 04

    Launch

    Release with completion and abuse monitoring, support coverage, a rollback decision, and a named acceptance owner.

  5. 05

    Retire

    Remove unused hCaptcha keys, account access, scripts, documentation, billing, privacy references, and alerts after the migration is accepted.

Clear responsibility

The current integration boundary is Cloudflare Turnstile.

hCaptcha may remain a separate third-party service, but it is not the active native CMS Max form-protection path.

CMS Max
Owns the current Cloudflare Turnstile plugin, public-form rendering and validation path, legacy migration mapping, and CMS Max support scope.
Cloudflare
Owns the replacement challenge and token-validation service, dashboard, keys, analytics, and provider support.
Legacy hCaptcha owner
Owns old account access, keys, billing, dashboards, data, decommissioning, and any non-CMS Max implementations.
Website and form owners
Own migration acceptance, form selection, legitimate completion, privacy updates, monitoring, notifications, support, and documentation.

Current references

Use the provider account and documentation as the live source.

Cloudflare publishes migration guidance for other CAPTCHA services and identifies server validation as mandatory. CMS Max source records the specific hCaptcha-to-Turnstile migration.

hCaptcha migration FAQ

Resolve the practical questions before production.

This page documents a legacy transition and should not be used to promise current hCaptcha support.

Is hCaptcha still a native CMS Max plugin?

No. The current CMS Max platform removed the hCaptcha plugin and its orphaned settings and uses Cloudflare Turnstile as the supported native form-protection path.

What happens to hCaptcha during a legacy CMS Max migration?

Current migration logic maps the legacy hCaptcha plugin identifier to Cloudflare Turnstile and installs the Turnstile plugin instead.

Can old hCaptcha keys be pasted into Turnstile settings?

No. Create or select the correct Turnstile account and use the Turnstile site key and secret key for that widget and environment.

Should the hCaptcha account be deleted immediately?

Not before inventory and acceptance. Confirm there are no other websites or applications using the account, preserve required records, and retire it under the organization's change process.

Where should new CMS Max form protection be configured?

Use the Cloudflare Turnstile plugin and enable CAPTCHA on each CMS Max form that requires protection.

Security requires operations

Plan the migration around forms, people, and evidence.

Bring the legacy form inventory, hCaptcha account ownership, current spam patterns, privacy references, notification flows, support needs, and acceptance criteria.

Building Relationships with Web Developers and Marketing Agencies that want better results

The world's fastest and most SEO friendly website code.