Simple Login Captcha icon

Simple Login Captcha

by Nikolay Nikolov

View on WordPress.org
77 Quality Score
Active Installs
18/30

Active on about 10,000 sites, this is a modest install base compared to top security plugins that run on millions of installs, so it lands mid-pack on reach.

Update Freshness
25/25

Updated within the past day and tested against WordPress 7.0, so maintenance signals are extremely fresh, though the low requires-WordPress (3.5) and PHP (5.2) values hint at a long-stable but minimally maintained codebase.

User Rating
12/15

A 78 out of 100 from 17 reviewers is a respectable rating, but the small sample size means the score carries limited statistical weight.

Support Health
8/15

Zero support threads and zero resolutions give a perfect 50 out of 15 on support health, which in practice means there is no public track record of the author helping users.

WP Compatibility
15/15

A perfect compatibility score reflects broad PHP and WordPress version tolerance, making it deployable on very old to very new environments.

Scores higher than 56% of indexed plugins

About

Adds a simple 3-digit number captcha on the login form.

Active Installs 10k+
Rating ★★★½ 3.9/5
Last Updated 2026-09-03 8:07pm GMT
Requires WordPress 3.5+
Tested Up To 7.1
Requires PHP 5.2+
✓ No known vulnerabilities

What It Does

Simple Login Captcha displays a small three-digit number challenge on the WordPress login screen that visitors must type before they can submit credentials. It is a lightweight, server-side captcha designed to block automated brute-force and credential-stuffing attempts. There is no configuration panel beyond enabling or disabling the captcha; it works out of the box.

Who It's For

This plugin suits site owners running a small business site, membership portal, or community forum who want a quick, no-fuss layer of login protection without managing settings or third-party API keys. It works well for blog owners or local service businesses who lack the technical confidence to configure a full security suite. It is best suited to WordPress sites using the default wp-login.php page where only a basic bot deterrent is needed.

Who Should Skip It

Anyone already using a comprehensive security plugin such as Wordfence, Jetpack, or Really Simple Security should skip this tool, since those suites include their own login captcha and brute-force protection. Sites facing serious, targeted attack traffic should also look elsewhere: a static three-digit captcha is trivially defeatable by modern OCR-driven bots.

The Bottom Line

Simple Login Captcha earns a 77.11 out of 100 from PluginCheck: it does one job and appears to do it well, but its tiny install base, near-empty support history, and trivially bypassable three-digit challenge limit its usefulness. Use it as a quick, free deterrent on a low-value site, but skip it on anything that stores sensitive data or attracts targeted attacks. Overall it is a decent, narrow tool rather than a replacement for a real security suite.

Tags

captcha login security simple spam