SimpleMath Captcha
Introduction
A privacy-first, fully accessible, self-hosted arithmetic CAPTCHA for Joomla 4.4, 5, and 6.
SimpleMath Captcha
SimpleMath Captcha asks visitors a simple maths question — "What is 7 + 5?" — instead of an
image puzzle or a third-party widget. The question is generated and checked entirely on your
own server. Nothing about the visitor is ever sent anywhere else: no external script, no
third-party cookie, no tracking pixel, no API call to Google, Cloudflare, or anyone.
Highlights
- Zero external services. No API key, no account, no internet access required.
- Five ready-made presets — Minimal, Standard, Accessible, Secure, or fully Custom.
- Seven visual timer styles — Circle, Pie, Underline, Dots, Equation fill, Ring, or Hidden.
- Full appearance control — theme, layout, size, colours, radius, spacing, and more, all through CSS custom properties.
- WCAG 2.2 AA accessible by default, with an Accessible preset and an AAA-contrast High Contrast mode.
- Five bundled languages — English, German, Spanish, Italian, and French.
- Works without JavaScript. The captcha is fully functional as a plain server-rendered field; JavaScript only adds the live countdown, instant validation, and refresh button on top.
- Layered security — single-use, session-bound, server-validated challenges, progressive delays on wrong answers, rate limiting, an optional honeypot field, and optional timing analysis.
- Runs on Joomla 4.4, 5.x, and 6.x from a single codebase, using the correct captcha API for each version automatically.
How it works
Every challenge is generated with a cryptographically secure random number generator, stored
as a keyed hash in the visitor's own session, and removed the instant it is checked. There is
no way to reuse a challenge, and the real answer is never present anywhere in the page markup.
Who it's for
Any Joomla site owner who wants effective spam protection on contact forms, registration, or
custom forms without asking visitors to solve an image puzzle, without a third-party account,
and without sending visitor data off-site.
Full documentation, with every setting explained field by field, is linked below.
Share