Wbcom CAPTCHA Manager 2.1.0 - Preactivated updates, hCaptcha fatal fix, five new locales
- New - Added a Discover tab to the admin with curated free Wbcom Designs tools.
- New - Added German, Spanish, French, Italian and Portuguese (Brazil) translations.
- Improve - Refreshed the settings screen with a modern card-based layout.
- Improve - reCAPTCHA and Turnstile scripts now load deferred on all browsers, improving page load speed and Core Web Vitals.
- Improve - More reliable ALTCHA spam detection.
- Improve - Automatic updates ship preactivated - there is no license key to enter and no account step.
- Improve - Section headings on Quick Setup, Protection and Advanced match the Overview tab instead of using a different blue and type size.
- Improve - Protection toggle cards are the same width in every section; the BuddyPress group no longer stretches wider than the WordPress group.
- Fix - Italian admin labels were shifted by one, so menu items read as the wrong thing - "Settings" showed as "Account", "Save Changes" as "Plugin Updates". Realigned every affected entry and restored the seven translations that had been dropped.
- Fix - The Italian block editor sidebar for the CAPTCHA Login block carried the same shift and is now correct.
- Fix - Text fields on Quick Setup and Advanced rendered at the browser default width and cut off their own values, so a saved error message could not be read back. They now fill the field column.
- Fix - The IP Whitelist box is a full-width monospace field instead of a single narrow line.
- Fix - The CAPTCHA language setting now applies correctly for hCaptcha and reCAPTCHA v2.
- Fix - Corrected the language selector display on the Advanced settings tab.
- Fix - The reCAPTCHA v3 score threshold set in the admin now takes effect.
- Fix - Removed unnecessary debug entries from the server error log.
- Fix - Prevented a fatal error on every failed hCaptcha verification.
- Fix - Prevented a rare fatal error when another plugin or theme uses the same generic class names.
- Fix - Prevented a fatal error on the front end when ALTCHA is the active provider.
- Fix - The plugin never registered its text domain, so bundled translations could never load.
- Fix - Block editor translations could never resolve, because the editor script was never told where this plugin keeps its translation files.
- Fix - Around thirty admin strings had no translatable source and always rendered in English.
- Security - Comment forms are now protected on every site, not only sites running WooCommerce.
- Security - Lost-password submissions are now verified on every site, not only sites running WooCommerce.
- Security - BuddyPress group creation is now blocked when the CAPTCHA is not completed.
- Security - The login widget now resets its CAPTCHA after a failed attempt, closing a token-reuse window.
- Security - The login form can no longer be submitted without completing the CAPTCHA on sites that do not use WooCommerce.
- Security - The setup wizard is now restricted to administrators.
- Dev - Corrected the minimum supported WordPress version metadata.
- Dev - Settings-field styles are scoped to the card-panel shell, which had orphaned them.
- Dev - Admin content styles now consume the shared admin design tokens; five competing accent blues consolidated to one.
- Dev - Removed an unused appearance-cards stylesheet that was still being loaded on every admin screen.
- Dev - PHPStan level 5 runs clean against the plugin's own config.
- Compat - Tested with WordPress 7.0.
Full changelog: https://wbcomdesigns.com/release-notes/buddypress-recaptcha/