ModKor Captcha & Bot Protection for Magento 2 & Hyva

Stop bot spam, fake accounts and brute-force logins with one invisible captcha and three layers of defense behind it. Choose Google reCaptcha (v2/v3), Cloudflare Turnstile or hCaptcha — tested across all four — tick the forms to protect, and save, all from one screen. Hyvä-native and CSP-compliant out of the box, with honeypot, time-trap, per-IP rate limiting, a block log, and configurable fail-open that always keeps login & checkout protected. No separate paid add-ons, no CSS-selector hunting.
Email to a Friend
SKU
CaptchaBotProtection
$199.00
Requirement
  • Magento 2.4.8+ (Community Edition)
  • Hyva 1.4.6+ (License required)
  • Php 8.4+
  • Node 20+
12 Month Support Included
Free Installation Included

Every form on your store is a door for bots — close them all in minutes.

Spam sign-ups, fake reviews, brute-force logins and bot-stuffed newsletters all arrive through your storefront's forms. ModKor Captcha & Bot Protection puts an invisible challenge in front of those forms and adds three more layers of defense behind it — so bots are stopped even when they forge or replay the captcha token.

Pick a provider, paste two keys, tick the forms to protect, and save — everything on one screen with a live preview. No devtools, no CSS-selector hunting, and no separate paid add-on for Hyvä.

One captcha. Four providers. Four layers of defense.

Four providers, one interface

  • Google reCaptcha v3 — invisible, risk-scored with your own threshold
  • Google reCaptcha v2 — classic checkbox or invisible
  • Cloudflare Turnstile — free, privacy-friendly, fully invisible
  • hCaptcha — privacy-first alternative
  • Tested across all four; store keys for each and switch the active provider any time

Hyvä-native & CSP-compliant — included

  • Pure Alpine/vanilla storefront integration (no RequireJS/Knockout)
  • Works on the Hyvä storefront, Hyvä Checkout and Luma Checkout
  • Content-Security-Policy compliant — every provider host whitelisted
  • No separate paid packages, unlike vendors who charge extra for Hyvä, Hyvä Checkout and CSP

Protect any form — no CSS selectors

  • Nine built-in forms: login, create account, forgot/reset password, edit account, newsletter, contact, product review, share wishlist, email a friend
  • Add any custom form by its route — no devtools, no selector hunting
  • data-mk-captcha attribute — drop it on any editable form to protect it instantly
  • Toggle checkout (place-order) protection with one switch

Layered bot defense (defense in depth)

  • Honeypot field — invisible to humans, filled by bots
  • Time-trap — HMAC-signed; blocks impossibly fast submissions
  • Per-IP rate limiting — caps submission floods and credential-stuffing
  • Captcha verification — provider token verified (and scored for v3)

Visibility, safety & control

  • Block log & dashboard — blocked submissions by reason, top forms, top IPs, recent hits
  • Configurable fail-open — keep shoppers moving during a provider outage, while login, password-reset and checkout always stay protected (fail closed)
  • IP allowlist, protect-guests-only, per-provider score threshold (v3)
  • Badge theme, position and language; custom failure message; encrypted secret keys
  • GraphQL config query for headless / PWA storefronts

Compatibility

Magento Open Source / Adobe Commerce 2.4.8+ · PHP 8.4+ · Hyvä Themes 1.4.6+