ALTCHA
WP-ImmoMakler supports the privacy-friendly spam protection ALTCHA. It is loaded entirely from your own WordPress server, without any connection to third-party services and without cookies.
How it works
Section titled “How it works”ALTCHA gives your visitor’s browser an automated computational task (a so-called proof of work). The browser solves it in the background as soon as the page has loaded, while your visitor fills in the form. All that is visible is a small field confirming that the check succeeded:
Your visitors therefore never have to solve a puzzle or click anything. For a spam bot submitting forms en masse, however, the computational effort adds up to a real obstacle.
The server then checks whether the submitted solution belongs to a task it issued itself. Each task is valid only once and only for a limited time.
ALTCHA is enabled by default – there is nothing for you to set up. You’ll find the selection in your website’s backend (wp-admin) under WP-ImmoMakler → Settings → Spam Protection → Level 2: CAPTCHA Providers, in case you’d like to choose a different provider or “No CAPTCHA (Level 1 only)” instead. No further settings and no external account are required – unlike the externally hosted CAPTCHAs, which all require a sitekey and secret key.
The setting applies to all of the plugin’s forms:
- the contact form in the property detail view
- the property alert form
- the withdrawal form
- the Propstack search profile form and the Propstack newsletter sign-up
Data protection
Section titled “Data protection”- The computational task is generated and verified by your own server. There is no connection to third-party servers.
- No cookies are set.
- No behavioural data about your visitors (mouse movements, keystrokes) is collected.
- The only thing transmitted is the solution to the computational task — a random numeric value along with a checksum.
The “Protected by ALTCHA” note inside the field is a plain text link to altcha.org. It does not load any content from there.
Technical details
Section titled “Technical details”REST API endpoint
Section titled “REST API endpoint”The browser fetches the computational task through a WordPress REST API endpoint:
GET /wp-json/immomakler/v1/altcha/challengeThe response is deliberately not cacheable (Cache-Control: no-store), because each task is valid only once.
Algorithm and defaults
Section titled “Algorithm and defaults”WP-ImmoMakler picks the algorithm based on what your server supports:
- Argon2id, if the PHP
sodiumextension is loaded – the case on almost every host. Argon2id is memory-hard: each computation step occupies 64 MB of memory. That’s negligible for your visitor’s browser, but it stops a spam bot from offloading the work to graphics cards, which would otherwise solve thousands of tasks in parallel. - PBKDF2/SHA-256 otherwise. It needs no extension and no notable amount of memory, but can be computed significantly faster on graphics cards than in a browser.
Both defaults match ALTCHA’s own recommendation for the respective algorithm:
| Parameter | Argon2id | PBKDF2/SHA-256 | Description |
|---|---|---|---|
algorithm | ARGON2ID | PBKDF2/SHA-256 | Algorithm used for the task |
Iterations (cost) | 1 | 5,000 | Effort per computation step |
Memory (memory_cost) | 65,536 KiB (64 MB) | – | Memory per computation step |
Steps (counter) | 100–200 | 5,000–10,000 | Number of steps until the solution is found |
| Validity | 30 minutes | 30 minutes | The task expires afterwards |
| Reuse | not possible | not possible | Each solved task is good for exactly one submission |
On a desktop machine, the task is solved with either algorithm in roughly two to three seconds, on a mid-range smartphone in about ten seconds. Since the computation starts as the page loads, it is finished in practice before the form has been filled in. A bot has to solve the same task anew for every single submission and therefore pays the same computing time per submission.
The Argon2id engine is loaded as a separate file from the plugin directory (vendors/altcha/workers/argon2id.js). If memory is tight on your server so that Argon2id can’t be computed there, WP-ImmoMakler automatically issues the affected task with PBKDF2 instead and notes this in the log.
Adjusting the difficulty
Section titled “Adjusting the difficulty”If you still receive spam with ALTCHA enabled, you can increase the computational effort through a filter. The filter receives the defaults for the algorithm your server uses; the following example doubles the effort for either one. Note that this also increases the waiting time on weak devices.
add_filter( 'immomakler_altcha_challenge_options', function ( $options ) { $options['counter_min'] *= 2; $options['counter_max'] *= 2; return $options;} );Raise the steps (counter) rather than the iterations (cost) or the memory (memory_cost): the effort for the browser is the product of the values either way, but the iterations and memory additionally determine how long your server takes to issue and verify each task.
The same filter also lets you set the algorithm. This is necessary if the Argon2id engine can’t be loaded in your setup – for example because an optimisation plugin or a CDN serves the plugin directory’s files from a different domain:
add_filter( 'immomakler_altcha_challenge_options', function ( $options ) { $options['algorithm'] = 'PBKDF2/SHA-256'; return $options;} );If the filter names an algorithm your server doesn’t support, the filter is ignored entirely – its steps would be many times too weak or too slow for the other algorithm.
Form filter
Section titled “Form filter”The spam protection hooks into the contact form validation through the following filter:
// Add your own validation logicadd_filter( 'immomakler_contact_form_errors_in_send', function( $errors ) { // $errors['my_error'] = true; return $errors;} );The error message shown when the check fails can be customised:
add_filter( 'immomakler_contactform_altcha_validationfailed', function ( $html ) { return '<div class="alert alert-danger" role="alert">Please try again.</div>';} );