RepairPlugin
Site & brandingIncluded on every plan

Block spam,
not customers.

Two layers of invisible security, CSRF protection and Google reCAPTCHA v3, keep bots out without adding friction for real customers.

2
security layers
0
customer friction
v3
reCAPTCHA version
CSRF protection
ON
reCAPTCHA v3
SCORE 0.9
Bots blocked
28 today
0 puzzles · 0 checkboxesreal customers pass through
Why repair shops choose it

Bot defence that customers never see.

CSRF tokens block forged submissions. reCAPTCHA v3 silently scores every visitor. Real bookings flow through; bots get blocked.

Two layers
1
CSRF token
per session
2
reCAPTCHA v3
invisible scoring
2layers

Double protection, zero hassle

CSRF protection verifies every form submission comes from a real visitor on your site. Google reCAPTCHA v3 runs invisibly in the background to detect bots. Neither requires customers to solve puzzles or check boxes.

Invisible to customers
Checkbox
Image puzzle
Audio captcha
Background score
0puzzles

Invisible bot detection

Google reCAPTCHA v3 works silently, no checkboxes, no image puzzles, no interruptions. Suspected bots are blocked from submitting forms while real customers proceed without knowing it's there.

Hide reCAPTCHA badge
Hide badge
Mention reCAPTCHA in your privacy policy.
1toggle

Hide the reCAPTCHA badge

Prefer a cleaner look? Turn on 'Hide reCAPTCHA Badge' to remove the floating Google badge from your website. Just remember to mention reCAPTCHA in your privacy policy as required by Google's Terms of Service.

Session token
_csrf
a8f3e9c1b2d4f6a8e0c2b4d6f8a0c2e4
ON by default
1token per session

CSRF protection on by default

A unique security token is created for each visitor session and verified with every form submission. Forged submissions from external sources are silently blocked. This is turned on by default and should stay on for all live websites.

How it works

Three steps. Spam-proof booking.

CSRF is on out of the box. Add reCAPTCHA keys when you're ready, and you're done.

Step 1 · CSRF
Already onno setup
1

CSRF is already on

CSRF protection is enabled by default. It creates a unique security token per visitor session and checks every form submission. No setup needed.

Step 2 · keys
Site Key
6Lc4...XYZ
Secret
6Le9...ABC
2

Get your reCAPTCHA keys

Register your site at the Google reCAPTCHA admin console. Choose reCAPTCHA v3, add your domain, and copy the Site Key and Secret Key.

Step 3 · enable
Enable Protection
Spam blocking live
3

Enter keys and enable

Go to Front-End Steps > Security & Integration, click Google reCAPTCHA, paste your keys, and turn on Enable Protection. Spam blocking starts immediately.

Plan availability

Included on every plan.

Spam protection is core storefront functionality, available from Essentials onwards.

EssentialsIncluded

Included

GrowthIncluded

Included

ScaleIncluded

Included

FAQ

Common questions.

Can I use reCAPTCHA v2 (the checkbox or image puzzle)?

No. RepairPlugin uses Google reCAPTCHA v3 exclusively. Keys from v2 won't work, make sure you select v3 when registering your site with Google.

Do I need to clear my cache after turning on security features?

No. Changes take effect immediately after saving. No page reload or cache clear is needed on the admin side.

Is CSRF protection on by default?

Yes. CSRF protection is turned on by default and should stay on for all live websites. Only turn it off for debugging purposes.

What forms are protected?

Both features cover booking forms, offer request forms, and other RepairPlugin submission points.

Turn visitors into customers.

Join 583+ repair shops already fixing their massive drop-offs.
Easy to install and live on your WordPress site in minutes.