=== Sergeev Studio Captcha for Elementor Forms with Yandex SmartCaptcha ===
Contributors: sergeevstudio
Tags: captcha, smartcaptcha, smart captcha, elementor forms, anti-spam
Requires at least: 6.5
Tested up to: 7.1
Requires PHP: 7.4
Stable tag: 1.3.3
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Invisible bot and spam protection for Elementor Pro forms using Yandex SmartCaptcha.

== Description ==

Adds an invisible captcha check to Elementor Pro forms using Yandex SmartCaptcha (also written as Yandex Smart Captcha). Visitors are not asked to solve anything unless the service considers the request suspicious. The captcha token is verified on the server before the form is processed, and it is deliberately kept out of the form fields so it never leaks into `[all-fields]`, email, Telegram or webhook notifications.

This is an independent integration. It is not affiliated with, endorsed by or sponsored by Yandex or Elementor. "Yandex SmartCaptcha" and "Elementor" are trademarks of their respective owners and are used here only to describe compatibility. Using the plugin requires a Yandex SmartCaptcha account (free) and Elementor Pro.

**Features**

* Invisible SmartCaptcha field for the Elementor Pro form builder
* Server-side token verification against Yandex
* Settings page with a one-click connection test ("check captcha")
* Detection of optimization plugins (WP Rocket, Clearfy, LiteSpeed Cache, Perfmatters, SG Optimizer) that can break the external captcha script, plus automatic exclusion of the plugin's own scripts from their optimization
* List of forms that actually contain the captcha field
* Strict mode: block submissions when Yandex cannot be reached (off by default so real leads are not lost)
* 30-day counters and a short log of recent blocks (no phone numbers or IP addresses stored)

**Requirements**

* Elementor and Elementor Pro (the form builder is a Pro feature)
* A Yandex SmartCaptcha site key and server key, created for free in Yandex Cloud

== External services ==

This plugin relies on Yandex SmartCaptcha, a third-party service by Yandex, to tell humans and bots apart. It is required for the plugin's only feature to work.

Nothing is sent to Yandex until an administrator has (1) created a Yandex SmartCaptcha key pair in Yandex Cloud and entered both keys on the plugin settings page, and (2) added the "Yandex SmartCaptcha" field to an Elementor form. Until then the plugin makes no external requests.

Once configured, the plugin uses the service as follows:

* On the front-end pages that contain the captcha field, the visitor's browser loads the SmartCaptcha script from `https://smartcaptcha.yandexcloud.net/captcha.js` and the challenge assets it references, and communicates with Yandex directly. Yandex processes the visitor's IP address, browser metadata and behavioural signals to score the request. This happens for every visitor of those pages.
* When such a form is submitted, the site sends the captcha token, the configured server key and the visitor's IP address to `https://smartcaptcha.yandexcloud.net/validate` (server to server) to verify the token.
* When an administrator presses "Check captcha" on the settings page, the site sends one test request with a dummy token to the same `/validate` endpoint.

Service, terms and privacy information:

* SmartCaptcha service: https://yandex.cloud/en/services/smartcaptcha
* Yandex Cloud Terms of Service: https://yandex.com/legal/cloud_termsofuse/
* Yandex Privacy Policy: https://yandex.com/legal/confidential/

== Installation ==

1. Install and activate the plugin (Elementor and Elementor Pro must be active).
2. In Yandex Cloud, open SmartCaptcha and create a captcha. Copy the **Site key** and **Server key**. Add your site's domain to the captcha's allowed domains.
3. Go to **Elementor → SmartCaptcha**, paste both keys and save.
4. Edit a form in the Elementor editor and add a field of type **Yandex SmartCaptcha** to every form you want to protect.
5. On the settings page press **Check captcha** to confirm the connection, and test a form in a private browser window.

== Frequently Asked Questions ==

= The form shows "the check failed" for visitors but works for me =

Optimization plugins often "localize" or delay the external `captcha.js`, which breaks it. Exclude the domain `smartcaptcha.yandexcloud.net` from script localization / delayed JavaScript in your optimization plugin, clear its cache, and test again while logged out. The settings page lists the optimization plugins it detected.

= Does the captcha token appear in form notifications? =

No. It is submitted outside the Elementor form fields, so it is not included in `[all-fields]` or in email / Telegram / webhook notifications.

= What happens if Yandex is unreachable from my server? =

By default the form is still submitted so real visitors are not blocked; such cases are counted on the settings page. Enable **Strict mode** to block instead.

= Do I need to mention this in my privacy policy? =

Yes. Because visitor data (including IP address) is processed by Yandex, you should disclose the use of Yandex SmartCaptcha in your site's privacy policy, as you would for any captcha service.

== Screenshots ==

1. Settings page: keys, connection test, protected forms, 30-day stats and recent blocks.
2. The "Yandex SmartCaptcha" field in the Elementor form editor.

== Changelog ==

= 1.3.3 =
* Fixed: forms inside Elementor Pro popups never received a captcha token and were rejected. The captcha is now set up when the popup opens.

= 1.3.2 =
* Admin health-check script moved to a properly enqueued file.
* Added the "Requires Plugins: elementor" header.
* Prepared for the WordPress.org plugin directory: readme, license, external services disclosure, hardened database query, debug logging gated behind WP_DEBUG.
