IN PROGRESS
Technical summary
NEXUS plugin that protects login and registration forms against brute force and spam with 100% self-hosted math challenges: each visit generates an addition or multiplication operation signed by HMAC-SHA256 in a base64 token with expiration and nonce-based anti-replay, verified in 4 steps before authentication. No GD, no external APIs and no third-party keys — with per-IP attempt auditing and a statistics dashboard in the Security tab.
Executed scope
plugin.json: v1.0.0, slugnexus-captcha-simple,is_core: true, "security" category (Security tab,shield-checkicon).- Self-hosted math captcha — no GD/Imagick (pure PHP 8.3) and no external services, unlike the
google-recaptcha/hcaptchasiblings: no third-party API keys required. captcha_simple_generate_challenge— picks a+or×operation based on config (operations):(2–20) + (1–20)or(2–9) × (2–9); generates arandom_bytes(16)nonce,exp = time() + ttl*60and returnsprompt,token,nonceand the expiration time.- Signed self-contained token —
a|op|b|answer|nonce|exppayload signed withhash_hmac('sha256', …)using the session secret (csrf_token, withDB_PASSfallback); token =base64(payload|sig)— the expected value is never exposed without verification. - 4-step verification (
captcha_simple_verify_answer) — (1)hash_equalssignature (anti-tamper); (2) expiration (time() > exp); (3) anti-replay: unique nonce stored in$_SESSION['captcha_used_nonces'], reuse rejected; (4) numeric answer comparison (string). - 4 hooks —
before_loginandbefore_register(priority 5) invalidate$data['valid']with a Portuguese error message when the challenge fails;login_form_after_fieldsandregister_form_after_fieldsinject the widget into the form. - Server-side widget — visible prompt,
captcha-simple-token(hidden),captcha-simple-answer(required numeric input) and a "Trocar" button that reloads the challenge via JS (nxRefreshCaptchaSimple→fetch('api.php?action=captcha_simple_challenge')). - Per-IP auditing —
nx_captcha_simple_logstable (workspace_id,action_type,success,user_ipVARCHAR(45) with IPv4/IPv6 support,created_at,INDEX idx_ws_time), created withCREATE TABLE IF NOT EXISTSon first verification — noinstall.sql; every attempt (success or blocked) is logged. - Settings —
settings_get_all()['security']['captcha_simple']with defaults (enabled,enable_login,enable_register,operations'add'|'all',ttl_minutes1–30, default 5) and save-time validation (ttl_minutesclamped, operations whitelisted). - Stats —
captcha_simple_get_stats:total,success,blocked,success_rate+ the last 20 workspace logs. - API: 5 actions (
captcha_simple_challenge,captcha_simple_verify,captcha_simple_settings_get,captcha_simple_settings_save,captcha_simple_stats_get). - Alpine.js UI (
tab.php, 388 lines) — emerald theme (emerald-600), Self-Hosted badge, Security tab; 3 sub-tabs: Test Challenge (simulator exposing the HMAC token in a mono block, expiration and realtime validation with feedback), History & Logs (4 KPI cards — Total, Successes, Blocked, Success Rate — and a table with Date/Time, Action, IP and a Success/Blocked badge), Settings (global/login/register toggles, operations and TTL with a save button). - Fastr:
/captcha→captcha_simple_challenge. - No i18n (Portuguese texts in
tab.php), no cron (nocronjob.json— on-demand) and no external dependencies (zero network calls in the protection flow).
Stack and tools
- PHP 8 (no framework, zero GD/Imagick)
- MySQL 8 (
nx_captcha_simple_logstable created on demand) - Alpine.js + Tailwind CSS (premium light, emerald)
- HMAC-SHA256 (
hash_hmac+hash_equals) with anti-replay nonce - NEXUS plugin system (PluginManager: tabs, filters, API actions, Fastr)
Operational tags
- Captcha
- HMAC
- Anti-Spam
- Anti-Brute Force
- Security
- Login
- Registro
- Plugin NEXUS
Operational result
- Local auth protection: login and registration require a math challenge before validation — no external API cost.
- Anti-tamper + anti-replay + expiration: HMAC-SHA256 signed token, single-use nonce and configurable TTL (1–30 min).
- Privacy and portability: zero network/third-party dependencies; runs on any pure PHP 8 server, even without image extensions.
- Anti-abuse visibility: full per-IP auditing with KPIs (total, successes, blocked, rate) and the last 20 events.
- Fine control: per-flow toggles (login/register), allowed operations and challenge validity.
/captchachat command to generate/validate challenges manually.
GitHub progress (issues)
Real-time panel with latest repository issues.
live feed
open issues on GitHubcarregando andamento...
não foi possivel carregar as issues agora. abra no github pelo link acima.
Real results
Lightweight, self-hosted anti-bot challenge mechanism protecting forms from automated abuse. Generates server-side timed mathematical challenges, securing web interactions without relying on external third-party captcha providers.
Architecture and organization
- PHP 8
- MySQL 8
- Alpine.js
- Tailwind CSS
- HMAC-SHA256
- Plugin NEXUS
Execution and operations
The project follows reproducible execution flow with technical validation in production-like environments.
Screenshots
Talk about this project
Apply this implementation pattern in your environment and accelerate delivery with technical consistency.