Cover image for project: NEXUS Captcha Simples IN PROGRESS

Technical summary

NEXUS plugin that protects login and registration forms against brute force and spam with 100% self-hosted math challenges: each visit generates an addition or multiplication operation signed by HMAC-SHA256 in a base64 token with expiration and nonce-based anti-replay, verified in 4 steps before authentication. No GD, no external APIs and no third-party keys — with per-IP attempt auditing and a statistics dashboard in the Security tab.

Executed scope

  • plugin.json: v1.0.0, slug nexus-captcha-simple, is_core: true, "security" category (Security tab, shield-check icon).
  • Self-hosted math captcha — no GD/Imagick (pure PHP 8.3) and no external services, unlike the google-recaptcha/hcaptcha siblings: no third-party API keys required.
  • captcha_simple_generate_challenge — picks a + or × operation based on config (operations): (2–20) + (1–20) or (2–9) × (2–9); generates a random_bytes(16) nonce, exp = time() + ttl*60 and returns prompt, token, nonce and the expiration time.
  • Signed self-contained token — a|op|b|answer|nonce|exp payload signed with hash_hmac('sha256', …) using the session secret (csrf_token, with DB_PASS fallback); token = base64(payload|sig) — the expected value is never exposed without verification.
  • 4-step verification (captcha_simple_verify_answer) — (1) hash_equals signature (anti-tamper); (2) expiration (time() > exp); (3) anti-replay: unique nonce stored in $_SESSION['captcha_used_nonces'], reuse rejected; (4) numeric answer comparison (string).
  • 4 hooks — before_login and before_register (priority 5) invalidate $data['valid'] with a Portuguese error message when the challenge fails; login_form_after_fields and register_form_after_fields inject the widget into the form.
  • Server-side widget — visible prompt, captcha-simple-token (hidden), captcha-simple-answer (required numeric input) and a "Trocar" button that reloads the challenge via JS (nxRefreshCaptchaSimple → fetch('api.php?action=captcha_simple_challenge')).
  • Per-IP auditing — nx_captcha_simple_logs table (workspace_id, action_type, success, user_ip VARCHAR(45) with IPv4/IPv6 support, created_at, INDEX idx_ws_time), created with CREATE TABLE IF NOT EXISTS on first verification — no install.sql; every attempt (success or blocked) is logged.
  • Settings — settings_get_all()['security']['captcha_simple'] with defaults (enabled, enable_login, enable_register, operations 'add'|'all', ttl_minutes 1–30, default 5) and save-time validation (ttl_minutes clamped, operations whitelisted).
  • Stats — captcha_simple_get_stats: total, success, blocked, success_rate + the last 20 workspace logs.
  • API: 5 actions (captcha_simple_challenge, captcha_simple_verify, captcha_simple_settings_get, captcha_simple_settings_save, captcha_simple_stats_get).
  • Alpine.js UI (tab.php, 388 lines) — emerald theme (emerald-600), Self-Hosted badge, Security tab; 3 sub-tabs: Test Challenge (simulator exposing the HMAC token in a mono block, expiration and realtime validation with feedback), History & Logs (4 KPI cards — Total, Successes, Blocked, Success Rate — and a table with Date/Time, Action, IP and a Success/Blocked badge), Settings (global/login/register toggles, operations and TTL with a save button).
  • Fastr: /captcha → captcha_simple_challenge.
  • No i18n (Portuguese texts in tab.php), no cron (no cronjob.json — on-demand) and no external dependencies (zero network calls in the protection flow).

Stack and tools

  • PHP 8 (no framework, zero GD/Imagick)
  • MySQL 8 (nx_captcha_simple_logs table created on demand)
  • Alpine.js + Tailwind CSS (premium light, emerald)
  • HMAC-SHA256 (hash_hmac + hash_equals) with anti-replay nonce
  • NEXUS plugin system (PluginManager: tabs, filters, API actions, Fastr)

Operational tags

  • Captcha
  • HMAC
  • Anti-Spam
  • Anti-Brute Force
  • Security
  • Login
  • Registro
  • Plugin NEXUS

Operational result

  • Local auth protection: login and registration require a math challenge before validation — no external API cost.
  • Anti-tamper + anti-replay + expiration: HMAC-SHA256 signed token, single-use nonce and configurable TTL (1–30 min).
  • Privacy and portability: zero network/third-party dependencies; runs on any pure PHP 8 server, even without image extensions.
  • Anti-abuse visibility: full per-IP auditing with KPIs (total, successes, blocked, rate) and the last 20 events.
  • Fine control: per-flow toggles (login/register), allowed operations and challenge validity.
  • /captcha chat command to generate/validate challenges manually.

GitHub progress (issues)

Real-time panel with latest repository issues.

abertas (amostra): -- fechadas (amostra): -- base: -- ultimas issues

carregando andamento...

Real results

Lightweight, self-hosted anti-bot challenge mechanism protecting forms from automated abuse. Generates server-side timed mathematical challenges, securing web interactions without relying on external third-party captcha providers.

Architecture and organization

Execution and operations

The project follows reproducible execution flow with technical validation in production-like environments.

Screenshots

Talk about this project

Apply this implementation pattern in your environment and accelerate delivery with technical consistency.