• Resolved Anonymous User

    (@anonymized-23393328)


    We recently set up Contact Forms 7 and followed this page to setup reCAPTCHA with a new Google account: reCAPTCHA (v3) | Contact Form 7.
    But now we received an E-Mail from Google “Security alert for your reCAPTCHA key”, saying we aren’t protected, our setup is incomplete and “It’s likely that you have missed the step: verify the reCAPTCHA token, because reCAPTCHA has not received any token verification1 requests from your site backend.”

    The frontend seems to work fine, the form is working, the reCAPTCHA admin console is showing a number of requests and the reCAPTCHA badge is displayed at the bottom right of the page.

    If I understood it correctly, the frontend sends a response token to the application backend after submitting the form. In the application backend this response token is then being sent to reCAPTCHA for verification (reCAPTCHA returns a risk score indicating the likelihood of a legitimate interaction). But this backend part is not working.

    In the Google Cloud Console where the reCAPTCHA keys are managed, it also says “Status: unprotected” and some links redirect to Authenticate to reCAPTCHA  |  Google Cloud or Create assessments for websites  |  reCAPTCHA  |  Google Cloud. I have not read those in detail but I assumed this backend part was also handeled by Contact Forms 7?
    Has this happend to someone before?
    Am I missing something here?

    • This topic was modified 7 months, 1 week ago by Yui. Reason: sitelink add

    The page I need help with: [log in to see the link]

Viewing 9 replies - 1 through 9 (of 9 total)
  • hi I’m not even able to reset the key

    do you see the same if you try to reset it ?

    Plugin Author Takayuki Miyoshi

    (@takayukister)

    Where can we see the website in question?

    Thread Starter Anonymous User

    (@anonymized-23393328)

    My bad, you can see it here:

    (link moved below 1st topic post by moderator)

    To me it looks like the issue is in the backend and the frontend appears to be working fine, so I didn’t think it was necessary

    @curzonpr what do you mean by resetting the key? I tried removing the key from the plugin and added it again, in case the secret key was somehow incorrect before but that didn’t resolve the issue.

    • This reply was modified 7 months, 1 week ago by Anonymous User.
    • This reply was modified 7 months, 1 week ago by Anonymous User.
    • This reply was modified 7 months, 1 week ago by Yui. Reason: link removed
    Plugin Author Takayuki Miyoshi

    (@takayukister)

    What other plugins and theme do you use on the site?

    Thread Starter Anonymous User

    (@anonymized-23393328)

    Other used plugins are: “Complianz | GDPR/CCPA Cookie Consent” and “Akismet Anti-spam: Spam Protection”

    The theme is “Twenty Twenty-Four”

    Plugin Author Takayuki Miyoshi

    (@takayukister)

    Do you get any response message after you submit the form?

    Thread Starter Anonymous User

    (@anonymized-23393328)

    Yes I get the expected response message after submitting the form.
    The validation error is working fine.
    The “OK” response message is also working and an email is successfully sent to the email that I configured.

    Plugin Author Takayuki Miyoshi

    (@takayukister)

    That indicates that reCAPTCHA is working as expected. You can confirm this with Flamingo.

    Thread Starter Anonymous User

    (@anonymized-23393328)

    Have any changes been made?
    I did not change anything but now I am not getting any more warnings in the google cloud console and in the reCAPTCHA admin console. It seems to be working fine.

Viewing 9 replies - 1 through 9 (of 9 total)

The topic ‘reCAPTCHA key security alert’ is closed to new replies.