Title: useHUMA — Invisible Bot Protection (No CAPTCHA)
Author: usehuma
Published: <strong>2026년 8월 19일</strong>
Last modified: 2026년 8월 21일

---

플러그인 검색

![](https://ps.w.org/usehuma/assets/banner-772x250.png?rev=3655426)

![](https://ps.w.org/usehuma/assets/icon-256x256.png?rev=3655426)

# useHUMA — Invisible Bot Protection (No CAPTCHA)

 작성자: [usehuma](https://profiles.wordpress.org/usehuma/)

[다운로드](https://downloads.wordpress.org/plugin/usehuma.1.0.2.zip)

 * [세부사항](https://ko.wordpress.org/plugins/usehuma/#description)
 * [평가](https://ko.wordpress.org/plugins/usehuma/#reviews)
 *  [설치](https://ko.wordpress.org/plugins/usehuma/#installation)
 * [개발](https://ko.wordpress.org/plugins/usehuma/#developers)

 [지원](https://wordpress.org/support/plugin/usehuma/)

## 설명

CAPTCHAs interrupt every visitor to catch a few bots — and modern bots solve them
anyway. useHUMA takes the opposite approach: it observes _how_ a visitor behaves(
mouse rhythm, typing cadence, scroll patterns, touch physics) and scores the probability
that a real human is present. Real visitors feel nothing. Bots get blocked.

**What it protects:**

 * **Comments** — spam comments are rejected before they reach your moderation queue
 * **User registration** — fake account signups are stopped at the door
 * **Contact Form 7** — form spam is invalidated on submission (if CF7 is installed)

**Why site owners choose it:**

 * **Invisible** — no checkbox, no image puzzles, no friction for real visitors
 * **Privacy-first** — zero PII: no keystroke contents, no names, no fingerprinting
   databases; only statistical aggregates of interaction patterns
 * **Fail-open by design** — if the verification service is ever unreachable, your
   forms keep working
 * **Tells you when it was an AI agent** — not just bot or human. Playwright, Puppeteer,
   browser extensions and computer-use agents come back with their own verdict, 
   on every plan including the free one
 * **One setting** — paste your API key and you’re protected

You’ll need an API key from [humaverify.com](https://humaverify.com/signup?utm_source=wordpress).
It is free and it stays free: every account starts with 14 days of the Starter plan
and then settles on the Free plan, 1,000 verifications a month, for ever, no credit
card. Most small sites never need more than that.

### External services

This plugin connects to the useHUMA API (https://humaverify.com) to score form submissions.
On each protected submission, the plugin sends: anonymous behavioral statistics 
collected on the page (timing variance of mouse/keyboard/scroll/touch interactions—
never the contents of what was typed) and a pseudonymous identifier. When the form
provides an email address it is hashed on your server first, with a salt generated
once and stored only in your own WordPress database, so the address itself never
leaves your site and the hash cannot be reversed or matched against any other site.
No other personal data is transmitted.

This service is provided by useHUMA: [terms of service](https://humaverify.com/terms),
[privacy policy](https://humaverify.com/privacy).

## 스크린샷

[⌊The whole configuration: one API key, a threshold, and what to protect. The key
is free at humaverify.com.⌉⌊The whole configuration: one API key, a threshold, and
what to protect. The key is free at humaverify.com.⌉[

The whole configuration: one API key, a threshold, and what to protect. The key 
is free at humaverify.com.

[⌊What your visitors see on a protected form: the form. No puzzle, no checkbox, 
no badge.⌉⌊What your visitors see on a protected form: the form. No puzzle, no checkbox,
no badge.⌉[

What your visitors see on a protected form: the form. No puzzle, no checkbox, no
badge.

## 설치

 1. Install and activate the plugin.
 2. Get a free API key at [humaverify.com/signup](https://humaverify.com/signup?utm_source=wordpress).
    No credit card.
 3. Go to **Settings  useHUMA**, paste your API key, and choose what to protect.
 4. Done — protection is invisible from this point on.

## FAQ

### Will my visitors see a CAPTCHA or checkbox?

No. Verification is completely invisible. Visitors just use your site normally; 
the behavioral score happens in the background.

### What data is collected?

Only statistical aggregates of interaction timing (e.g. “how much did typing rhythm
vary”), never the contents of what a visitor types, and never biometric identifiers.
See the External services section for the full list.

### What happens if the useHUMA API is down?

The plugin fails open: submissions are allowed through. An outage will never lock
real users out of your forms.

### What is strict mode?

By default, submissions without behavioral signals (e.g. from visitors with JavaScript
disabled) are allowed. Strict mode rejects them — which blocks direct-POST bots 
completely, at the cost of also blocking no-JavaScript visitors.

### Is it really free, or is it a trial that ends?

Both. Every account gets 14 days on the Starter plan, then settles on the Free plan
and stays there: 1,000 verifications a month, no expiry, no card, with the AI-agent
verdict included. A thousand a month is enough for most personal and small business
sites. If your forms see more than that, the paid plans start at $49 a month, and
the same API key keeps working.

### Does it work with caching plugins?

Yes. The collector runs client-side after page load, so full-page caching doesn’t
affect it.

## 후기

이 플러그인에 대한 평가가 없습니다.

## 기여자 & 개발자

“useHUMA — Invisible Bot Protection (No CAPTCHA)”(은)는 오픈 소스 소프트웨어입니다.
다음의 사람들이 이 플러그인에 기여하였습니다.

기여자

 *   [ usehuma ](https://profiles.wordpress.org/usehuma/)

[자국어로 “useHUMA — Invisible Bot Protection (No CAPTCHA)”(을)를 번역하세요.](https://translate.wordpress.org/projects/wp-plugins/usehuma)

### 개발에 관심이 있으십니까?

[코드 탐색하기](https://plugins.trac.wordpress.org/browser/usehuma/)는, [SVN 저장소](https://plugins.svn.wordpress.org/usehuma/)
를 확인하시거나, [개발 기록](https://plugins.trac.wordpress.org/log/usehuma/)을 
[RSS](https://plugins.trac.wordpress.org/log/usehuma/?limit=100&mode=stop_on_copy&format=rss)
로 구독하세요.

## 변경이력

#### 1.0.2

 * Email addresses are now hashed on your own server before anything is sent. The
   address itself never leaves your site, and the readme no longer claims zero PII
   while transmitting one.

#### 1.0.1

 * The bundled collector now reports automation tells, and the plugin forwards them
   instead of dropping them. Without this a headless browser that moved the cursor
   a little was scored as a real visitor.

#### 1.0.0

 * Initial release: comment, registration and Contact Form 7 protection, settings
   page, bundled behavioral collector.

## 기초

 *  버전 **1.0.2**
 *  최근 업데이트: **1개월 전**
 *  활성화된 설치 **10보다 적음**
 *  워드프레스 버전 ** 5.8 또는 그 이상 **
 *  다음까지 시험됨: **7.0.5**
 *  PHP 버전 ** 7.4 또는 그 이상 **
 *  언어
 * [English (US)](https://wordpress.org/plugins/usehuma/)
 * 태그:
 * [anti-spam](https://ko.wordpress.org/plugins/tags/anti-spam/)[bot protection](https://ko.wordpress.org/plugins/tags/bot-protection/)
   [captcha alternative](https://ko.wordpress.org/plugins/tags/captcha-alternative/)
   [comments](https://ko.wordpress.org/plugins/tags/comments/)[spam](https://ko.wordpress.org/plugins/tags/spam/)
 *  [고급 보기](https://ko.wordpress.org/plugins/usehuma/advanced/)

## 평점

아직 제출된 리뷰가 없습니다.

[Your review](https://wordpress.org/support/plugin/usehuma/reviews/#new-post)

[모든  리뷰 보기](https://wordpress.org/support/plugin/usehuma/reviews/)

## 기여자

 *   [ usehuma ](https://profiles.wordpress.org/usehuma/)

## 지원

할 말 있으신가요? 도움이 필요하신가요?

 [지원 포럼 보기](https://wordpress.org/support/plugin/usehuma/)