Module configuration in OXID Admin:
Extensions > Modules > ALTCHA Spam Protection > Settings
| Setting | Default | Description |
|---|---|---|
| Enable Module | On | Master switch for all protection features |
| Setting | Default | Description |
|---|---|---|
| Enable ALTCHA | On | Shows "I'm not a robot" checkbox that auto-verifies |
| Max Number (Difficulty) | 50000 | Higher = harder challenge, more CPU time required |
| Expiry Seconds | 300 | How long a challenge is valid (5 minutes default) |
| HMAC Secret | (auto) | Auto-generated if empty. Secret key for signing challenges |
About Challenge Difficulty:
| Setting | Default | Description |
|---|---|---|
| Enable Honeypot | On | Adds invisible trap field that catches bots |
| Field Name | website | Name of the honeypot input field |
The honeypot is a hidden form field that legitimate users never see or fill out. Bots that automatically fill all form fields will trigger this trap.
| Setting | Default | Description |
|---|---|---|
| Enable Content Validation | On | Checks form contents for gibberish patterns and blocks disposable email addresses |
Content validation works entirely server-side and requires no additional frontend changes. It is enabled by default and protects all forms automatically.
| Setting | Default | Description |
|---|---|---|
| Enable Rate Limiting | On | Limits form submissions per IP address |
| Max Requests | 5 | Maximum submissions per time window |
| Window Minutes | 60 | Rate limit window (1 hour default) |
Note: IP addresses are stored as SHA-256 hashes with HMAC in the database for GDPR compliance. The original IP cannot be reconstructed from the hash.
| Setting | Default | Description |
|---|---|---|
| Enable Challenge Rate Limit | On | Protects challenge endpoint from DoS attacks |
| Max Challenges | 30 | Maximum challenges per IP per window |
| Window Minutes | 60 | Rate limit window for challenges |
Content validation is a multi-layered detection system that analyzes form contents for spam patterns. It consists of two main components: Gibberish Detection and Disposable Email Detection.
Gibberish detection analyzes text input in the following form fields:
Six different analysis methods are combined:
| Method | Description | Threshold |
|---|---|---|
| Consonant Ratio | Too many consonants indicate random input | > 75% (> 90% for words up to 7 chars) |
| Keyboard Sequences | Detects keyboard mashing like "asdfgh", "qwerty", "zxcvbn" | 4-6 character sequences |
| Repeating Characters | Identical characters in sequence (e.g. "aaaa") | 3+ identical characters |
| Consecutive Consonants | Unnaturally many consonants without a vowel | 6+ consonants in a row |
| Consonant Clusters | Multiple groups of dense consonants in a word | 2+ clusters of 4+ consonants each |
| Bigram Frequency Analysis | Checks whether letter pairs occur in natural languages | Min. 30% known bigrams (164 reference pairs) |
The detection uses a 2-field threshold: At least 2 form fields must be flagged as suspicious before an input is marked as spam. This minimizes false positives for unusual but legitimate names.
German names with high consonant density (Schmidt, Schwartz, Fritz) as well as international names (Polish, Turkish, French) are correctly recognized as legitimate. The analysis treats umlauts (ae, oe, ue) as vowels and includes 164 common bigrams from multiple languages.
Blocks registrations and contact requests using disposable email addresses. The integrated blocklist covers 63 known providers, including:
The blocklist is maintained statically within the module and extended with updates. Custom domains cannot currently be added via the admin panel.