Symptom: a protected form rejects every submission.
Check: does the form's template actually render the widget (mmd_altcha_widget() or the matching mmd_altcha.widget* hook)? A ticked target with no visible widget fails every submission, because no proof is ever sent.
Solution: add the Twig call or hook to the form's current template - see Storefront Integration.
Symptom: every protected form started rejecting submissions after an APP_SECRET rotation.
Check: channel settings -> was "Generate a new secret" ticked and saved for every affected channel?
Solution: open each channel's settings, tick "Generate a new secret", save. This is expected and intentional - the plugin fails closed on a secret mismatch rather than silently accepting unverifiable proofs.
Symptom: doctrine:migrations:migrate aborts at this plugin's first migration.
Check: is the application database MySQL/MariaDB? The migrations are MySQL DDL.
Solution: there is no fix on PostgreSQL - this plugin cannot be installed on it. On MySQL/MariaDB, run mmd:altcha:setup instead, which gives a clearer message when Sylius' own migrations are still outstanding.
Symptom: legitimate customers occasionally get rejected with reason gibberish or disposable_email.
Check: the ALTCHA gibberish log for the actual score and reasons, or confirm the customer's e-mail domain against the ALTCHA blocked domains list.
Solution: for gibberish, raise the reject score (start at 100 and lower gradually, see Practical Examples); for e-mail, add an Allow override for that domain.
Symptom: the widget disappears after a composer update.
Check: did altcha-org/altcha get updated past ~2.1.0? The widget script and the PHP verification library speak one protocol version.
Solution: pin altcha-org/altcha to the version this plugin requires; do not let Composer float it independently.
data-live-ignore and the plugin does not check the component's default re-render requests, but the widget surviving a re-render in a real browser has not been verified against every theme.altcha 3.2.4 (MIT); only a German translation ships in addition to the built-in English.General
Does this plugin send any data to a third party? No. Every check - proof-of-work verification, rate limiting, honeypot, disposable-mail and gibberish checks - runs entirely on your own server.
Does ALTCHA show a visible challenge to visitors? No, by default it solves silently in the background. There is no click-a-tile or distorted-text step.
Configuration
Can I protect forms in one channel but not another? Yes - every setting, including which forms are protected, is scoped to a single channel.
What happens if I enable a form target but forget to place the widget? Every submission of that form is rejected, because no proof is ever sent.
Compatibility
Does this work with the Shop API, not just the storefront? Yes - that is the point of the dual mode, see Shop API / Headless.
Can I use this on PostgreSQL? No, see the requirements on the overview page - the migrations are MySQL DDL.