hCaptcha is an anti-bot solution that protects user privacy and rewards websites.

Detection looks at response headers, script sources, javascript globals, dom selectors, stylesheets across 7 fingerprint rules among the site's public responses.

01

Websites using hCaptcha

Loading website list…

02

Signal classes

PluginView evaluates public page signals in these classes when identifying hCaptcha. Individual fingerprint rule bodies are proprietary and are not published.

  • Response headers
  • Script sources
  • JavaScript globals
  • DOM selectors
  • Stylesheets
03

Example public indicators for hCaptcha

Illustrative indicators derived from public catalog metadata for hCaptcha. A live scan may match additional proprietary rules beyond these examples.

  • content-security-policy: .//hcaptcha.com
  • hcaptcha.com/?/api.js
  • hcaptcha.getRespKey
  • hcaptchaOnLoad
  • hcaptcha_sitekey
  • link
  • #cf-hcaptcha-container
04

What a detection means

Establishes
The listed vendor-controlled browser component was present and active on the scanned page at scan time.
Does not establish
It does not prove a sitewide installation, current commercial contract, backend-only use, exclusive use, or production transaction volume.
05

Minimum proof rule

Observe a live browser request, loaded script, or iframe to the listed unique vendor endpoint. Source-text-only matches do not qualify.

Best pages to check: Forms, signup, checkout

06

How to check a site for hCaptcha

  1. 1. Enter the website URL in the scan form — homepage, pricing, checkout, or login pages usually expose the strongest hCaptcha signals (prefer: Forms, signup, checkout).
  2. 2. PluginView reads only public responses (response headers, script sources, javascript globals) and scores them against the hCaptcha signature set (7 rules).
  3. 3. Review the confidence score and text explanation for hCaptcha on the results page.
07

FAQ: detecting hCaptcha

Can PluginView detect hCaptcha without logging in?
Yes. PluginView only reads publicly accessible responses when checking for hCaptcha — typically response headers, script sources, javascript globals, dom selectors. It does not bypass authentication or paywalls.
What category is hCaptcha?
hCaptcha is classified under Security, Consent, CAPTCHA & Accessibility in the PluginView directory.
How many fingerprint rules cover hCaptcha?
This reference currently tracks 7 fingerprint rules across response headers, script sources, javascript globals, dom selectors, stylesheets. Individual rule bodies are proprietary and are not published.
What public signals suggest a site uses hCaptcha?
Illustrative public indicators for hCaptcha include content-security-policy: .//hcaptcha.com; hcaptcha.com/?/api.js; hcaptcha.getRespKey. A live scan may match additional proprietary rules beyond these examples.
Which pages are best for detecting hCaptcha?
For hCaptcha, start with: Forms, signup, checkout.

More in Security

View category →