ARTICLE

Google reCAPTCHA on Hyva Magento Forms: Which Forms to Protect, Invisible vs Checkbox, and the Performance Cost

Google reCAPTCHA on Hyva Magento Forms: Which Forms to Protect, Invisible vs Checkbox, and the Performance Cost

On a Hyva storefront, Google reCAPTCHA is configured with Magento’s native settings and supports v3 Invisible, v2 Invisible, and v2 checkbox. Hyva’s default theme loads Google’s script only when a shopper starts typing in a form, so invisible types add almost nothing to page load. The checkbox loads early and costs more.

That makes the choice of type a performance decision as well as a security one. This guide covers which forms Adobe lets you protect and which ones are worth it, how Hyva loads reCAPTCHA, how to tune the v3 score threshold, how to add reCAPTCHA to custom forms, and the checkout problems to test before launch.

What Magento offers out of the box

Adobe Commerce and Magento Open Source include Google reCAPTCHA modules. Adobe’s Google reCAPTCHA configuration guide lists three types:

  • reCAPTCHA v3 Invisible, which scores each request in the background with no challenge for the shopper.
  • reCAPTCHA v2 Invisible, which runs on submit and only shows a challenge when Google is unsure.
  • reCAPTCHA v2 (“I am not a robot”), the checkbox, which always asks the shopper to click and sometimes to solve an image challenge.

Storefront settings are under Stores, Settings, Configuration, Security, Google reCAPTCHA Storefront. You add keys for each type you use and then choose a type per form. Adobe notes several requirements that cause most setup failures:

  • Each type needs its own key pair. Keys created for the v2 checkbox do not work with v2 Invisible.
  • Every domain and subdomain the store runs on must be added to the key in Google’s console.
  • PHP must have allow_url_fopen = 1.
  • Caches need a refresh after saving.

Which forms can be protected

Adobe’s storefront list includes Customer Login, Forgot Password, Create New Customer Account, Edit Customer Account, Contact Us, Product Review, Newsletter Subscription, Checkout/Placing Order, Wishlist Sharing, and Coupon Codes. Depending on edition and hosting, it also includes Create New Company Account for B2B, Gift Card, Invitation Create Account, Send To Friend, and the PayPal PayflowPro payment form.

Not every form is worth protecting. Each one adds a dependency on Google and a chance of blocking a real shopper. A practical priority list:

Form Typical abuse Protect? Suggested type
Create New Customer Account Fake account creation Yes v3 Invisible
Customer Login Credential stuffing Yes v3 Invisible
Forgot Password Email flooding, account probing Yes v3 Invisible
Newsletter Subscription List pollution, fake signups Yes v3 Invisible
Contact Us Spam submissions Yes v3 or v2 Invisible
Product Review Review spam Yes v3 Invisible
Coupon Codes Code guessing Often v3 Invisible
Checkout/Placing Order Card testing Case by case v3 Invisible, after testing
Wishlist Sharing, Send To Friend Spam relay If enabled v3 Invisible
Edit Customer Account Low risk for most stores Rarely Usually off

Checkout is the hardest call. Card testing attacks are real, but a reCAPTCHA failure at Place Order costs a real sale. Many stores get better results from payment provider fraud tools and edge rate limiting on checkout, and reserve reCAPTCHA for account and marketing forms. Our guide to managing bot traffic and rate limiting with Cloudflare covers the edge side, including when Cloudflare Turnstile is a lighter alternative.

How Hyva supports reCAPTCHA

Hyva works with Magento’s native reCAPTCHA modules. The Hyva reCAPTCHA documentation states that v3 Invisible is supported, and that v2 Invisible and the v2 checkbox are supported since Hyva 1.1.15. Forms that Magento ships are controlled by the per-form admin settings, the same as on Luma.

One requirement trips up many migrations. Hyva does not support Magento’s older built-in CAPTCHA, the image CAPTCHA under Customer Configuration. The Hyva documentation says to disable it, because otherwise forms will not work:

bin/magento config:set customer/captcha/enable 0

If login or account creation silently fails after a Luma to Hyva switch, check this setting first.

How Hyva loads Google’s script

This is where Hyva differs most from Luma, and where the performance story comes from.

In Hyva’s default theme, available in the public Hyva default theme repository, the reCAPTCHA script loader renders nothing at all if no reCAPTCHA keys are configured. When keys exist, it does not load Google’s script on page load. Instead it waits for the shopper to interact with a form field, and only then injects api.js from Google asynchronously. Pages where nobody touches a form never download reCAPTCHA.

The checkbox works differently. Because the “I am not a robot” widget has to be visible when the page renders, Hyva’s checkbox template forces the script to load as soon as the page is ready. That means every page with a checkbox-protected form pays for Google’s script and its iframe up front, whether or not the shopper uses the form.

A second detail affects forms rendered after the page loads. Forms built dynamically by Alpine.js or Magewire, such as a login form in a modal or a checkout step, may need the script loaded when they appear rather than on interaction. Hyva’s templates handle this for v2 Invisible in those cases.

For performance, the conclusion is simple:

  • Invisible types are close to free on pages where shoppers do not use a form.
  • The checkbox adds third-party JavaScript to every page that renders it, which can affect load time and interaction responsiveness.
  • A newsletter form in the footer is on every page. Protect it with an invisible type, never the checkbox.

Tuning the v3 score threshold

reCAPTCHA v3 returns a score for each request, where 1.0 is very likely a human and 0.0 is very likely a bot. Magento compares it with the Minimum Score Threshold, which Adobe lists as 0.5 by default.

Requests scoring below the threshold are rejected. So:

  • If real shoppers report that login or signup fails, lower the threshold.
  • If spam still gets through, raise it in small steps, and watch for complaints.

Some third-party guides describe this backwards. The rule is that a higher threshold is stricter.

Change the threshold based on evidence, not guesses. Log rejected submissions where possible, compare spam volume before and after, and keep in mind that new visitors, privacy browsers, and VPN users tend to score lower.

Adding reCAPTCHA to custom forms on Hyva

Custom forms, such as a B2B quote request, a dealer application, or a warranty registration, need to be wired up manually. Hyva’s documentation describes the pieces:

  • The form must sit inside an Alpine.js component.
  • A validation child block is attached to the form block under the alias recaptcha_validation. Hyva provides blocks for each type: recaptcha_validation, recaptcha_validation_invisible, and recaptcha_validation_recaptcha.
  • A matching hidden input block carries the token: recaptcha_input_field, recaptcha_input_field_invisible, or recaptcha_input_field_recaptcha.
  • The Hyva\Theme\ViewModel\ReCaptcha view model gives templates access to reCAPTCHA settings.
  • v3 requires showing Google’s legal notice when the badge is hidden.
  • The form’s parent block name may only contain letters, slashes, and underscores.

Server-side verification is the half that is easy to forget. A token in a hidden field protects nothing unless the controller that receives the form verifies it. Use Magento’s reCAPTCHA validation on the server for every custom form you protect.

Checkout, GraphQL, and CSP

Checkout. Adobe has published patches for reCAPTCHA problems at checkout on the Luma checkout, including a case where the Place Order button became disabled with v3 Invisible and certain payment methods. On Hyva Checkout, order placement runs through its own place order service, so do not assume Luma behavior carries over. If you enable reCAPTCHA for Checkout/Placing Order, test every payment method, including express wallets, before launch.

GraphQL and headless. For PWA or headless frontends, Adobe exposes reCAPTCHA settings through GraphQL. The recaptchaV3Config query returns the site key, minimum score, and the list of protected forms, so a headless client can apply the same rules as the Magento admin.

Content Security Policy. reCAPTCHA loads scripts and frames from Google domains. If your store enforces a CSP, allow the required script, frame, and connect sources, and test in report-only mode first so a policy change does not quietly break login.

Monitoring after launch

reCAPTCHA is not a set-and-forget control. Watch a few signals for the first month after enabling it or changing types:

  • Account creation and newsletter signup rates. A sudden drop with no change in traffic usually means real shoppers are being rejected.
  • Contact form and review volume. Spam should fall; legitimate submissions should not.
  • Support tickets mentioning login or “something went wrong” errors.
  • Google’s reCAPTCHA console, which shows request volume and score distribution for each key.

Review these again after every key rotation, domain change, or Hyva upgrade that touches the reCAPTCHA templates.

A pre-launch checklist

  1. Disable the legacy Magento CAPTCHA.
  2. Create separate keys for each reCAPTCHA type, with every domain added.
  3. Use v3 Invisible for account and marketing forms; avoid the checkbox on sitewide forms.
  4. Decide on checkout deliberately and test every payment method if you enable it.
  5. Wire custom forms with the Hyva validation and input blocks, and verify tokens on the server.
  6. Start at the 0.5 threshold and adjust based on logged rejections.
  7. Check CSP and confirm Google’s script loads only after form interaction on invisible types.
  8. Add form submissions to your end-to-end tests so a key rotation or module update does not break login unnoticed.

Working with Bemeir

Bemeir is a Brooklyn ecommerce agency. Our Hyva development services and Magento development services cover storefront security, checkout, and performance for Magento Open Source and Adobe Commerce. Teams on other platforms can look at our Shopify development, Shopware development, and BigCommerce development work. Related reading: form validation on Hyva covers the client-side checks that sit alongside reCAPTCHA. Learn more about Bemeir, see our technology partners, or visit the Bemeir home page.

FAQ

Does Hyva support Google reCAPTCHA?

Yes. Hyva works with Magento’s native reCAPTCHA modules. v3 Invisible is supported, and v2 Invisible and the v2 checkbox are supported since Hyva 1.1.15. Built-in forms are configured per form in the Magento admin, and custom forms are wired with Hyva’s validation and input blocks.

Which reCAPTCHA type is best for a Hyva storefront?

v3 Invisible suits most forms, because it shows no challenge and Hyva loads Google’s script only when a shopper interacts with a form. Avoid the v2 checkbox on forms that appear on every page, since Hyva loads its script as soon as the page is ready.

Why do forms stop working after switching to Hyva?

The most common cause is Magento’s legacy image CAPTCHA, which Hyva does not support. Disable it with bin/magento config:set customer/captcha/enable 0. Mismatched reCAPTCHA key types and missing domains on the key are the next things to check.

What is the default reCAPTCHA v3 score threshold in Magento?

Adobe lists the Minimum Score Threshold default as 0.5. Requests below it are rejected, so lower the threshold if real shoppers are blocked and raise it gradually if spam gets through.

Should I enable reCAPTCHA on Magento checkout?

Only after testing. A reCAPTCHA failure at Place Order blocks a real sale, and Adobe has published fixes for checkout reCAPTCHA issues in the past. Many stores rely on payment fraud tools and edge rate limiting for checkout, and use reCAPTCHA on account and marketing forms.

Let us help you get started on a project with Google reCAPTCHA on Hyva Magento Forms: Which Forms to Protect, Invisible vs Checkbox, and the Performance Cost and leverage our partnership to your fullest advantage. Fill out the contact form below to get started.

more articles about ecommerce

Read on the latest with Shopify, Magento, eCommerce topics and more.