librecaptcha/lc-core
52.1
Adequate · 20 September 2026
2.7k
lines of production code
Scala
with Java, PHP
1
measurement over time
What this system is
LibreCaptcha is an open-source CAPTCHA framework that generates and validates various types of image-based challenges via a RESTful HTTP API. It supports multiple challenge providers with different difficulty levels and media formats, utilizing background workers to pre-generate and persist challenges in an embedded H2 database for efficient serving. The system includes a configurable web playground for testing, a WordPress plugin for form protection, and comprehensive tooling for automated solving and load testing.
How it got here
2018–2020 — Initial release and testing infrastructure
6 changes.
This period covers the initial public release of the LibreCaptcha framework, establishing the core Scala-based HTTP service, Docker deployment configuration, and client-side interface. It also involved setting up comprehensive testing infrastructure, including automated CAPTCHA solving scripts and Locust-based load and functional tests to validate performance and workflow correctness.
2021–2026 — infrastructure modernization and provider expansion
11 changes.
The project overhauled its core infrastructure by migrating to the picoserve HTTP framework, implementing structured configuration management, and introducing H2-based persistence for captcha challenges. This period also focused on expanding the library's capabilities by adding numerous new captcha providers with varied difficulty levels and media formats, alongside a new WordPress plugin for external integration.
Features
Add basic webpage template for Libre Captcha
The client now includes a basic webpage template consisting of an HTML entry point, CSS styles, and JavaScript logic. This template provides a user interface with an email input field and a Register button, which triggers a fetch request to the /v1/token endpoint to retrieve and display a secret token.
client · high confidence
Added browser-based CAPTCHA demo page
A new interactive HTML demo page has been added to the application resources, allowing users to test the CAPTCHA service directly in a browser. The page provides input fields for configuring CAPTCHA parameters such as difficulty level, media type, input type, and size, and includes JavaScript to fetch a CAPTCHA from the /v2/captcha endpoint, display the image, and submit answers via the /v2/answer endpoint. It also handles and displays error messages if the API requests fail.
src/main/resources · high confidence
Initial release of LibreCaptcha framework with Docker support and API documentation
This change introduces the initial public release of LibreCaptcha, an open-source CAPTCHA framework that provides an HTTP interface for generating and validating CAPTCHAs, including background workers for pre-computation and garbage collection. The release adds Docker support via a multi-stage Dockerfile and docker-compose configuration, allowing users to deploy the service on port 8888. It also includes comprehensive documentation in the README, detailing quick start instructions for Java and Docker, API endpoint specifications (v1 and v2), and examples for various CAPTCHA types like ShadowText and PoppingCharacters. Additionally, build and formatting configurations for Scala 3 and sbt are established, along with CI integration via Travis CI.
(repo-wide) · high confidence
Initial release of the LCFramework application
Introduces the main entry point for the LCFramework, which initializes and manages the captcha service lifecycle. The application loads configuration from a JSON file, sets up the captcha providers and manager, starts a background task for cleanup, and launches the HTTP server with optional authentication, CORS, and playground support. It also includes a utility to generate captcha challenge samples for testing.
src/main/scala/lc · high confidence
Introduce LibreCaptcha WordPress plugin for form protection
Adds a new WordPress plugin that integrates LibreCaptcha into login, registration, and comment forms. The plugin provides server-side verification of CAPTCHA answers via API calls to a configured LibreCaptcha server, supports an authentication key for secure communication, and includes a settings page with a connection test tool to validate the server configuration.
plugins/wordpress · high confidence
Introduction of picoserve HTTP server framework
The application now utilizes the picoserve library to handle HTTP requests, replacing previous server implementations. This new server component supports method-specific routing, allowing different handlers for GET, POST, and other HTTP verbs on the same path, and includes built-in support for handling CORS preflight OPTIONS requests to ensure proper cross-origin access control.
src/main/java/org · high confidence
New captcha providers: CrumpledText, Debug, Filter, Label, and RainDrops
The captcha module now includes five new challenge providers. CrumpledTextCaptcha generates PNG images with a localized shearing algorithm to simulate a crumpled paper effect, with difficulty levels adjusting fold frequency and character set. DebugCaptcha provides simple, high-contrast PNG images for testing OCR capabilities. FilterChallenge applies Gaussian blur, smear, and ripple filters to text in PNG images, with difficulty controlling filter intensity and character complexity. LabelCaptcha presents a hybrid challenge combining known and unknown image pairs, tracking user responses to potentially migrate unknown images to the known set. RainDropsCaptcha generates animated GIF sequences featuring falling rain drops and outlined text, with difficulty affecting text length and drop density.
src/main/scala/lc/captchas · high confidence
New captcha providers: FontFun, PoppingCharacters, and ShadowText
The library introduces three new CAPTCHA challenge providers: FontFunCaptcha (medium difficulty, PNG), PoppingCharactersCaptcha (hard difficulty, animated GIF), and ShadowTextCaptcha (easy difficulty, PNG). These providers implement the ChallengeProvider interface, allowing users to generate CAPTCHA challenges with specific difficulty levels and image formats, and verify answers against the generated secrets.
src/main/java/lc/captchas · high confidence
New image utility classes for GIF, PNG, and helper functions
Added three new utility classes in the lc.misc package: GifSequenceWriter for creating animated GIF sequences with configurable frame timing and looping; PngImageWriter for generating PNG images with embedded DPI metadata (set to 245 DPI); and HelperFunctions providing static methods for random string generation (with safe alphabet support to avoid ambiguous characters like 'I', 'l', 'O', '0', '1'), size parsing, and graphics rendering hint configuration (antialiasing, text antialiasing, fractional metrics).
src/main/java/lc/misc · high confidence
Behavioural changes
Background task now pre-generates captchas for all parameter combinations
The background task has been refactored to proactively generate captchas for every valid combination of parameters (level, media, input type, and size) rather than relying on on-demand generation. It calculates the required count per combination based on the \bufferCount\ configuration and creates them in batches, ensuring a steady supply of pre-generated challenges is available for users.
src/main/scala/lc/background · high confidence
Introduces structured configuration and captcha provider management
The core module now uses a new configuration system based on ZIO Blocks Schema for JSON parsing, replacing the previous approach. This introduces a \Config\ class that loads settings from a file (or generates defaults), including options for port, address, buffer count, seed, captcha expiry, thread delay, playground visibility, CORS headers, and authentication requirements. A new \CaptchaManager\ class manages captcha generation and validation, while \CaptchaProviders\ handles provider selection based on configuration filters. Several enumerations (\ParametersEnum\, \AttributesEnum\, \ResultEnum\, \ErrorMessageEnum\) define supported parameters, attributes, results, and error messages. New captcha providers like \CrumpledTextCaptcha\ and \DebugCaptcha\ are registered, and existing ones like \GifCaptcha\ have been renamed to \PoppingCharactersCaptcha\. The system now supports filtering captchas by level, media, input type, and size, and allows configuring which captchas are available for each parameter combination.
src/main/scala/lc/core · high confidence
Introduction of H2-based captcha persistence with connection and schema management
The application now persists captcha challenges and their mappings using an embedded H2 database. A new DBConn class manages the JDBC connection to the H2 file at ./data/H2/captcha3, while the Statements class defines the schema (challenge and mapId tables) and prepares SQL statements for inserting, selecting, updating, and deleting captcha data. The system uses a ThreadLocal to provide per-thread Statement instances, addressing concurrency issues observed with multiple connections in earlier H2 versions, and includes logic to respect size, level, and content parameters when selecting or counting captchas.
src/main/scala/lc/database · high confidence
New HTTP server implementation with CORS, auth, and playground support
The server component has been rewritten to use the picoserve library, introducing explicit support for CORS preflight (OPTIONS) handlers on API routes, configurable authentication via an 'Auth' header, and a toggleable web playground. Users can now enable a demo interface via the playground flag, which serves a welcome page and a demo HTML file, while API endpoints enforce optional access control and return appropriate CORS headers when configured.
src/main/scala/lc/server · high confidence
Test coverage
Added Locust-based load and functional test suite; Added server authentication and integration tests; Added simpleTest.py script for automated CAPTCHA solving.
Dependencies
Initial project setup with Scala 3.8.2 and core dependencies
The build configuration establishes the project as 'LibreCaptcha' using Scala 3.8.2. It introduces specific library dependencies including scrimage (core and filters) version 4.6.7 for image processing, zio-blocks-schema version 0.017 for schema handling, and ScalaTest 3.2.20 for testing. The build also configures the assembly plugin to produce 'LibreCaptcha.jar' with the main class 'lc.LCFramework', sets up resource directories, and enables forking for both run and test tasks.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Baseline
- First survey — no prior run to compare against. CAI 52.
Lenses
- Code Health 96
- Architecture 88
- Maturity 58
- Readiness 59
- Security 68
- Accessibility 39
Changes since last survey
- 300 commits — 295 feature/other, 5 fixes
By area
- (repo) — 128 commits
- (root) — 100 commits
- project/build.properties — 24 commits
- project/plugins.sbt — 16 commits
- src/main — 16 commits
- plugins/wordpress — 5 commits
- .github/workflows — 4 commits
- .github/scala-steward.conf — 2 commits
- src/test — 2 commits
- tests/debug-config.json — 1 commit
- tests/locustfile-functional.py — 1 commit
- tests/run.sh — 1 commit
Notable commits
- fix: Fix Java runtime version and test endpoints
- fix: Fix tests and locust debug-config issue
- fix: Merge pull request #328 from librecaptcha/fix/ci-duplicate-runs-18274624062406751999
- fix: Revert DB modifications and fix tests via sbt forking
- fix: fix URL of image in plugin
- change: Add 'Reformat with scalafmt 3.11.0' to .git-blame-ignore-revs
- change: Add 'Reformat with scalafmt 3.9.5' to .git-blame-ignore-revs
- change: Add 'Reformat with scalafmt 3.9.7' to .git-blame-ignore-revs
- change: Add AuthRequired config and API enforcement
- change: Add CORS OPTIONS preflight handlers to API routes
- change: Add CrumpledTextCaptcha provider
- change: Add WordPress plugin for LibreCaptcha integration
- change: Add auth key and server-side testing to WP plugin
- change: Add connection test tool to WP plugin settings
- change: Adjust fold levels for crumpled captcha difficulty
- change: CaptchaConfig.config should be an object
- change: Implement localized shearing algorithm for realistic crumpled effect
- change: Merge branch 'master' into update/sbt-scalafmt-2.5.2
- change: Merge branch 'master' into update/sbt-scalafmt-2.5.4
- change: Merge branch 'master' into update/scalafmt-core-3.11.0
- …and 280 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
librecaptcha/lc-core was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 20 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 7757f9119cb1646cc285eea2b4a10c12648f4252 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-b51f968c9b10.