markets/invisible_captcha
66.8
Adequate · 20 September 2026
309
lines of production code
Ruby
primary language
1
measurement over time
What this system is
InvisibleCaptcha is a Ruby gem designed to prevent spam in Rails applications by implementing invisible form protection mechanisms. It operates by injecting hidden honeypot fields, validating submission timestamps, and performing IP-based spinner detection to distinguish between human users and bots. The system provides configuration options for these checks, integrates with Rails via helpers and controller extensions, and includes a dummy application for testing and demonstration purposes.
Features
Initial release of Invisible Captcha gem
This change introduces the Invisible Captcha gem, a spam protection solution for Rails applications that uses honeypot fields, time-sensitive form submission checks, and IP-based spinner validation to block bots without impacting user experience. The release includes the core library code, configuration options (such as \honeypot\_enabled\, \timestamp\_threshold\, and \spinner\_enabled\), controller and view helpers, and a dummy application for testing. It also establishes the project's CI infrastructure via Appraisals to support Rails versions 5.2 through 8.0 and Ruby 2.7+, along with standard project files like the changelog, license, and documentation.
(repo-wide) · high confidence
Initial release of InvisibleCaptcha gem
Introduces the InvisibleCaptcha library, providing a spam prevention mechanism for forms that hides input fields from human users while remaining visible to bots. The gem integrates with Rails via a Railtie and offers configuration options for honeypot fields, timestamp-based submission checks, and spinner detection. It includes view and form helpers to inject hidden fields and styles, with support for internationalization and customizable error messages.
lib · high confidence
Behavioural changes
Invisible Captcha v2.3.0 introduces IP-based spinner validation and refined spam detection
This release upgrades the spam detection logic by adding an IP-based spinner token that is stored in the session and validated using constant-time comparison to prevent timing attacks, alongside the existing timestamp and honeypot checks. The controller extension now explicitly removes honeypot parameters from the request to prevent UnpermittedParameters exceptions, supports custom callbacks for spam events, and uses \redirect\_back\ for fallback redirects. The view helper generates dynamic CSS classes for the honeypot inputs and includes \tabindex="-1"\ to improve keyboard accessibility.
_lib/invisible\captcha · high confidence
Test coverage
Added Rails dummy application for testing; Added Topic model for testing purposes; Added demo view for visual honeypot testing; Added dummy Rails application for testing and demo purposes; Added test coverage for dummy app environment configurations; Added test coverage for dummy app initializers; Added test coverage for dummy app public assets; Added test infrastructure for dummy application helpers; Demo app layout displays Ruby and Rails versions for debugging; Expanded dummy app controller examples for testing; Initial test suite for InvisibleCaptcha.
Dependencies
Expanded CI support for Rails 5.2 through 8.0
The gemfiles directory now includes dedicated Appraisal configurations for Rails versions 5.2, 6.0, 6.1, 7.0, 7.1, 7.2, and 8.0, enabling the library to be tested against this broader range of Rails releases. Each configuration pins the specific Rails version and constrains the concurrent-ruby gem to versions below 1.3.5.
gemfiles · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Baseline
- First survey — no prior run to compare against. CAI 67.
Lenses
- Code Health 99
- Architecture 69
- Maturity 61
- Readiness 65
- Security 89
Changes since last survey
- 254 commits — 232 feature/other, 22 fixes
By area
- (root) — 147 commits
- lib/invisible_captcha — 49 commits
- (repo) — 28 commits
- spec/dummy — 14 commits
- spec/controllers_spec.rb — 6 commits
- lib/invisible_captcha.rb — 3 commits
- spec/helpers_spec.rb — 2 commits
- spec/view_helpers_spec.rb — 2 commits
- .github/workflows — 1 commit
- gemfiles/rails_4.2.gemfile — 1 commit
- spec/spec_helper.rb — 1 commit
Notable commits
- fix: CI updates and fixes (#47)
- fix: CI: fix matrix exclude
- fix: Fix flash message. (#125)
- fix: Fix mime-types-data dependency for TravisCI in ruby 1.9.3
- fix: Fix spec for Ruby 1.9.3
- fix: Rename and re-order methods. Fix tests.
- fix: Stores DateTimes as string in Session, parsing them back as needed. Fixes #16
- fix: allow controller flow with only specific honeypot (no scope), fix docs
- fix: changelog: fix v0.6.2 link
- fix: completely fix issue on specs (continuation of 41071da)
- fix: fix coladinha in readme
- fix: fix doc [ci_skip]
- fix: fix docs [ci skip]
- fix: fix readme style
- fix: fix specs: seems in Rails 4.2 html attributes are not sorted before render
- fix: fix tests for Rails 3.2: in that version input attributes are alphabetically sorted
- fix: fix tests for Rails 5.2
- fix: fix tests: reset timestamp_enabled for each run
- fix: little Readme fixes [ci skip]
- fix: makes the default timeout url do a redirect to root_path. Fixes #18
- …and 234 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
markets/invisible_captcha was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 20 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 468719871737212fd197be6a33b6d8cdd44744cb — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-b51f968c9b10.