tiagozip/cap
Free, open-source and self-hosted CAPTCHA alternative to reCAPTCHA. Privacy-first and powered by proof-of-work and instrumentation challenges.
About the project
Lightweight open-source CAPTCHA alternative using proof-of-work and instrumentation challenges, with no images or tracking. Replaces visual captchas while preserving user privacy.
Useful for
- Protect a signup form from bots without visual captchas
- Deploy the standalone Cap Docker container with analytics
- Style the widget via CSS variables to match the site design
README summarized by DeepSeek V4.1 Flash. Details may be inaccurate.
Why it’s trending
- 7 stars so far today, about 12 expected by the end of the day.
- GitHub Trending JavaScript today: #9, +8 stars.
Stars per day
Bars are daily stars, the line is the usual pace. Red marks spike days.
Numbers
- Total stars
- 7,890
- Today
- 7 · ≈ 12 by evening
- Forks
- 600
- Issues and pull requests
- 307
- Watchers
- 26
- Language
- JavaScript
- Latest release
- [email protected] · September 23, 2026
- Created
- January 11, 2025
- Last push
- September 24, 2026
Star trust
Growth looks organic: forks and discussion are in line with active projects, and stars arrive unevenly, the way people give them.
These are heuristics, not a verdict: we judge by the repository’s behavior, not by a list of stargazers.
Spotted in
- September 29, 2026GitHub Trending JavaScript today: #9, +8 stars
More in this category
-
6.8
JoasASantos/Offensive-Security-AI-Models
A curated list of open-weight uncensored LLMs fine-tuned for cybersecurity tasks such as red teaming, penetration testing and security research. Each entry lists base model, size, context, VRAM and uncensoring method.
-
4.8
SecFathy/xss-specialist
Research prototype for XSS discovery: an offline study on specializing a small LLM via KEV-gated continual learning plus a live authorized assessment system where findings are confirmed only by execution in a headless…
-
4.7
angusdevgo/Seep-Reverse-Lab
Agent-native reverse engineering workbench for binaries and CWE-602 client-side authorization auditing: unifies Radare2, JADX, Apktool, Frida and IDA via 23 MCP tools with automatic task routing.
-
4.5
dagowda/notRDP
A Havoc C2 plugin that creates a hidden alternate Windows desktop, streams it to a browser viewer, and forwards mouse and keyboard input while staying invisible to the target user.
-
4.2
derv82/wifit3
Cross-platform USB Wi-Fi auditor in Python: scans networks, captures WPA handshakes and PMKIDs, attacks WPS and WEP via its own userland drivers without aircrack-ng.
-
3.8
TwoSevenOneT/InjectSetConsole
Proof of Concept for Windows process code injection via a named pipe, without using VirtualAllocEx or WriteProcessMemory. Demonstrates an EDR evasion technique for security researchers.