EAA
European Accessibility Act (2025) alignment guidance.
Scope
SCaptcha can support an accessible implementation. Whether the complete service meets EAA requirements still depends on its configuration, integration, and the operator’s testing.
This page maps SCaptcha 2.3.0 behavior to the named framework. It is not a certification or legal advice.
EAA scope and timelines
Since 28 June 2025, the EAA applies to specified consumer products and services offered in the EU. Whether it applies to an operator and service needs a separate assessment.
An accessible CAPTCHA is only one part of service-level compliance.
WCAG alignment
SCaptcha replaces image puzzles with text-based verification, reducing visual barriers.
Keyboard and screen reader support align with WCAG guidance referenced by the EAA.
How SCaptcha supports EAA compliance
Under-Attack Mode offers a consistent verification screen with minimal friction.
Optional audio fallback provides an alternative when additional verification is required.
Implementation checklist
Ensure your theme preserves contrast, focus indicators, and readable typography.
Document accessibility testing and use analytics to refine behavior checks.
SCaptcha 2.3.0 behavior
Each challenge uses its own cryptographically random 32-byte salt. Your WoltLab installation validates the salt, hash, algorithm, answer, and HMAC against the issuing session. The challenge expires after 60 seconds and does not require an external CAPTCHA provider.
This option is off by default. If you enable it, SCaptcha sends the visitor's public IP address to proxycheck.io for proxy, VPN, or Tor evidence. SCaptcha 2.3.0 sends tag=0 by default; administrators can opt in to provider logging. The IP address is transmitted for every lookup either way.
A pre-submit marker and the optional text/audio proof are valid for 5 minutes. Under-Attack mode uses a signed, user-agent-bound access cookie for 5 to 30 minutes; the default is 10. Sentinel can store a server-side rejection in a separate signed cookie for 10 minutes. Sentinel itself is off by default.
Request analytics are on by default. Logs can contain linkable operational data, including IP address, user agent, request, network and location fields, reasons, and submitted browser telemetry. Retention defaults to 90 days and can be set from 1 to 3,650 days. Turning analytics off stops new collection but does not erase existing rows or exports.
What operators need to review
Document enabled features, limit access to security logs, and assess optional external services separately. SCaptcha does not replace legal review or accessibility testing of the complete website.
Enable only the options you need. Update privacy and cookie notices, restrict access to analytics and logs, and test the actual form integration before launch.
Report an accessibility problem
If you encounter a barrier on this website or in an SCaptcha integration, email us with the affected page, browser, and assistive technology, if applicable, at info@softcreatr.dev.