BenchRank
#39 in Application SecurityUpdated 2026-08

Cap

by Cap · Self-hosted, open-source CAPTCHA with no visual puzzles

BenchRank score

34 — BenchRank score out of 100

Screenshots of Cap

Homepage · Cap

Homepage of Cap

Overview

Cap is a self-hosted CAPTCHA that replaces reCAPTCHA, hCaptcha or Turnstile. Each verification runs two layers at once: proof-of-work using SHA-256 and time-lock challenges in WASM, and a freshly generated JavaScript program that checks the browser environment through DOM and canvas operations. The widget is about 20 kB, shows no visual puzzles and sends no data to third parties.

Best for
Teams replacing reCAPTCHA who want bot protection running on their own servers
Pricing
No prices are published: Cap is Apache 2.0 licensed and self-hosted with no quotas or per-request fees, and the site says Cap Standalone fits on a $5 VPS for most sites.
Runs on
Self-hosted

Strengths and trade-offs

Strengths

  • Apache 2.0 licensed and runs entirely on your own server
  • ~20 kB widget, zero dependencies, no third-party scripts
  • Invisible checks: proof-of-work plus JS instrumentation
  • siteverify API is compatible with reCAPTCHA and hCaptcha

Trade-offs

  • No hosted option — you run, update and monitor the server yourself
  • Migration needs client-side code swapped, not just the API endpoint
  • Challenges rely on WASM and JavaScript running in the visitor's browser
  • Compliance list is the vendor's own; the site states it is not legal advice

How Cap markets itself

A structured read of the promise, proof and page design on Cap’s captured homepage.

Homepage capture

“Self-hosted CAPTCHA”

  • Angle: Contrarian / anti-incumbent
  • Hero: 3D render

Pricing

Published plans and prices from Cap’s own pricing page.

How this score is made up

Each dimension is scored out of 100 and combined into the headline score using fixed weights.

  • MCP support

    Whether an agent can drive the product through the Model Context Protocol, and how much setup that takes.

  • API quality

    Public API surface: machine-readable spec, official SDKs, documented auth, errors, rate limits and versioning.

  • Documentation

    Publicly reachable docs — coverage, freshness, code samples and machine readability.

  • Agent friendliness

    How readable the site is to an automated client: llms.txt, structured data, server-rendered content, crawler access.

  • Changelog

    A public, dated record of what shipped and when — the clearest signal that a product is still alive.

  • Marketing site structure

    Whether the site answers a buyer's questions: clear positioning, the pages that matter, and accessibility.

  • Page speed

    How fast the site loads for real visitors: Chrome UX Report 75th-percentile LCP, INP and CLS, with a Lighthouse mobile run standing in where a site has too little traffic for field data.

  • Operational trust

    Status page and incident history, security disclosure, compliance and data-processing documentation.

Measured, but not part of the score

Useful to know, but not a mark for or against the product — so these do not affect the ranking.

  • Openness

    Source availability, self-hosting, data export and open standards. Scored and shown, but not part of the composite — paid SaaS is not worse for being paid SaaS.

  • Maintenance

    Release cadence and repository activity. Scored and shown, but not part of the composite — it is only measurable for open repositories.

This doesn’t look right — report a problem with Cap’s score

Where this comes from

The Cap pages BenchRank reads when it scores the product — its documentation, release notes, status and security pages, and its repository where there is one.

Alternatives in Application Security

  • Ranked 1

    83.1 — BenchRank score out of 100

    Sentry

    Sentry · Error tracking and application performance monitoring for developers

    Best for: Development teams wanting error monitoring, tracing and session replay tied to one trace

  • Ranked 2

    80.8 — BenchRank score out of 100

    GrowthBook

    GrowthBook · Warehouse-native feature flags, experimentation and product analytics

    Best for: Product and engineering teams running feature flags and experiments on their own data warehouse.

  • Ranked 3

    79.4 — BenchRank score out of 100

    Temps

    Temps · Self-hosted deploy platform with built-in analytics, errors and monitoring

    Best for: Teams self-hosting deployments who also want analytics, error tracking and uptime on their own server

See all 53 alternatives to Cap

Is this your product?

Claim Cap to manage its profile. Claiming lets you suggest edits to the descriptive fields — it never changes scores or rankings.

Claim this business

Report a problem with this page

Report an issue with Cap