npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@evarentha/linearpress-easy-captcha

v3.0.0

Published

为登录、注册与评论提供人机验证:普通 PNG 文本验证码(复杂度/变形/字符数/字符集可调)或 Cloudflare Turnstile,验证码错误次数超限自动封禁账号。

Readme

人机验证(easy-captcha)

LinearPress npm Node.js TypeScript License: GPL-3.0-or-later

English | 简体中文

为 LinearPress 的登录、注册与评论提交提供人机验证。支持两种方式:零依赖的内置 PNG 文字验证码,或 Cloudflare Turnstile。校验运行于服务端中间件,绕过表单直接请求接口同样会被拦截,答错次数超限将升级为临时封禁。

安装

git clone https://github.com/Evarentha/linearpress-easy-captcha.git src/plugins/easy-captcha

目录名必须与插件 id 一致,安装后需重启 LinearPress。也可以在 base 检出中执行 sh scripts/sync-plugins.sh easy-captcha,或在后台插件页上传 ZIP、填写 npm 包名。内置验证码不需要任何外部服务;Turnstile 需要 Cloudflare 后台签发的站点密钥(Site Key)与机密密钥(Secret Key)。

工作方式

答错次数达到阈值(默认 5 次)后,该主体将被封禁一段可配置的时间(默认 10 分钟),封禁期内即使答案正确亦予拒绝。登录与注册按提交的用户名计数;评论按用户 id 计数,游客按 IP。答对即清零计数,24 小时无活动后计数自动过期。

正确答案始终不会离开服务器:存储于访客会话,公开的仅为渲染出的图片,图片接口同时限流为每 IP 每秒 10 次。内置验证码以 5x7 笔画字体渲染至像素缓冲,再经自行实现的 PNG 编码器输出;字符数(1-8)、字符集(纯数字 / 纯字母 / 混合)、复杂度与变形(各 1-3 档)均可配置。使用 Turnstile 时,是否弹出挑战由 Cloudflare 决定;siteverify 调用设有 10 秒超时并按失败关闭处理:无法联系 Cloudflare 时,验证不会静默放行。

界面由前端脚本注入至现有的登录、注册、评论表单(按 form[action=...] 匹配),封装于由本插件自行适配样式的 .ec-box 元素中;不覆盖任何主题视图,因此兼容包括 Fluent 在内的所有主题;主题仅需在表单内提供提交按钮。

设置

设置页位于 /admin/easy-captcha,由基础权限 plugin:manage 守护(本插件不自定义权限)。可选择验证方式、调整文字验证码参数、设置答错阈值与封禁时长、填写 Turnstile 密钥。站点密钥经 GET /plugins/easy-captcha/config 发布给前端组件;机密密钥(Secret Key)永不离开服务器、设置页亦不回显,留空即保留已存值。

答错计数与封禁记录存储于本地基础设施 SQLite 的 ec_attempts 表,因此更换主数据库驱动(例如迁移至 MySQL)不影响人机验证状态。校验发生在登录、注册、评论处理器之前,可与其他插件在这些流程上共存:easy-2fa 与 oidc-sso 使用不同的路由与时序,SSO 回调不经过人机验证。

许可证

本项目以 GPL-3.0-or-later 许可发布,Copyright (C) 2026 Evarentha,完整文本见 LICENSE。