We’re on a roll this week! Just a few days after launching QuickHover (our popular new Bric that adds beautiful hover animations to any element in Blocs), I’m excited to release TurnGuard, a powerful new Bric that brings Cloudflare Turnstile spam protection to your Blocs forms.
Turnstile is Cloudflare’s modern, privacy-respecting alternative to old-school CAPTCHAs. Instead of forcing users to solve annoying puzzles, it works mostly invisibly in the background and only challenges suspicious visitors with a simple checkbox when needed.
Key features of TurnGuard:
Completely invisible on the live site (only shows a clean settings card inside Blocs)
Supports Managed, Non-Interactive, and fully Invisible modes
Works perfectly with Blocs’ built-in contact form and custom forms
Smart positioning, sizing, theming, language options & more
Option to disable the submit button until verification is complete
Custom CSS class support
No server-side code required and works great on static hosting
Setup is incredibly fast: just grab your free Cloudflare Site Key, drag the Bric onto the page (wherever you want! ) , paste the key, and you’re protected.
We built TurnGuard because We were tired of dealing with form spam while still wanting to deliver a smooth, professional experience for real visitors.
Or, you can grab TurnGuard for only $9.99 directly on Gumroad: Here
And if you haven’t checked out RichForms, creating fully branded HTML emails yet, go have a look. It works seamlessly with Turnguard and has been getting great feedback!
We would love to hear your thoughts or any feature requests for future Brics.
Just implemented both TurnGuard and RichForms on my first Blocs site (work in progress). They are both very nice and are very easy to implement. Just a quick thank you to all of the Blocs / Brics and Template developers. You are all very talented and deserve a round of applause for making us no-technical web developers look like pros . I came from the Rapidweaver world and am really enjoying Blocs, thank for that Norm and Helen.
TurnGuard 1.1.1 is out with an amazing update: server-side verification
Until now TurnGuard did everything in the browser. The widget rendered, the submit button stayed locked until Turnstile handed over a token, and the form could not be sent without one. That already stops the everyday spam bots. What it could not do was prove the token was real, because that proof has to come from your own server asking Cloudflare. Some of you have seen the notice in the Cloudflare dashboard saying the widget is never verified with siteverify. That is what 1.1.1 fixes.
What is new
Verify on server (PHP). A new checkbox in the sidebar. When it is on, every token is sent to a small PHP file that Blocs exports with your site. That file asks Cloudflare whether the token is genuine, was issued for TurnGuard, and, if you want, came from one of your own hostnames. Only a yes from Cloudflare unlocks the submit button. A forged or reused token gets nowhere.
Secret Key field. Your Turnstile Secret Key now has a home in Blocs. It is written into the exported PHP file and nowhere else. It never appears in the page HTML or in the page JavaScript, and it is stripped from the Bric on export.
Hostnames. Optional. A comma separated list, and the token must have been issued on one of them. Leave it empty to skip the check.
Get Secret Key button. Sits next to Get Site Key and opens the Cloudflare page where the secret is shown beside the site key.
Size: Invisible in the Size dropdown now actually works. It was in the list before but fell back to Normal.
The canvas card shows a Server: On or Server: Off pill so you can see the state at a glance.
With the checkbox off, nothing changes. The Bric behaves exactly as 1.0.0 did.
Get TurnGuard now for only $9.99 in the Blocs Store : here
Read the full documentation prior purchasing : here