# wenlng/go-captcha: behavior CAPTCHA generation in Go, without a third-party service

> wenlng/go-captcha is a Go library that draws click, slide, drag-drop and rotate CAPTCHAs from your own images and fonts. It is a generator and a verifier, not a drop-in hosted CAPTCHA, and the frontend half lives in separate packages.

**wenlng/go-captcha** — 🖖 GoCaptcha: A high-performance, interactive behavior captcha library for Go. Supporting click, slide, drag-drop, and rotation modes to secure your applications with ease.

- Repository: https://github.com/wenlng/go-captcha
- Website: http://gocaptcha.wencodes.com
- Stars: 2,435 · Forks: 221
- Language: Go
- License: Apache-2.0
- Published: 2026-09-28 · Updated: 2026-09-28 · Language: en
- Canonical page: https://hysenlabs.com/projects/wenlng-go-captcha

## What wenlng/go-captcha actually produces

The library generates behavioral CAPTCHAs, meaning the user proves humanity by performing an action rather than by reading distorted text. The README lists four modes: Click, Slide, Drag-Drop and Rotate. In a click CAPTCHA the user selects characters or shapes in order; in a slide CAPTCHA they push a puzzle piece to a gap; drag and rotate work along the same lines with a different gesture.

The output is image data plus the answer the server must remember. The README describes built-in dynamic image generation and processing that produces a main image, a thumbnail, a puzzle piece and shadow effects. That is the shape of the payload: the client receives a background and one or more movable pieces, and the server keeps the coordinates or the character set that counts as correct.

This is aimed at Go teams that do not want to call an external CAPTCHA vendor. The repository is a library, not a SaaS. Nothing in it phones home to a verification service. The trade-off is that you own the storage of the challenge and its answer, and you own the frontend rendering.

## The Go library and the JavaScript packages are separate projects

The README's ecosystem table is the part worth reading twice. Under the main go-captcha repository sit go-captcha-jslib, go-captcha-vue, go-captcha-react, go-captcha-angular, go-captcha-svelte, go-captcha-solid and go-captcha-uni. Each is its own repository with its own release cadence. There is also go-captcha-assets for embedded resources, go-captcha-example for Golang plus web and app samples, and go-captcha-service with its own SDK.

So the split is: the Go module draws the image and validates the answer, and a frontend package handles pointer events and submits the result. If you use the Vue package, you are depending on two projects that version independently. The README does not document a compatibility matrix between the Go library and the frontend packages, which is a real gap when you upgrade one side.

The go-captcha-service entry is a different deployment shape altogether. The README says it supports binary and Docker image deployment, exposes HTTP and gRPC interfaces, and supports standalone and distributed modes with service discovery, load balancing and dynamic configuration. That is for teams that want the CAPTCHA as a network service rather than an imported package.

## Getting the module and wiring up a first CAPTCHA

The module path is github.com/wenlng/go-captcha, and go.mod declares go 1.16 with two dependencies: github.com/golang/freetype and golang.org/x/image. The freetype dependency is the tell that text rendering happens inside the library rather than in a template engine.

The README points to go-captcha-assets for the images and fonts the generator draws with, since the library itself does not ship a picture set. The README does not print a go get line for either module, so the module path above is the only install detail it gives; the project site at gocaptcha.wencodes.com and the example repository go-captcha-example are where the README sends you for a working Golang plus web setup.

The README states that images, fonts, colors, angles and sizes are configured through Options and Resources. The exact constructor names and option fields are documented on the project site and in the GoDoc link in the README, not in the README itself, so read those before writing the handler. Treat the assets repository as a required companion rather than an optional extra: without an image set and a font, there is nothing for the generator to draw.

If you would rather not import anything, the go-captcha-service repository is described as supporting binary and Docker image deployment with HTTP and gRPC interfaces. The README does not give a docker run command or an image name, so take those from that repository's own documentation.

## Where the design puts work on you

The library generates and verifies. It does not store. Every issued challenge needs a key and an expected answer held somewhere the verification handler can reach, and the README does not prescribe Redis, a database or an in-process map. That choice is yours, and it decides whether your CAPTCHA survives a restart or a second instance behind a load balancer. The go-captcha-service entry addresses this with distributed mode and service discovery, which implies the library alone is not distributed.

Rate limiting is also outside the library. Nothing in the README describes throttling challenge generation, so an endpoint that mints a new image on every request is an endpoint someone can hammer for CPU. Image generation is not free, and freetype plus golang.org/x/image means each challenge costs real work.

Finally, a behavioral CAPTCHA is not a bot detector by itself. It raises the cost of automated submission. The README does not claim otherwise, and it should not be read as a complete anti-abuse layer.

## How this differs from AJ-Captcha and from hosted CAPTCHA services

AJ-Captcha is the closest thing in the search results around this project, and the difference is language and packaging. AJ-Captcha is a Java project; wenlng/go-captcha is a Go module with go.mod declaring go 1.16. If your backend is Java, go-captcha is not a drop-in replacement, and the frontend packages will not save you because the generator is the Go side.

Hosted services such as Google's reCAPTCHA take the opposite approach: you embed a script, the challenge is rendered and scored by the vendor, and your server verifies a token against their endpoint. You get less control over appearance and you send traffic to a third party. With go-captcha the images come from your own asset set and the verification stays in your process, which matters if you cannot call out to an external domain from the login page.

The cost of that independence is that you assemble the pieces. The README's ecosystem table is long precisely because the frontend side is not one package but seven, plus a service and an SDK.

## Release cadence, licence and upgrade cost

The last push to the repository was on 2026-03-07, the same day v2.0.5 was released. Before that, v2.0.4 landed on 2025-05-18 and v2.0.3 on 2025-02-16. That is roughly a release every few months, with a gap of about ten months between v2.0.3 and v2.0.4. The repository is not archived. Plan upgrades around that cadence rather than around a fixed schedule.

The licence is Apache-2.0, and the LICENSE file sits at the repository root alongside README.md and README_zh.md. Apache-2.0 permits commercial use and modification and includes an explicit patent grant. It also requires that you keep the licence and notice files with any redistribution. That is the standard reading of the text; for your own product's obligations, ask your legal team rather than treating this paragraph as advice.

The upgrade cost that matters here is not the Go module. It is the pairing between the Go library version and whichever frontend package you picked, plus go-captcha-assets if the image set changes. The README does not publish a compatibility table, so budget time to re-check the frontend package on each Go-side bump.

## Conclusion

Adopt wenlng/go-captcha if you already run a Go backend and want the CAPTCHA image produced on your own servers from your own image assets, with the browser side handled by go-captcha-vue, go-captcha-react or the plain JavaScript package. Do not adopt it if you want a hosted CAPTCHA with a dashboard, or if you have no Go service to host the generator. Verify first that your chosen frontend package and the Go library version match, that you have a store for the captcha key and answer, and that the go-captcha-service deployment mode you pick is the one your infrastructure can actually run.

## FAQ

### Is wenlng/go-captcha a hosted CAPTCHA service?

No. It is a Go library that generates behavioral CAPTCHA images and verifies the answer inside your own process. If you want it as a network service, the ecosystem lists go-captcha-service, which the README says supports binary and Docker image deployment with HTTP and gRPC interfaces.

### Which CAPTCHA types does wenlng/go-captcha support?

The README lists four interactive types: Click, Slide, Drag-Drop and Rotate. Images, fonts, colors, angles and sizes are configured through Options and Resources.

### Does wenlng/go-captcha include the frontend code?

Not in the main repository. The README's ecosystem table lists separate packages for JavaScript, Vue, React, Angular, Svelte, Solid and UniApp, each in its own repository. The Go module generates the image and verifies the answer; the frontend package handles the interaction.

### What Go version does wenlng/go-captcha need?

The go.mod file at the repository root declares go 1.16 and requires github.com/golang/freetype and golang.org/x/image.

### Under what licence is wenlng/go-captcha released?

Apache-2.0. The LICENSE file is at the repository root, and the README links to it on the v2 branch.

## Sources

- [License: Apache-2.0](https://github.com/wenlng/go-captcha/blob/master/LICENSE)
- [Project website](http://gocaptcha.wencodes.com)
- [README](https://github.com/wenlng/go-captcha/blob/master/README.md)
- [Releases](https://github.com/wenlng/go-captcha/releases)
- [wenlng/go-captcha on GitHub](https://github.com/wenlng/go-captcha)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/wenlng-go-captcha
