Be part of JetBrains PHPverse 2026 on June 9 – a free online event bringing PHP devs worldwide together.

eludic's avatar

Does Laravel need CAPTCHA

Laravel forms have a unique token then does it still require CAPTCHA? What is your opinion. I am in 2 minds if I should implement it in my project.

0 likes
3 replies
JohnBraun's avatar
Level 33

The CSRF token is not meant to prevent spamming, but from preventing form submissions from other websites (the cross site request forgery). Spambots visiting your website can still submit your form, as the CSRF token is included when they visit your page.

The idea of a CAPTCHA is that spambots can't easily get the answer/value. To block spambots you could and should implement a captcha.

Please or to participate in this conversation.