Skip to content
nForms project interface
Partial

Public pages and primary sources were checked, but the core workflow was not independently completed or audited.

nForms

What makes it notable is not replacing image puzzles with math alone, but compressing form delivery, spam defense, and accessible validation into one progressively adoptable interface.

Original author
Noah Kellner
Last verified
2026-07-18

01 / ANALYSIS

Product analysis

Verification profile
Maturity
Pilot
Confidence
Partial
Verified
2026-07-18
Commercial relation
Not sponsored

Problem solved

A basic contact form often needs separate delivery, bot protection, and accessible validation systems. nForms accepts submissions through a form action or one script tag and layers SHA-256 proof-of-work with ARIA error states.

Why it was selected

The public material includes a no-JavaScript form action, script enhancement, migration guides, API details, retention periods, and a dogfooded contact form. Its privacy policy separates submission data, analytics, authentication, email, and payment processors, preventing 'zero cookies' from being mistaken for 'zero data processing.'

What is genuinely novel

It puts computational cost on each submission instead of a visual challenge, supplementing proof-of-work with single-use nonces, timing, and content scoring. The same script handles validation rules, error relationships, and focus management.

Best for

Small teams needing an EU-hosted form backend and front-end developers studying CAPTCHA-free abuse prevention and accessible forms

Editorial evaluation

Problem insightstrong
Originalitystrong
Executionmedium
Transferabilitystrong

KEEP DISCOVERING

A few more products worth noticing

A small set selected by product shape and profile similarity, with independent verification records.

Browse all products

02 / WHAT STANDS OUT

Three product decisions worth noticing

01

Charge the submission, not the person

Background proof-of-work turns verification from a visual ability test into per-request compute cost, improving interaction and privacy while still requiring difficulty tuning for weak devices.

02

Unify adjacent failure points

Submission, spam rejection, and error feedback happen in one action; a unified integration reduces configuration drift and makes fallback behavior easier to explain.

03

Automate only the mechanical layer

ARIA state, error relationships, and focus movement can be generated, while page semantics, task comprehension, and real assistive-technology use still need human design and testing.

Product insight worth carrying forward

Replace 'prove you are human' with a verifiable per-submission cost, then make error semantics and focus management part of the same integration layer; leave compliance conclusions to a complete audit.

03 / DO NOT COPY

What not to copy

Do not turn 'zero CAPTCHA' into 'bots cannot pass' or 'zero conversion loss'; benchmark real abuse, weak devices, and failure fallbacks.
Do not present automatic ARIA, EU hosting, or zero cookies as proof of complete WCAG, EAA, or GDPR compliance; each is an audit input, not the audit conclusion.

04 / LIMITS & RISKS

Limits and risks

The ~200 ms solve time, inability for bots to scale, and zero conversion loss are unverified marketing claims; low-power devices and attackers may behave differently. Injected ARIA cannot replace semantic labels, keyboard paths, error copy, and assistive-technology testing. The terms describe 99.9% as a target rather than a guarantee, while the privacy policy discloses in-memory PostHog analytics, OAuth, Resend, Lemon Squeezy, and plan-based retention; buyers still need to review the DPA, subprocessors, and actual data path.

Compared with alternatives

Compared with visual CAPTCHAs it removes interaction and reduces tracking surface; compared with proof-of-work-only components it also hosts submissions, notifications, and analytics. The tradeoff is dependence on a managed service, whose combined security, accessibility, and privacy claims each require separate review.

05 / EVIDENCE

Visual evidence

nForms' official share image presenting its one-script, CAPTCHA-free positioning
The current official share image published by nForms; security, abuse prevention, and accessibility outcomes still require independent testing.

06 / SOURCE

Source and verification

Original author
Noah Kellner
Country / region
Germany
Maturity
Pilot
Confidence
Partial
Discovered
2026-07-18
Last verified
2026-07-18

What this review checked

We verified the English site, pricing, technical docs, GitHub organization, privacy policy, terms, and the visible public demo flow. We did not create an OAuth account, submit a form, benchmark proof-of-work, or conduct keyboard, screen-reader, or security testing. The site remains labeled Beta, so performance, spam resistance, WCAG 2.2 AA, and EU data-boundary claims remain first-party.

Latest change

Initial profile created from the site, pricing, docs, GitHub, privacy policy, and terms; no account or submission was created, and security and accessibility claims were not independently tested.

Ready to explore further?

Open the product, or return to the original source to verify the details.

ONE-TAP FEEDBACK

Did this profile help you judge the product?

One tap. No writing required.