Edumall
Edumall – Education WordPress Theme
What it adds
- Shortcodes:
[tm_zoom_meeting] - Integrates with WooCommerce
Installation
- In your admin panel, go to Appearance > Themes and click the Add New button.
- Click Upload and Choose File, then select the theme's .zip file. Click Install Now.
- Click Activate to use your new theme right away.
Faq
Does this theme support any plugins?
How do I protect the sign-up and login forms with a CAPTCHA?
Since 4.8.0 the theme ships a built-in CAPTCHA for its account forms, and everything is configured under Appearance > Customize > CAPTCHA.
Out of the box the "Honeypot" option is already active on the registration forms, so a fresh install is protected against ordinary spam bots without any setup. A honeypot adds a decoy field that only an automated script fills in; real visitors never see it and nothing extra is asked of them.
A sign-up is accepted only if the decoy field arrives with the submission and arrives empty, so both the bots that fill in every field they find and the scripts that post straight to the endpoint without reading the form are turned away. Please still treat the honeypot as the free, zero-friction baseline rather than a guarantee: a bot written for your site can replay the form exactly and leave the decoy empty. If you are being targeted deliberately, or spam continues after enabling it, switch to one of the CAPTCHA services below - those verify every submission against the provider itself.
If you use a full-page cache, clear it after updating and again whenever you turn the CAPTCHA on or change provider, so visitors are not served a copy of a page from before the field existed. With the Honeypot this is forgiving: submissions missing the decoy are accepted for a 48-hour grace window that starts when it first goes live (its first render, verification or admin page load). With reCAPTCHA, Turnstile or hCaptcha there is no such window - a cached page carries no challenge, so the submission arrives with no token and is refused, and the visitor is told the CAPTCHA failed on a form that never showed them one. This covers every cached page carrying a guarded form, not only the Register Form widget.
A notice in the WordPress admin reports how many submissions were rejected in the last 7 days, split by cause. Automated submissions look the same as a broken form from the server's point of view, so as a rule the numbers just mean the protection is working and no action is needed. Act only if real visitors report they cannot register.
To use a CAPTCHA service instead:
- Create keys for the provider you want to use:
- Go to Appearance > Customize > CAPTCHA.
- Pick the provider under "CAPTCHA Provider" and paste the Site Key and Secret Key. The key type must match the provider - a v2 Checkbox key will not work with the v3 option and vice versa.
- Choose which forms are protected under "Protected Forms". "Registration" is on by default and covers the account popup, the Register Form Elementor widget, the instructor registration popup, and the WordPress (wp-login.php), Tutor LMS student / instructor and WooCommerce My Account registration forms. "Login" and "Lost Password" cover the theme's account popups plus the wp-login.php, Tutor LMS and WooCommerce login and lost-password forms; "Comments" covers the guest comment form and WooCommerce product reviews.
- For reCAPTCHA v3 only, "Score Threshold" (0 - 1, default 0.5) controls how strict the invisible check is: raise it if spam still gets through, lower it if real visitors get rejected.
- Optional: "Show Login Challenge After" shows the login challenge only once an IP address has failed to log in that many times within 15 minutes (0 = always); "If the Provider Is Unreachable" decides whether submissions are blocked (default) or let through for two minutes while the verification service is down; "Whitelisted IP Addresses" skips the CAPTCHA for your own addresses.
- Publish, then open the site in a private window and submit a test registration to confirm the widget appears and the form still submits.
Notes:
- Keys can also be defined in wp-config.php via the EDUMALL_CAPTCHA_SITE_KEY and EDUMALL_CAPTCHA_SECRET_KEY constants; they override the Customizer values.
- If a provider is selected but a Site or Secret Key is missing, no challenge can be shown, so the guarded forms reject every submission (fail closed) until both keys are added - except the Login forms, which are let through so nobody is locked out (see below); a warning notice is shown in the WordPress admin. The Honeypot option needs no keys.
- Setting "CAPTCHA Provider" to "Disabled" turns the whole feature off, including the honeypot.
- The CAPTCHA guards the theme's own account popups and Register Form widget, plus the WordPress (wp-login.php), Tutor LMS and WooCommerce registration, login and lost-password forms and the guest comment form. Login forms built with wp_login_form() (the login widget/block, BuddyPress, Elementor Pro) post to wp-login.php and get the field too. It deliberately does not run when a logged-in administrator creates an account or sends a reset link, nor on the accounts WooCommerce creates outside its My Account form (checkout, stock notifications), so it never blocks legitimate back-office or purchase flows. The BuddyPress registration page and, on multisite, the network sign-up screen (wp-signup.php) use separate flows and are not covered; the guest comment form is left alone when Jetpack Comments replaces it. A third-party plugin with its own registration, login or lost-password form that never prints the theme field will have its submissions rejected while the matching option is on - use the edumall_captcha_skip filter to exempt it (or place its form where the standard register_form / login_form / lostpassword_form hooks fire).
- Wrong or missing keys: registration, lost-password and comment submissions are rejected (fail closed) until the keys are fixed, but the Login forms are deliberately the exception - while a key is blank, does not look like a key of the selected provider, or is reported wrong by the provider itself, logins are let through unverified and a warning is shown in the WordPress admin, so a typo can never lock the administrators out of their own site (the edumall_captcha_login_leniency filter turns this off). The keys are checked the moment they are saved (their shape, and - where the provider allows it - the Secret Key against the provider), so most mistakes are reported before any visitor meets the form; Google and hCaptcha only judge the Secret Key on a real solve, so a wrong Google/hCaptcha secret of the right shape is reported after the first submission instead. Only a verdict about this site's own keys opens the Login forms, never one a visitor's submission could provoke.
- Locked out anyway (for example a wrong Site Key, whose widget cannot render, or a server that cannot reach the provider with the failsafe set to Block)? Add define( 'EDUMALL_CAPTCHA_DISABLE', true ); to wp-config.php to switch the whole feature off, fix the keys under Customize > CAPTCHA (or set "If the Provider Is Unreachable" to Allow), then remove the line. Tip: test the login form in a private window right after saving the keys, while your admin session is still open.
- Other CAPTCHA plugins: if hCaptcha for WP or Simple Cloudflare Turnstile already protects one of the WordPress, WooCommerce or Tutor LMS forms, the theme CAPTCHA steps aside on that form (no second widget, no double verification) and keeps guarding the theme's own popups and widget, which no plugin can reach; an info notice on the Dashboard, Plugins and Themes screens lists the forms left to the plugin. The theme only steps aside from requests the plugin will actually verify itself; a submission the plugin would skip (its "only on the login page" options, a foreign WooCommerce nonce, an unusual action) is still checked by the theme. Two set-ups get their own warning: hCaptcha for WP in reCAPTCHA-compatibility mode next to the theme's Google reCAPTCHA (enable "Disable reCAPTCHA Compatibility" in hCaptcha, or pick another theme provider), and Turnstile's "WordPress Login" check while the theme's Login option is off (the check runs inside the theme login popup, where its widget cannot appear - enable the theme's Login option, or Turnstile's "only on the login page"). Tutor Pro's Fraud Protection (Tutor LMS Pro > Settings > Authentication) is handled the same way: on the forms its reCAPTCHA v2/v3 guards (WordPress and Tutor registration, WordPress and Tutor login, Tutor lost password - per its "Location" setting) the theme shows no second widget and lets Tutor Pro verify the token, but still rejects a submission that carries no reCAPTCHA token at all, because Tutor Pro only checks the token when it is present. Its honeypot method is invisible and simply runs alongside the theme's. So a site that already had Tutor Pro's reCAPTCHA on keeps working after the update with a single challenge per form; if Tutor Pro's reCAPTCHA is selected without keys, its widget renders broken and the theme keeps guarding - a warning in the WordPress admin says so.
- For the WordPress, Tutor and WooCommerce forms (which submit with a normal page reload), the reCAPTCHA v2 Checkbox, Turnstile, hCaptcha or Honeypot options are recommended over reCAPTCHA v3; the invisible v3 token is best suited to the theme's own popups.
- For reCAPTCHA, Turnstile and hCaptcha, the solution's host is checked against your site's home URL host (www and apex are treated as equivalent) to reject tokens solved on a copy of your public Site Key elsewhere. If your Site Key is registered for several domains, or the site is reached on a staging or secondary host, add those hosts with the edumall_captcha_allowed_hostnames filter so real visitors there are not turned away. If you switch the provider back to Honeypot after running a CAPTCHA service, the 48-hour grace window restarts on your next admin page load.
- The provider script (api.js) is loaded only on pages that actually show a guarded form, and only once the form is on screen; the edumall_captcha_preload_api filter restores loading it on every page. If the verification service ever reports that your keys are wrong, or cannot be reached from your server, a notice in the WordPress admin says so.
- Developers can override the server-side decision with the edumall_captcha_is_valid filter (or the host decision with edumall_captcha_hostname_valid / edumall_captcha_allowed_hostnames), skip the CAPTCHA per request with edumall_captcha_skip, register more forms with edumall_captcha_forms, add providers with edumall_captcha_providers, set the widget language with edumall_captcha_language, map a trusted proxy header with edumall_captcha_client_ip, and extend the popup template allowlist with edumall_popup_lazy_load_templates.
Which CAPTCHA setup should I use?
Run ONE CAPTCHA system on the site. Every extra one adds a second challenge to the same form, a second script to the same page, and one more place to look when sign-ups stop working. Pick whichever of these three descriptions fits you and follow only that one.
-
You have no CAPTCHA plugin yet - use the theme's (recommended)
Appearance > Customize > CAPTCHA, pick a provider, tick the forms. Turn Tutor Pro's Fraud Protection OFF (Tutor LMS Pro > Settings > Authentication) and do not install a CAPTCHA plugin. This is the only setup that also covers the theme's own account popups, the Register Form widget and the instructor registration - forms no plugin can see - as well as the WordPress, Tutor LMS and WooCommerce forms and the comment form.
-
You already run hCaptcha for WP or Simple Cloudflare Turnstile - keep it
Leave the plugin configured as it is and set the theme's provider to the SAME service (or to Honeypot). The theme steps aside on every form the plugin already protects and only guards what the plugin cannot see, so each form still gets exactly one challenge. Do not point the theme at Google reCAPTCHA while hCaptcha for WP runs in its default reCAPTCHA-compatibility mode: hCaptcha then takes over the Google script and the theme's reCAPTCHA widget cannot render (either enable "Disable reCAPTCHA Compatibility" in hCaptcha, or choose another theme provider). A notice in the WordPress admin points this out if it happens.
-
You already run Tutor Pro's Fraud Protection - decide which one keeps the Tutor forms
With its reCAPTCHA method configured, the theme steps aside on the forms its "Location" setting covers and Tutor Pro challenges them; the theme keeps guarding its own popups, the WooCommerce forms and the comment form. Nothing breaks, but two Google keys on one site is a setup we recommend against, and mixing versions (for example the theme on reCAPTCHA v2 and Tutor Pro on v3) means a page that shows both a theme form and a Tutor form loads Google's script twice, which the two versions do not always survive. If you keep Tutor Pro's, match its version and keys in the theme, or untick the forms it covers; the simpler answer is to turn Fraud Protection off and let the theme do all of it. The WordPress admin warns when both are on.
Choosing a provider
- Honeypot - no keys, invisible, on by default. Stops ordinary spam bots and asks nothing of your visitors. Start here; move on only if spam gets through.
- Cloudflare Turnstile - a visible but usually click-free box, no Google account needed, the friendliest option for visitors in regions where Google is slow or blocked.
- Google reCAPTCHA v2 - the familiar "I'm not a robot" checkbox. Reliable, and the safest choice for forms that submit with a normal page reload (WordPress, Tutor LMS, WooCommerce).
- Google reCAPTCHA v3 - invisible and score based. Best on the theme's own popups; on ordinary page-reload forms prefer v2, Turnstile or hCaptcha. Raise the score threshold if spam gets through, lower it if real visitors are rejected.
- hCaptcha - like reCAPTCHA v2 with a stronger privacy stance.
Choosing the forms
- Registration is on by default and is where the spam is; leave it on.
- Comments is worth turning on for any site whose posts accept guest comments.
- Login and Lost Password are for sites that are actually being probed. When you turn Login on, set "Show Login Challenge After" to 3 - 5 so ordinary visitors see nothing and only an address that keeps failing meets the challenge.
Keys
- Create the keys for the provider you selected and add YOUR SITE'S DOMAIN to them (Google and hCaptcha reject solutions from unlisted domains).
- Each provider keeps its own Site Key and Secret Key fields, so switching between reCAPTCHA v2, v3, Turnstile and hCaptcha never loses the keys you already pasted - and never reuses another service's, which would not work (a v2 key and a v3 key even look identical). A provider you have not given keys to yet shows empty fields and reports itself as misconfigured until you fill them in. Keys of the wrong shape (a Turnstile key under reCAPTCHA, a key cut off when paste
Install
composer require meteorgpl-theme/edumall
The vendor’s license checks are intact: activate the theme in WordPress with a license key bought from the vendor.
License
Declared license: GPL-2.0-or-later. The code is redistributed under the license the vendor declared in the theme’s own headers. License profile: gpl-full.
Artwork, fonts, media and documents that may be licensed separately are not redistributed; the licensing page explains what is replaced or removed, and the security tab lists it per version. Support and update entitlement come with the license you buy from the vendor.