What is the wordfence_verifiedHuman cookie?
wordfence_verifiedHuman is an HTTP cookie set by the Wordfence Security plugin for WordPress, used on millions of sites to protect against attacks, botnets, and automated traffic.
The cookie appears when Wordfence presents a visitor with a verification challenge (such as a CAPTCHA or an interim "human verification" page) triggered by a security rule — suspicious traffic patterns, rate limits being exceeded, or a temporarily blocked area of the site. It is set directly by the plugin at the server level, not by an external third-party script.
What data it stores
The cookie stores a simple flag confirming the visitor has successfully passed Wordfence's anti-bot check. It does not contain personally identifiable data such as a name, email address, or IP address in plain text.
The exact value format is not publicly documented by Wordfence and may vary between plugin versions. The data stays on the site's own server — the cookie is not sent to external Wordfence or Defiant Inc. servers; it's used locally by the WordPress installation that set it.
What it is used for
The cookie's purpose is purely functional and security-related: it avoids making the visitor repeat the human-verification challenge on every page load, for 1 day. Without it, a legitimate user could be repeatedly blocked or challenged by Wordfence's anti-bot system.
For the site owner, the cookie is part of the mechanism that filters automated traffic (scrapers, spam bots, brute-force attempts), reducing server load and attack risk.
Does it require consent?
In CookieFix's classification, wordfence_verifiedHuman is categorized as strictly necessary. Since it is indispensable to the site's security mechanism (protection against bots and automated attacks), it does not fall under the prior-consent requirement of the ePrivacy Directive (transposed in Romania via Law 506/2004).
- It does not require visitor consent to be set.
- It must still be disclosed, with purpose and duration, in the site's cookie policy, per GDPR transparency requirements and the standards of Romania's data protection authority (ANSPDCP).
- It should not be placed under the "statistics" or "marketing" categories in the consent banner.
How to block or delete wordfence_verifiedHuman
A visitor can delete or block this cookie from browser settings (Chrome, Firefox, Edge, Safari — per-site cookie management). Blocking it may cause Wordfence's human-verification challenge to reappear on every visit to the protected site.
For site administrators, since this cookie is strictly necessary, it should not — and typically cannot — be blocked pending consent without breaking the anti-bot protection. A CMP platform like CookieFix can automatically block scripts from categories that require consent (statistics, marketing) until the visitor accepts, while strictly necessary cookies like this one remain active to keep the site's core security functioning.
Frequently asked questions
No, it's a legitimate security cookie used only to confirm the visitor passed an anti-bot check. It doesn't contain personally identifiable data.
It only appears when Wordfence triggers a security check for that visitor, for example due to suspicious traffic, not on every normal visit.
No, it's classified as strictly necessary for the site's security protection, so it falls outside the prior-consent requirement, but it must still be listed in the cookie policy.
Wordfence may ask you to pass the human-verification check again the next time you visit the protected site.