Security and privacy decision

HealthCAPTCHA

A competent developer can build a useful client-side squat CAPTCHA widget in about a week using existing in-browser pose models; the vendor adds polish, analytics, and enterprise features you would forfeit.

Visit website
You pay

Not priced

No pricing page we fetched carried a figure, so there is nothing to compare against. The build side is still real.

You’d pay instead

$50one-off22 h to build

$0/mo1 h/mo upkeep

No published price to break even against.

Open-source builds that already do this

Every project below is open source and already does this job today. Fork one, self-host it, or take the parts you need - the build prompt further down assumes an empty file, and this is the shortcut past that. Licences differ; check the one on each card before you ship. All HealthCAPTCHA alternatives, with the arithmetic →

What a replacement has to do

  • Embed a client-side webcam pose detector that counts squats and returns a signed verification token to the host site.

What it still won’t have

  • Vendor-managed usability polish, A/B testing and analytics
  • Enterprise integrations, SLAs, and support
  • Proprietary anti-deepfake or fraud datasets and ongoing model tuning
  • Legal/brand assurances (attestations, ICO/compliance support)

What remains hard

  • Product polish and ongoing maintenance
Read the build prompt

First-year cost

No published price

HealthCAPTCHA does not publish a price we could read, so there is nothing to compare against. What building costs is below.

Money you would actually spend

Keep paying
—

Subscription price × seats × 12

Build it
—

AI build —APIs + hosting —

Time you would spend

—

—

What you would spend

What we assumed

The verdict above measures whether you could build it. This one is only about money.

Runnable build prompt

Not run yet
Build an embeddable client-side HealthCAPTCHA widget: use a static Node/Express host for demos and a client widget in plain JS that uses MediaPipe BlazePose or TensorFlow MoveNet in the browser for pose estimation. In scope: webcam permission UI, real-time squat counting (5 squats), signed short-lived verification token returned to the host page (HMAC with server-held key), accessible fallbacks (arm raises/head nods), anti-replay nonce and timestamp, CI tests for core functions, and basic end-to-end integration example page. Out of scope: server-side enterprise dashboard, analytics pipeline, paid billing, and advanced deepfake detection beyond client-side liveness heuristics. Include error handling for camera denial, low light, and model load failures, unit tests for counter logic, and an integration test that verifies token acceptance on the example host.
How we checked2 sources · 3/3 runs agreed · evidence score 88

How the score was reached

  • Build verdict base78
  • An open-source build was found+5
  • 2 cited sources+1
  • 3/3 assessment runs agreed+4
  • Evidence score88

The base comes from the verdict. Everything under it is a check that either happened or did not, and each one is a fact frozen in this record rather than a judgement made at render time - so the same evidence always produces the same number.

How scoring works →

Cited sources · 2

Every page the run actually retrieved.

Integrity checks

What held up, and what did not.

✓ 3 independent runs, one answer✓ Citations limited to fetched pages! 1 moat recorded