Security and privacy decision
HealthCAPTCHA
A competent developer can build a useful client-side squat CAPTCHA widget in about a week using existing in-browser pose models; the vendor adds polish, analytics, and enterprise features you would forfeit.
Visit website↗Not priced
No pricing page we fetched carried a figure, so there is nothing to compare against. The build side is still real.
$50one-off22 h to build
$0/mo1 h/mo upkeep
No published price to break even against.
Open-source builds that already do this
Every project below is open source and already does this job today. Fork one, self-host it, or take the parts you need - the build prompt further down assumes an empty file, and this is the shortcut past that. Licences differ; check the one on each card before you ship. All HealthCAPTCHA alternatives, with the arithmetic →
What a replacement has to do
- Embed a client-side webcam pose detector that counts squats and returns a signed verification token to the host site.
What it still won’t have
- Vendor-managed usability polish, A/B testing and analytics
- Enterprise integrations, SLAs, and support
- Proprietary anti-deepfake or fraud datasets and ongoing model tuning
- Legal/brand assurances (attestations, ICO/compliance support)
What remains hard
- Product polish and ongoing maintenance
First-year cost
No published price
HealthCAPTCHA does not publish a price we could read, so there is nothing to compare against. What building costs is below.
Money you would actually spend
Time you would spend
—
What you would spend
What we assumed
The verdict above measures whether you could build it. This one is only about money.
Runnable build prompt
Build an embeddable client-side HealthCAPTCHA widget: use a static Node/Express host for demos and a client widget in plain JS that uses MediaPipe BlazePose or TensorFlow MoveNet in the browser for pose estimation. In scope: webcam permission UI, real-time squat counting (5 squats), signed short-lived verification token returned to the host page (HMAC with server-held key), accessible fallbacks (arm raises/head nods), anti-replay nonce and timestamp, CI tests for core functions, and basic end-to-end integration example page. Out of scope: server-side enterprise dashboard, analytics pipeline, paid billing, and advanced deepfake detection beyond client-side liveness heuristics. Include error handling for camera denial, low light, and model load failures, unit tests for counter logic, and an integration test that verifies token acceptance on the example host.
How we checked
How the score was reached
- Build verdict base78
- An open-source build was found+5
- 2 cited sources+1
- 3/3 assessment runs agreed+4
- Evidence score88
The base comes from the verdict. Everything under it is a check that either happened or did not, and each one is a fact frozen in this record rather than a judgement made at render time - so the same evidence always produces the same number.
How scoring works →Cited sources · 2
Every page the run actually retrieved.
- official productHealthCAPTCHA — The Physical CAPTCHA That AI Can't Solve
- open sourceJ-Rios/TLG_JoinCaptchaBot
Integrity checks
What held up, and what did not.



