Hey @everyone 
Big update on Turnstile for HivePress. The plugin from my original post has
been completely rewritten since v1, and after a full testing pass on a
live staging site with real challenge solves, I’m happy to call the new build
stable! 
Download it here! - (always the latest version, and you’ll now get any future updates in your WP dashboard):
What’s new since v1
Proper HivePress integration. The plugin now uses
HivePress’s own native captcha field system (the same three form filters core
uses for reCAPTCHA), so the widget is a genuine form field rather than injected
HTML. That means it works everywhere HivePress renders a form, including the
login, register and reset password modal pop-ups, with no blank widgets when you
switch between them.
One simple “Protected Forms” list. Open Settings >
Cloudflare Turnstile, expand the HivePress section and tick the forms you want
protected. The list is discovered from HivePress itself, so it automatically
includes captcha-ready forms from any extension you run: Login, Register,
Reset Password, Submit Listing and Report Listing from core, plus Confirm
Booking (Bookings), Claim Listing (Claim Listings), Dispute Order
(Marketplace), Send Message (Messages), Submit Request and Submit Offer
(Requests), and Write a Review / Reply to Review (Reviews).
All your Simple Cloudflare Turnstile settings apply automatically.
Keys, theme, size, language, appearance, failure message, whitelist rules and
the Cloudflare-down failsafe. Nothing to configure twice.
Automatic updates. The plugin now updates itself
from GitHub through the normal WordPress Plugins screen: update notices, a
“View details” changelog and one-click updates, plus a “Check for updates”
link on the plugin row.
Small-screen fix. Cloudflare draws its widget at a fixed width,
which could overflow narrow popups on small phones. The widget now scales to
fit, so it sits neatly inside the modal on any screen size.
Tested properly before this post. Every protectable form from
the official extensions, all six official themes, WordPress 7.0, caching and
JS-optimisation plugins (Autoptimize and SiteGround Speed Optimizer), and a
full staging pass over HTTPS, including the wrong-password retry case that
used to trip captcha plugins up.
Requirements and installing
New users: install and activate both plugins above, then this one. Enter
your keys under Settings > Cloudflare Turnstile, open the HivePress section at
the bottom of that page, tick the forms you want and save.
If you installed version 1 from this thread: update once by hand. Go to
Plugins > Add New > Upload Plugin, choose the zip from the link above and pick
“Replace current with uploaded” when WordPress offers it. Then open the
settings and tick your forms again (the selection format changed in the
rewrite). From this version on, updates arrive on your Plugins screen like any
other plugin.
A few things worth knowing
- If you also have HivePress’s built-in reCAPTCHA keys configured, protected
forms will show BOTH captchas and require both to pass. If you are switching
to Turnstile, remove the reCAPTCHA keys from HivePress settings first. The
plugin shows a warning if it spots this.
- If a caching or JS-optimisation plugin ever stops the widget appearing, add
challenges.cloudflare.com and turnstile-render.js to its “exclude from
delay/defer JavaScript” list. In my testing the popular ones needed no
exclusions at all.
- If Cloudflare itself has an outage, the plugin follows the Simple Cloudflare
Turnstile failsafe setting, so your forms behave exactly like the rest of
your site.
If you hit a problem, reply here with your theme and the form involved and
I’ll take a look. @kseniia - the original topic was closed, so if you wouldn’t mind merging this - and, if you could update the link in the OP, that would be amazing! 
Cheers,
Chris 
P.S. The plugin is free and always will be. If it saves your site from the
bots and you fancy keeping the community tools coming, you can buy me a coffee here 