Hiawatha already supports partial downloads (for static files only).
The captcha is only an extra check. The real anti-spam filtering is done by the server. I receive a few hunderd spam messages per day. Only a few message per month get passed this filter. So, there is no need to update it.
And as you can see, this forum is well protected. XSS won't work here