plugin-icon

Spambargo – Anti-Spam for Forms & Comments

Door idoa89·
Local anti-spam protection for contact forms, comments and WooCommerce using signed timing, honeypots, content checks and rate limiting.
Versie
2.4.8
Laatst bijgewerkt
Aug 6, 2026

Spambargo puts automated spam under embargo across Contact Form 7, Elementor Pro Forms, Ninja Forms, JetFormBuilder, WooCommerce registration and checkout, WooCommerce Checkout Blocks, WordPress comments, and eligible generic lead forms.

Spambargo uses a layered, local-first architecture designed to reduce automated spam while minimizing false positives:

  • Native integrations validate once at the server, avoiding duplicate checks and duplicate rate-limit increments.
  • All administration and visitor-facing strings use the WordPress translation API. WordPress.org language packs select translations from the active locale.
  • The dashboard and the most useful protection settings share one simple screen. Technical controls remain available under Advanced settings.
  • Simple recommendation buttons add optional starting values without removing existing administrator entries.
  • Generic lead forms use a best-effort browser/AJAX pre-check only when no native integration exists; direct server POST requests require a native or custom server-side integration.
  • Signed, stateful behavior tokens measure elapsed time on the server instead of trusting browser-provided time fields.
  • Signed tokens and correct challenges allow a small bounded retry window so unrelated field validation errors do not lock out real users.
  • The optional math challenge is rendered, bound to the form/client context, expires, and limits failed attempts.
  • Rate limiting uses atomic database counters, fixed minute/hour windows, and configurable IPv6 prefix grouping (default /64).
  • Forwarded IP headers are ignored unless the direct peer is listed as a trusted proxy.
  • IPv4 and IPv6 CIDR lists are supported.
  • Optional browser correlation uses coarse attributes plus a random per-session identifier, a signed token and sessionStorage. Canvas and WebGL fingerprinting are not used.
  • Log cleanup runs daily. CSV export streams in batches and neutralizes spreadsheet formulas.
  • Email/webhook alerts are batched asynchronously. Webhooks use safe HTTP requests, require a 2xx response and can be HMAC-signed.

Supported integrations

  • Contact Form 7 (native spam filter)
  • Elementor Pro Forms (native validation)
  • Ninja Forms
  • JetFormBuilder (before form actions)
  • WooCommerce classic registration and checkout
  • WooCommerce Checkout Blocks (server-side Store API checks; behavior token and math challenge are not applied to Blocks)
  • WordPress comments
  • Generic browser-submitted lead forms containing email, phone or textarea fields (client-side AJAX pre-check only)

Forms can be explicitly protected with data-wpas-protect="1" or excluded with data-wpas-ignore="1".

Privacy

Spambargo does not send data to a service operated by the plugin author. All checks run on the site server by default.

When a submission is blocked, the plugin may store the IP address, email address, form identifier, block reason, optional content snippet and optional verified fingerprint hash. The content snippet can be disabled and logs are cleaned according to the configured retention period.

Optional browser correlation collects coarse screen-size buckets, timezone, language, platform, CPU-core count and touch capability. The server combines them with a random per-session identifier and returns a signed hash token stored in browser sessionStorage for up to eight hours. Raw attributes are not written to the spam log. Administrators should update their privacy notice as required by applicable law. Spambargo integrates with WordPress personal-data export and erasure tools and adds suggested text to the Privacy Policy Guide.

When a webhook URL is configured, batched blocked-submission data is sent to that administrator-selected endpoint. This is the only optional external data transfer performed by the plugin.

Gratisvoor betaalde abonnementen
Door te installeren, ga je akkoord met de Servicevoorwaarden van WordPress.com en de voorwaarden voor plugins van derden.
Getest tot
WordPress 7.0.2
Deze plugin kan worden gedownload, zodat je hem op je kan gebruiken.