{"id":300842,"date":"2026-08-06T08:47:49","date_gmt":"2026-08-06T08:47:49","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/anti-spam-enough-is-enough\/"},"modified":"2026-08-11T11:24:23","modified_gmt":"2026-08-11T11:24:23","slug":"spambargo","status":"publish","type":"plugin","link":"https:\/\/ms.wordpress.org\/plugins\/spambargo\/","author":14816083,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"2.4.9","stable_tag":"2.4.9","tested":"7.0.3","requires":"6.2","requires_php":"7.4","requires_plugins":null,"header_name":"Spambargo: Anti-Spam for Forms & Comments","header_author":"Ido Aviv","header_description":"Local anti-spam protection for forms, comments and WooCommerce without mandatory third-party CAPTCHA services.","assets_banners_color":"","last_updated":"2026-08-11 11:24:23","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"https:\/\/profiles.wordpress.org\/idoa89\/","rating":0,"author_block_rating":0,"active_installs":50,"downloads":261,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"2.4.8":{"tag":"2.4.8","author":"idoa89","date":"2026-08-09 15:11:20"},"2.4.9":{"tag":"2.4.9","author":"idoa89","date":"2026-08-11 11:24:23"}},"upgrade_notice":{"2.4.9":"<p>Refreshes the plugin name and descriptions for clarity. Protection logic, defaults and stored data are unchanged.<\/p>","2.4.8":"<p>Uses WordPress.org language packs and validates the webhook signing secret without altering printable characters.<\/p>"},"ratings":[],"assets_icons":{"icon-256x256.png":{"filename":"icon-256x256.png","revision":3639337,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":[],"assets_blueprints":{},"all_blocks":[],"tagged_versions":["2.4.8","2.4.9"],"block_files":[],"assets_screenshots":[],"screenshots":[]},"plugin_section":[],"plugin_tags":[2656,166108,107,1154,2419],"plugin_category":[44,54],"plugin_contributors":[274609],"plugin_business_model":[],"class_list":["post-300842","plugin","type-plugin","status-publish","hentry","plugin_tags-anti-spam","plugin_tags-bot-protection","plugin_tags-comments","plugin_tags-contact-forms","plugin_tags-spam-protection","plugin_category-discussion-and-community","plugin_category-security-and-spam-protection","plugin_contributors-idoa89","plugin_committers-idoa89"],"banners":[],"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/spambargo\/assets\/icon-256x256.png?rev=3639337","icon_2x":"https:\/\/ps.w.org\/spambargo\/assets\/icon-256x256.png?rev=3639337","generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p>Spambargo is a simple anti-spam plugin for WordPress site owners, agencies and website builders. It helps block unwanted form submissions, comments and WooCommerce spam without requiring a third-party CAPTCHA service or complicated setup.<\/p>\n\n<p>It works with Elementor Pro Forms, Contact Form 7, JetFormBuilder, Ninja Forms, WooCommerce registration and checkout, WooCommerce Checkout Blocks, WordPress comments, and eligible generic lead forms.<\/p>\n\n<p>Start with the recommended settings, add common spam rules with one click, and adjust only what your site needs. The most useful controls are shown first, while technical options stay under Advanced settings.<\/p>\n\n<h4>What can Spambargo block?<\/h4>\n\n<ul>\n<li>Messages containing blocked words or phrases.<\/li>\n<li>Messages with too many links.<\/li>\n<li>Disposable and suspicious email addresses.<\/li>\n<li>Forms submitted unrealistically fast.<\/li>\n<li>Repeated submissions from the same visitor.<\/li>\n<li>Specific email addresses and email domains.<\/li>\n<li>Specific IP addresses and IPv4 or IPv6 network ranges.<\/li>\n<li>Messages written mostly in capital letters.<\/li>\n<li>Clearly suspicious phone number patterns when the optional phone check is enabled.<\/li>\n<li>Additional automated spam using optional browser-token and math-challenge checks.<\/li>\n<\/ul>\n\n<h4>Supported forms and integrations<\/h4>\n\n<ul>\n<li>Elementor Pro Forms.<\/li>\n<li>Contact Form 7.<\/li>\n<li>JetFormBuilder.<\/li>\n<li>Ninja Forms.<\/li>\n<li>WooCommerce registration and classic checkout.<\/li>\n<li>WooCommerce Checkout Blocks.<\/li>\n<li>WordPress comments.<\/li>\n<li>Eligible generic HTML lead forms using a best-effort browser-side pre-check.<\/li>\n<\/ul>\n\n<p>Native integrations validate submissions on the server. Generic forms without a native integration use a browser-side pre-check and require a native or custom server-side integration for protection against direct POST requests.<\/p>\n\n<h4>Simple to set up<\/h4>\n\n<ul>\n<li>Dashboard statistics and the main protection settings are available on one screen.<\/li>\n<li>Blocked words and phrases, link limits, email checks and automatic limits appear first.<\/li>\n<li>Recommendation buttons can add useful starting values without deleting existing settings.<\/li>\n<li>Advanced technical controls stay collapsed until you need them.<\/li>\n<li>A searchable spam log helps you understand what was blocked and why.<\/li>\n<\/ul>\n\n<h4>How protection works<\/h4>\n\n<p>Spambargo combines several lightweight checks instead of relying on a single CAPTCHA:<\/p>\n\n<ul>\n<li>Literal blocked-word and phrase rules with case-insensitive matching.<\/li>\n<li>Link-count and email-pattern checks.<\/li>\n<li>Honeypot and minimum submission-time checks.<\/li>\n<li>Atomic minute and hourly rate limits with IPv6 network grouping.<\/li>\n<li>Manual email, domain, IP and CIDR block lists.<\/li>\n<li>Optional phone validation, math challenge and temporary signed browser correlation token.<\/li>\n<li>Trusted-proxy handling for forwarded visitor IP addresses.<\/li>\n<li>Automatic log retention, streamed CSV export and batched email or webhook notifications.<\/li>\n<\/ul>\n\n<p>Spambargo runs its checks locally on the WordPress site by default and does not require a CAPTCHA service operated by a third party.<\/p>\n\n<h3>Privacy<\/h3>\n\n<p>Spambargo does not send data to a service operated by the plugin author. All checks run on the site server by default.<\/p>\n\n<p>When a submission is blocked, the plugin may store the IP address, email address, form identifier, block reason, optional content snippet and optional verified fingerprint hash. The content snippet can be disabled and logs are cleaned according to the configured retention period.<\/p>\n\n<p>Optional browser correlation collects coarse screen-size buckets, timezone, language, platform, CPU-core count and touch capability. The server combines them with a random per-session identifier and returns a signed hash token stored in browser sessionStorage for up to eight hours. Raw attributes are not written to the spam log. Administrators should update their privacy notice as required by applicable law. Spambargo integrates with WordPress personal-data export and erasure tools and adds suggested text to the Privacy Policy Guide.<\/p>\n\n<p>When a webhook URL is configured, batched blocked-submission data is sent to that administrator-selected endpoint. This is the only optional external data transfer performed by the plugin.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>spambargo<\/code> folder to <code>\/wp-content\/plugins\/<\/code>.<\/li>\n<li>Activate the plugin.<\/li>\n<li>Open Spambargo. The dashboard and the main protection settings appear together on the first screen.<\/li>\n<li>Test every important form in a staging environment before enabling strict signed-token mode, the math challenge, phone validation or browser correlation.<\/li>\n<li>If the site is behind a reverse proxy or CDN, add only the actual proxy IPs\/CIDRs to Trusted Proxies before relying on forwarded client IPs.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20the%20plugin%20intercept%20every%20form%3F\"><h3>Does the plugin intercept every form?<\/h3><\/dt>\n<dd><p>No. Native integrations are never pre-validated by the universal AJAX checker. Generic interception targets likely lead forms and can be controlled with CSS selectors or data attributes. This generic mode is a browser-side, best-effort pre-check and cannot stop a bot that posts directly to a custom form handler; server-enforced protection requires one of the listed native integrations or custom server-side validation.<\/p><\/dd>\n<dt id=\"can%20visitors%20without%20javascript%20submit%3F\"><h3>Can visitors without JavaScript submit?<\/h3><\/dt>\n<dd><p>By default, yes. The honeypot and server checks continue to work, while a missing behavior token is allowed. Administrators can enable strict token mode, which is stronger but requires JavaScript.<\/p><\/dd>\n<dt id=\"does%20checkout%20blocks%20support%20the%20math%20challenge%3F\"><h3>Does Checkout Blocks support the math challenge?<\/h3><\/dt>\n<dd><p>Not in this release. Checkout Blocks receive server-side identity, blacklist, content, phone and rate checks. Behavioral tokens and the visual math challenge are deliberately skipped because Blocks require a dedicated client-side extension-data integration.<\/p><\/dd>\n<dt id=\"how%20are%20blocked%20words%20and%20phrases%20matched%3F\"><h3>How are blocked words and phrases matched?<\/h3><\/dt>\n<dd><p>Each line is a separate literal rule. A single-word line blocks that complete word, not a longer word that merely contains it. A multi-word rule blocks only when all of its words appear in the same order, although other words or punctuation may appear between them. Matching is not case-sensitive. Regular expressions are not executed. One matching line is enough to block a submission.<\/p><\/dd>\n<dt id=\"what%20does%20the%20english%20spam%20recommendation%20button%20add%3F\"><h3>What does the English spam recommendation button add?<\/h3><\/dt>\n<dd><p>It adds an optional, intentionally strict list of common English spam terms covering gambling, pharmaceuticals, crypto, SEO outreach, adult content and similar messages. It is especially suitable for sites whose legitimate enquiries are mainly written in Hebrew. The list is never added automatically, does not replace existing entries and can be edited before saving.<\/p><\/dd>\n<dt id=\"are%20logs%20deleted%20automatically%3F\"><h3>Are logs deleted automatically?<\/h3><\/dt>\n<dd><p>Yes. A daily WordPress cron event removes entries older than the configured retention period and clears expired rate-limit counters.<\/p><\/dd>\n<dt id=\"what%20happens%20on%20uninstall%3F\"><h3>What happens on uninstall?<\/h3><\/dt>\n<dd><p>Data is preserved by default. Enable \u201cDelete all data when plugin is uninstalled\u201d before deleting the plugin to remove its tables and settings.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>2.4.9<\/h4>\n\n<ul>\n<li>Changed the plugin name punctuation to a colon for cleaner, consistent branding in WordPress Admin.<\/li>\n<li>Rewrote the short description to clearly name supported form integrations and key spam checks.<\/li>\n<li>Updated the dashboard title and related plugin-name strings for consistency.<\/li>\n<li>No spam-protection logic, defaults or stored data were changed in this release.<\/li>\n<\/ul>\n\n<h4>2.4.8<\/h4>\n\n<ul>\n<li>Removed bundled PO and MO files so translations are delivered through translate.wordpress.org language packs.<\/li>\n<li>Converted built-in visitor messages to the standard WordPress gettext API.<\/li>\n<li>Registered every setting with an explicit type and sanitization callback.<\/li>\n<li>Added a dedicated webhook-secret validator that preserves printable HMAC secrets exactly without exposing them in the interface.<\/li>\n<\/ul>\n\n<h4>2.4.7<\/h4>\n\n<ul>\n<li>Removed an unnecessary fclose() call from the streamed CSV export so the package passes WordPress Coding Standards.<\/li>\n<li>The php:\/\/output stream remains managed automatically by PHP at the end of the request.<\/li>\n<\/ul>\n\n<h4>2.4.6<\/h4>\n\n<ul>\n<li>Replaced the optional English recommendation preset with a strict, editable set of common gambling, pharmaceutical, financial, SEO outreach and adult-spam rules.<\/li>\n<li>Kept every recommended rule opt-in and stopped adding blocked-content rules automatically on new installations.<\/li>\n<li>Clarified that each line is an independent literal rule, matching complete words or ordered multi-word phrases without case sensitivity.<\/li>\n<li>Removed administrator-supplied regular-expression execution and bounded the text allowed between phrase terms.<\/li>\n<li>Fixed the zero-link setting so it blocks every message containing a link.<\/li>\n<li>Prepared signed fields for native integrations even when their forms contain password fields.<\/li>\n<li>Restricted webhook delivery to validated HTTPS endpoints.<\/li>\n<li>Localized the honeypot label, sanitized custom visitor messages defensively and refreshed the Hebrew translation files.<\/li>\n<\/ul>\n\n<h4>2.4.5<\/h4>\n\n<ul>\n<li>Removed dynamically interpolated SQL fragments from spam-log filtering and sorting queries.<\/li>\n<li>Prepared every log query with an explicit placeholder list and fixed replacement counts.<\/li>\n<li>Escaped WooCommerce Store API exception messages directly at the exception sink for static-analysis compatibility.<\/li>\n<\/ul>\n\n<h4>2.4.4<\/h4>\n\n<ul>\n<li>Resolved Plugin Check errors for prepared database queries, output handling and translator comments.<\/li>\n<li>Sanitized request inputs and removed discouraged runtime configuration and translation-loading calls.<\/li>\n<li>Added a conservative starter list of common spam phrases while preserving customized lists.<\/li>\n<\/ul>\n\n<h4>2.4.1<\/h4>\n\n<ul>\n<li>Clarified how blocked words and phrases are matched in the settings screen.<\/li>\n<li>Multi-word rules now require every word in the same order while allowing extra words between them.<\/li>\n<li>Expanded the safe local recommendation set without adding broad one-word rules.<\/li>\n<\/ul>\n\n<h4>2.4.0<\/h4>\n\n<ul>\n<li>Combined the dashboard and main protection settings on one screen.<\/li>\n<li>Moved technical controls into an accessible Advanced settings panel that is closed by default.<\/li>\n<li>Reordered the settings so blocked phrases, link limits, temporary email domains and automatic limits appear first.<\/li>\n<li>Rewrote field labels and explanations in clear English and Hebrew.<\/li>\n<li>Changed the recommended minimum submission time to 2 seconds and clarified that only faster submissions are blocked.<\/li>\n<li>Kept Spam Log and Tools as separate menu pages.<\/li>\n<\/ul>","raw_excerpt":"Block spam in Elementor, Contact Form 7, JetFormBuilder, Ninja Forms, WooCommerce and comments with keyword, link and email checks.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ms.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/300842","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ms.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/ms.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/ms.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=300842"}],"author":[{"embeddable":true,"href":"https:\/\/ms.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/idoa89"}],"wp:attachment":[{"href":"https:\/\/ms.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=300842"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/ms.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=300842"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/ms.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=300842"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/ms.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=300842"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/ms.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=300842"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/ms.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=300842"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}