Artiman Guard protects WordPress and WooCommerce forms without sending CAPTCHA data or security reports to an external service.
Protection layers include:
- Local browser proof-of-work with a mathematical fallback.
- One-time signed challenges, dynamic honeypots and form timing checks.
- Local rate limiting and a managed IP blocklist.
- Registration firewall, one-time registration permits and account quarantine.
- Spam-username detection and registration-source monitoring.
- Internal/external link classification for comments, product reviews and form submissions.
- Writing-system checks with automatic site-language defaults and administrator overrides.
- Content-risk scoring for repetition, advertising language, gibberish, disposable email, suspicious domains, invalid phone numbers and duplicate submissions.
- Block, quarantine, suspicious and allow-with-flag decisions.
- Review queues for comments, Elementor Pro Forms and Gravity Forms.
- 404 scanner detection, sensitive-path protection and repeated-request blocking.
- Internal broken-link reports, redirect suggestions and crawl-budget reports.
- Soft-404 and suspicious-200 reporting.
- Internal-search and WooCommerce-filter noindex protection.
- WordPress login, registration, lost-password and comment protection.
- WooCommerce login, registration and product-review protection.
- Dedicated Elementor Pro Forms and Gravity Forms fields.
- A local Security Center for suspicious events and managed IP blocks.
- Persian translation and support for WordPress language packs.
Artiman Guard is designed to cooperate with WordPress Core, WooCommerce, Yoast SEO, Rank Math, AIOSEO and SEOPress. SEO directives owned by an active SEO plugin are not replaced.
Developer website:
https://artimanweb.com/
0.8.0
- Added internal and external link classification for WordPress comments, WooCommerce reviews, Elementor Pro Forms, Gravity Forms and compatible integrations.
- Added configurable handling for external links: moderation, spam or immediate blocking.
- Added trusted external-domain rules while keeping links to the current site and its subdomains safe.
- Added writing-system detection with automatic defaults based on the WordPress site language.
- Added custom Latin, Persian/Arabic, Cyrillic, Chinese, Japanese and Korean controls.
- Added configurable moderation, spam or blocking actions for clearly unexpected-language comments.
- Kept the optional comment-author website check disabled by default to reduce false positives.
- Applied existing repeated-abuse limits and managed IP blocking to the new content signals.
0.7.2
- Added provider-aware robots integration for WordPress, Yoast SEO and Rank Math.
- Deferred robots control to AIOSEO and SEOPress when either plugin is active.
- Added an allowlist for intentionally indexable WooCommerce filter URLs.
- Removed search and add-to-cart requests from generic crawl-trap classification.
- Limited automatic query cleanup to the WordPress
replytocom parameter and made cleanup opt-in after upgrade.
- Prevented high-confidence search crawler agents from being blocked for ordinary repeated 404 requests.
- Excluded sitemap, robots and standard icon paths from ordinary 404 blocking.
- Avoided blocking legitimate singular content and archive-like routes with generic sensitive words.
- Limited no-cache handling to sensitive or blocked scanner traffic.
- Paused automatic IP blocking when forwarding headers arrive from an untrusted proxy.
- Fixed Elementor editor previews and trusted-administrator submissions when the field is marked as required.
0.7.1
- Added a shared abuse counter and automatic blocking for repeated form failures, suspicious submissions and 404 requests.
- Added a managed IP blocklist with release and permanent-block actions.
- Stopped storing routine successful checks.
0.7.0
- Added a shared decision engine and administrator feedback to reduce false positives.
- Added one-time registration permits and quarantine for unverified public user creation.
- Suppressed notifications and feeds for locally quarantined submissions.
For the complete release history, see
changelog.txt.