| 开发者 | byabdalla |
|---|---|
| 更新时间 | 2026年9月29日 07:25 |
| PHP版本: | 7.4 及以上 |
| WordPress版本: | 7.1 |
| 版权: | GPLv2 or later |
| 版权网址: | 版权信息 |
wp-admin/admin-post.php or wp-admin/admin-ajax.php are picked up automatically by the generic adapter.
The Vault
Blocked submissions are stored encrypted for 30 days (configurable). Review them in the admin: see what was blocked, which page it was submitted from, and which inbox the notification was headed to. Mark false positives as legitimate and forward them by email in a couple of clicks — the sender's address becomes the Reply-To, so answering in your mail client reaches the person who filled the form. The forwarded email treats the submission as untrusted: links and addresses in it are broken up so they cannot be clicked by accident. Passed (legitimate) submissions are logged too, so you can audit both sides of every decision.
Self-learning
When you mark a Vault entry as "spam" the engine extracts the sender's address, the email domain, the domains of links in the message and distinctive phrases (and the hashed IP address), and stores them in a learned-rules table with a score modifier. Marking an entry as legitimate does the opposite: that sender and the matching signals get negative weights. Future submissions matching those signatures get extra points, automatically. Auto-confirmed rules from repeat offenders are added too. Decay over time keeps the rule set fresh. Review, re-weight, deactivate or delete every learned rule from the Learned Rules screen.
Privacy
sha256(site_secret + "|" + ip), never as the address itself. The secret is kept in the same database, so the hash stops anyone from simply reading an address; someone with a full copy of the database could still work an IPv4 address out by trying every possible one.formghost folder to wp-content/plugins/ (or install through the Plugins screen).Yes. All nine layers, the Vault, the self-learning system, Ghost Response — everything ships in the free plugin. There is no Pro tier and no license key.
No. FormGhost is invisible — no CAPTCHA, no extra fields visible to humans, no JavaScript prompts. The honeypot fields are hidden via multiple CSS techniques and aria-hidden. The timing token and proof-of-work fields are injected by JavaScript with no UI footprint.
Partly. The WordPress comment, login, registration and password-reset forms work without JavaScript as long as "Allow visitors without JavaScript" is on (the default). Forms from form plugins need JavaScript: FormGhost adds its checks to them with JavaScript, so a submission without it looks like a bot and is held. Turning the setting off makes the core forms strict too.
No — FormGhost has no servers of its own and its spam detection never leaves your site. The only outbound calls the plugin can make are the optional, off-by-default Turnstile / hCaptcha token verification and the DNS MX lookup, both described under "External services" below.
Choose which surfaces to protect (comments, login, registration, contact forms, WooCommerce, password reset) and a sensitivity profile — Low, Medium or High. FormGhost applies a curated recipe of timing thresholds, proof-of-work difficulty and pattern aggressiveness. You can fine-tune everything afterwards in Settings, and re-run the wizard any time.
Open the Vault, click Legit on the entry, then Send and Send email to forward it to the inbox it was originally headed to. FormGhost learns from your correction: that sender's address and the matching domains and phrases get negative weights, so similar messages are less likely to be held.
Yes. The Vault detail view shows the score, the layer that held it and its reason code, the page the form was submitted from, and the inbox the notification was headed to.
Yes. The honeypot CSS is inline, and the timing token, proof-of-work challenge and Behavioral layer nonce are fetched fresh from a no-cache endpoint when the page loads, so cached pages still work. Heavy page caching does not weaken FormGhost.
Yes. Everything that must be fresh is fetched after the page loads, and the plugin sends nocache_headers() on its own AJAX endpoint. On a Cloudflare-fronted site, also see the rate-limit question below.
Add this line to wp-config.php, above the line that says "That's all, stop editing!":
define( 'FORMGHOST_DISABLE', true );
FormGhost then does nothing at all — no checks, no scripts, no hooks — while staying activated, so your settings are kept. Log in, fix the setting that caused the problem, and remove the line to switch FormGhost back on.
On the login form the CAPTCHA is a bot deterrent, not an authentication control. If it cannot be checked — the widget did not load, the provider could not be reached, or it rejected your secret key — FormGhost lets the login continue instead of locking you out of your own site. Every other FormGhost check and the login rate limit still apply to that attempt, so a bot that simply leaves the CAPTCHA out gains nothing it could use against an account it does not already have the password for. A token the provider actually rejects still blocks the login. When a successful login gets through unchecked, or the provider cannot be reached, or your secret key is rejected, FormGhost shows an admin notice so a broken setup does not go unnoticed. Comments, registration and password reset do not fail open.
Only failed logins count. By default, one IP address can fail 10 times on the same account, and 30 times across all accounts, within 15 minutes. After that FormGhost blocks further login attempts from that address until the 15 minutes are up — the correct password included, so a password-guessing bot gets nowhere. A successful login clears that account's failures, so someone who mistypes a few times still gets in. Developers can change the numbers with the ratelimit_limits setting.
Not on Cloudflare. With "Trust reverse-proxy headers" off, WordPress sees Cloudflare's addresses instead of your visitors', and many visitors share each one. FormGhost recognises Cloudflare's published addresses and uses the visitor address Cloudflare reports for the login rate limit, so one person's typos do not lock others out. Behind other proxies — nginx, a load balancer, Docker — FormGhost cannot safely trust the forwarded address on its own, so everyone behind the proxy shares one limit until you act. In both cases wp-admin shows a notice: turn on "Trust reverse-proxy headers" under FormGhost → Settings → General, which also lets every other check tell your visitors apart.
In a {prefix}formghost_vault table you control, encrypted with AES-256-GCM against a per-site secret stored in formghost_site_secret. Default retention is 30 days; configurable; uninstall removes the table entirely.
Run the wizard once and enable the registration / WooCommerce scopes that match your attack surface, with the Medium sensitivity profile. Layers 4 (Behavioral), 5 (Rate limit) and 6 (Email) add the most uplift against modern bots and are on by default.
formghost/fields/internal_keys, formghost/fields/context_keys and formghost/learning/never_learn_domains; new FormGhost_Settings::sanitize_all(); the formghost/vault/created action now receives the payload as stored.define( 'FORMGHOST_DISABLE', true ); in wp-config.php turns FormGhost off completely without deactivating it. See the FAQ.hxxps[:]// example[.] com) so nothing can be clicked by accident, and FormGhost's own hidden fields are no longer shown.formghost/skip_form filter, so a disabled FormGhost never intercepts an Elementor submission.wp_doing_ajax(), $pagenow) instead of matching the request URI, so non-standard wp-admin locations work.<style> blocks (dashboard widget, honeypot) moved to enqueued stylesheets.load_plugin_textdomain() call were removed.formghost/engine/rest_browser_form_types for other JS-driven REST forms.missing_after_js).