Linux 软件免费装
Banner图

FormGhost

开发者 byabdalla
更新时间 2026年9月29日 07:25
PHP版本: 7.4 及以上
WordPress版本: 7.1
版权: GPLv2 or later
版权网址: 版权信息

标签

honeypot spam antispam gdpr captcha alternative

下载

1.2.6 1.2.4 1.2.5

详情介绍:

The spam never happened. FormGhost is a privacy-first WordPress antispam plugin that makes spam quietly disappear: bots are shown a fake success page and walk away believing they got through, while you never receive a thing. No CAPTCHA is shown unless you choose to add one, no data leaves your server unless you switch on that optional CAPTCHA, and what FormGhost keeps stays in your own database: held submissions encrypted for a limited time, IP addresses only as keyed hashes. Spam goes into the Vault. Real users never see anything. Every feature is free. There is no Pro version, no license key, no upsell. Why FormGhost How it works Every submission is checked by up to nine independent layers, plus an identity check that notices one mailbox sending under many names. Each layer adds to a spam score. A score of 50 or more is held, and a filled-in honeypot is held straight away. FormGhost then usually answers with a silent Ghost Response, so the bot never learns it was blocked.
  1. Honeypot — Daily-rotated, site-suffixed hidden fields. Different on every FormGhost site; resistant to "fill every field" bots.
  2. Timing — Encrypted submission timestamp. Submissions that arrive too fast (or with a replayed token) fail this layer.
  3. Proof-of-Work — Lightweight browser challenge solved by a WebWorker. Stops curl / wget / scripted submissions cold.
  4. Behavioral fingerprint — Mouse curvature, keystroke variance, scroll, focus and touch signals computed entirely in the browser. Only the resulting score is transmitted.
  5. Rate limiting — Per-IP limits for each kind of form (contact forms, comments, registration, WooCommerce, password reset) within a time window, a separate failed-login limit per account and per IP address, and whitelisting of single IPs or CIDR ranges.
  6. Disposable email detection — Curated disposable-domain blocklist (extensible with your own block/allow lists), optional MX heuristic.
  7. Content patterns — Casino / SEO / pharma phrase detection with a self-learning twist.
  8. WordPress hardening — Disable XML-RPC, harden the REST users endpoint, generic login errors, optional Application Passwords lockdown.
  9. Optional CAPTCHA — Turnstile / hCaptcha / ALTCHA on the core WordPress forms you choose (comments, login, registration, password reset) if you want a visible challenge as a last line of defence. Off by default.
Form plugin compatibility Built-in adapters for: Custom forms POSTing to wp-admin/admin-post.php or wp-admin/admin-ajax.php are picked up automatically by the generic adapter. The Vault Blocked submissions are stored encrypted for 30 days (configurable). Review them in the admin: see what was blocked, which page it was submitted from, and which inbox the notification was headed to. Mark false positives as legitimate and forward them by email in a couple of clicks — the sender's address becomes the Reply-To, so answering in your mail client reaches the person who filled the form. The forwarded email treats the submission as untrusted: links and addresses in it are broken up so they cannot be clicked by accident. Passed (legitimate) submissions are logged too, so you can audit both sides of every decision. Self-learning When you mark a Vault entry as "spam" the engine extracts the sender's address, the email domain, the domains of links in the message and distinctive phrases (and the hashed IP address), and stores them in a learned-rules table with a score modifier. Marking an entry as legitimate does the opposite: that sender and the matching signals get negative weights. Future submissions matching those signatures get extra points, automatically. Auto-confirmed rules from repeat offenders are added too. Decay over time keeps the rule set fresh. Review, re-weight, deactivate or delete every learned rule from the Learned Rules screen. Privacy

安装:

  1. Upload the formghost folder to wp-content/plugins/ (or install through the Plugins screen).
  2. Activate FormGhost on the Plugins screen.
  3. Run the one-time wizard that appears on activation — toggle the surfaces to protect and pick a sensitivity profile; FormGhost sets timing, proof-of-work and detection sensitivity to match.
  4. Done. Real users keep submitting; bots stop arriving.

屏幕截图:

  • The Vault — blocked, ghosted and passed submissions with the page they came from, the inbox they were headed to and whether they were delivered; forward a false positive to that inbox.
  • Settings — choose exactly where FormGhost runs; every layer is tunable.
  • Learned Rules — what FormGhost learned from your reviews and from spam it caught on its own; adjust or switch off any rule.
  • The wp-admin dashboard widget — key numbers right after login.

升级注意事项:

1.2.6 Privacy fix. Update now if FormGhost protects your WordPress comments: every earlier version stored commenters' IP addresses and browser details in plain text in the Vault, although IPs were documented as hashed only. 1.2.6 stops this and removes them from stored entries. 1.2.5 Update now if you switched on the CAPTCHA for login or comments: 1.2.4 rejects every login and comment while it is on, including your own login. Also adds the FORMGHOST_DISABLE emergency switch. 1.1.0 All features are now free. New passed-submissions view and wp-admin dashboard widget.

常见问题:

Is FormGhost really completely free?

Yes. All nine layers, the Vault, the self-learning system, Ghost Response — everything ships in the free plugin. There is no Pro tier and no license key.

Will it break my real forms?

No. FormGhost is invisible — no CAPTCHA, no extra fields visible to humans, no JavaScript prompts. The honeypot fields are hidden via multiple CSS techniques and aria-hidden. The timing token and proof-of-work fields are injected by JavaScript with no UI footprint.

Does it work without JavaScript?

Partly. The WordPress comment, login, registration and password-reset forms work without JavaScript as long as "Allow visitors without JavaScript" is on (the default). Forms from form plugins need JavaScript: FormGhost adds its checks to them with JavaScript, so a submission without it looks like a bot and is held. Turning the setting off makes the core forms strict too.

Does it send data to your servers?

No — FormGhost has no servers of its own and its spam detection never leaves your site. The only outbound calls the plugin can make are the optional, off-by-default Turnstile / hCaptcha token verification and the DNS MX lookup, both described under "External services" below.

How does the wizard configure my site?

Choose which surfaces to protect (comments, login, registration, contact forms, WooCommerce, password reset) and a sensitivity profile — Low, Medium or High. FormGhost applies a curated recipe of timing thresholds, proof-of-work difficulty and pattern aggressiveness. You can fine-tune everything afterwards in Settings, and re-run the wizard any time.

I marked a legitimate submission as blocked. What now?

Open the Vault, click Legit on the entry, then Send and Send email to forward it to the inbox it was originally headed to. FormGhost learns from your correction: that sender's address and the matching domains and phrases get negative weights, so similar messages are less likely to be held.

Can I see why a submission was held?

Yes. The Vault detail view shows the score, the layer that held it and its reason code, the page the form was submitted from, and the inbox the notification was headed to.

Does it work with caching plugins?

Yes. The honeypot CSS is inline, and the timing token, proof-of-work challenge and Behavioral layer nonce are fetched fresh from a no-cache endpoint when the page loads, so cached pages still work. Heavy page caching does not weaken FormGhost.

Is it compatible with WP Rocket / W3 Total Cache / Cloudflare?

Yes. Everything that must be fresh is fetched after the page loads, and the plugin sends nocache_headers() on its own AJAX endpoint. On a Cloudflare-fronted site, also see the rate-limit question below.

How do I switch FormGhost off if I cannot log in?

Add this line to wp-config.php, above the line that says "That's all, stop editing!": define( 'FORMGHOST_DISABLE', true ); FormGhost then does nothing at all — no checks, no scripts, no hooks — while staying activated, so your settings are kept. Log in, fix the setting that caused the problem, and remove the line to switch FormGhost back on.

Why does the login CAPTCHA let some logins through unchecked?

On the login form the CAPTCHA is a bot deterrent, not an authentication control. If it cannot be checked — the widget did not load, the provider could not be reached, or it rejected your secret key — FormGhost lets the login continue instead of locking you out of your own site. Every other FormGhost check and the login rate limit still apply to that attempt, so a bot that simply leaves the CAPTCHA out gains nothing it could use against an account it does not already have the password for. A token the provider actually rejects still blocks the login. When a successful login gets through unchecked, or the provider cannot be reached, or your secret key is rejected, FormGhost shows an admin notice so a broken setup does not go unnoticed. Comments, registration and password reset do not fail open.

How does the login rate limit work?

Only failed logins count. By default, one IP address can fail 10 times on the same account, and 30 times across all accounts, within 15 minutes. After that FormGhost blocks further login attempts from that address until the 15 minutes are up — the correct password included, so a password-guessing bot gets nowhere. A successful login clears that account's failures, so someone who mistypes a few times still gets in. Developers can change the numbers with the ratelimit_limits setting.

My site is behind Cloudflare. Does the rate limit lock out everyone at once?

Not on Cloudflare. With "Trust reverse-proxy headers" off, WordPress sees Cloudflare's addresses instead of your visitors', and many visitors share each one. FormGhost recognises Cloudflare's published addresses and uses the visitor address Cloudflare reports for the login rate limit, so one person's typos do not lock others out. Behind other proxies — nginx, a load balancer, Docker — FormGhost cannot safely trust the forwarded address on its own, so everyone behind the proxy shares one limit until you act. In both cases wp-admin shows a notice: turn on "Trust reverse-proxy headers" under FormGhost → Settings → General, which also lets every other check tell your visitors apart.

Where are blocked submissions stored?

In a {prefix}formghost_vault table you control, encrypted with AES-256-GCM against a per-site secret stored in formghost_site_secret. Default retention is 30 days; configurable; uninstall removes the table entirely.

I run a forum / membership / e-commerce site — what do you recommend?

Run the wizard once and enable the registration / WooCommerce scopes that match your attack surface, with the Medium sensitivity profile. Layers 4 (Behavioral), 5 (Rate limit) and 6 (Email) add the most uplift against modern bots and are on by default.

更新日志:

1.2.6 1.2.5 1.2.4 1.2.3 1.2.2 1.2.1 1.2.0 1.1.0 1.0.0