Linux 软件免费装
Banner图

Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms

开发者 MatthiasNordwig
更新时间 2026年8月4日 18:02
捐献地址: 去捐款
PHP版本: 7.1 及以上
WordPress版本: 7.0
版权: GPLv2 or later
版权网址: 版权信息

标签

recaptcha captcha spam anti-spam spam-protection

下载

2.1.3 2.2.2 5.1.1 1.1.1 5.1 5.2.0 3.6.4 2.1.4 4.1.1 3.6.5 1.0.1 1.1.0 3.6.9 3.8 3.8.1 4.0 3.5.7 1.3 1.4.1 1.4.2 2.0.3 2.0.4 2.0.5 2.1.1 2.1.2 2.1.0 2.0.2 2.1.5 2.3.2 2.3.3 3.5.2 2.4 2.4.1 2.5.1 3.0 3.0.1 3.0.2 3.0.3 3.0.5 3.0.7 3.0.8 3.1 3.2 3.3 3.4 3.5 3.5.1 1.2.1 2.2.1 2.5 3.5.4 3.5.5 3.5.6 3.5.8 1.0.0 1.4 2.5.2 3.6 2.0 3.0.4 1.2.0 2.0.1 3.7.2 3.7.3 3.0.6 3.5.3 3.6.3 3.6.6 3.6.7 3.6.8 1.4.3 3.6.10 2.3 3.7 1.0.2 2.2.0 2.3.1 3.6.1 3.6.2 3.7.1 4.1 4.1.2 5.0

详情介绍:

Spam protection your visitors never see. No image grids, no "I'm not a robot" checkbox, no puzzles, nothing to click. Your visitors just hit Send — while their browser silently solves a tiny cryptographic challenge (proof-of-work) in a few milliseconds. Real humans never notice. Mass-spam bots either fail the challenge or have to burn so much computing power per message that spamming your site stops being worth it. Every form, out of the box. WordPress logins, registrations and comments, WooCommerce checkout and reviews, and virtually every form plugin — Contact Form 7, Elementor Pro Forms, WPForms, Gravity Forms, Ninja Forms, Fluent Forms, Formidable and dozens more (full list below). One plugin protects all of them, and the most popular builders are detected and configured automatically on activation. Truly universal — not a list of integrations Most anti-spam tools protect only the form plugins they ship an integration for. If your builder is not on their list — or you use a hand-coded form, a theme's built-in form, or three different builders on one site — you are on your own. This plugin works differently: it recognizes submissions by their signature — the characteristic fields and actions of the request itself — instead of hooking into specific form plugins. That is why it covers any form: And because no integration code is involved, nothing breaks when your form builder updates. In practice that solves two everyday problems: Why "invisible" wins Every CAPTCHA interaction costs you real visitors: an extra click here, an unreadable image there, "select all traffic lights" on a phone screen — and the contact request or sale is gone. This plugin flips the deal: instead of making humans prove themselves, it makes the device pay. The visitor's browser proves it is a real, JavaScript-running client by doing a moment of invisible computation. Zero friction for people, real costs for bots. Self-contained and featherweight Everything runs on your own web server — there is no external service in the loop. That is not just a privacy nicety, it is an operational one: Why not just use ... And they all share one structural limit: they protect the forms they ship an integration for. This plugin protects the forms you actually have (see "Truly universal" above). Key features Setup Guide [vimeo https://player.vimeo.com/video/905897718] Works with WordPress: Login, Registration, Password Reset, Comments WooCommerce: Checkout, Login, Registration, Password Reset, Comments, Product Reviews Form and page builders: Elementor Pro Forms, Contact Form 7, Fluent Forms, Jetpack Forms, Divi Forms, WPForms, Forminator, Thrive Architect & Thrive Apprentice, Gravity Forms, Formidable Forms, Mailchimp for WordPress Forms, BuddyPress Registration Form, bbPress Create Topic & Reply Forms, Ultimate Member Forms, wpDiscuz Custom Comments Form, Easy Digital Downloads Forms, Paid Memberships Pro Forms, MemberPress Forms, WP-Members Forms, WP User Frontend Forms, CheckoutWC & Flux Checkout, Ninja Forms, Everest Forms, WS Forms, Quform, Otter Blocks, Typeform, NEX-Forms, Bit Form, Form Maker, Funnelforms, Mailjet, Jotform, Page Builder, Metform, Calculated Fields Form, JetFormBuilder, weForms, Responsive Contact Form Builder, Zoho Forms, Smart Forms, Kali Forms, Happyforms, ApplyOnline, Subscribe Forms, FormCraft, Advanced Forms, CRM Perks Forms, Tripetto, Formstack, BuddyForms, vcita, Easy Form Builder, SimpleForm Anything not on the list can be added in minutes with the built-in analysis modes — no code required.

安装:

  1. Install & activate the plugin via the WordPress Plugins page — protection starts immediately with balanced defaults, and popular form builders are configured automatically
  2. Watch the short setup video (see above) to understand the message inbox and the analysis modes
  3. After a few days, check the message inbox: real submissions arrive as messages, spam lands in the spam folder
  4. Using a custom or exotic form that was not recognized? Turn on direct analysis mode and add it with one click, straight from the live form
  5. (Optional) Decide how to treat spam: block it, deliver it flagged, or just collect it

屏幕截图:

  • The message inbox: real submissions and spam side by side — open any message to see exactly which fields were submitted
  • Direct analysis mode: teach the spam check a new form with one click, straight from the live page
  • Every option explained in place — no documentation hunting

升级注意事项:

5.2.0 Maintenance release — see the changelog for details. 5.1.1 Security release. Fixes three reported vulnerabilities (SQL injection and stored XSS in the admin message views) plus related access-control hardening. Update recommended for all sites. 5.1 Recommended for everyone. Stronger spam protection (gibberish detection, repeat-sender lock, adaptive re-challenge) and a fix for sites that flagged every submission. If forms misbehave right after updating, flush OPcache and any page/object cache once. 5.0 Major release: proof-of-work is now bound to single-use signed tokens (much stronger against replay bots), adaptive under-attack difficulty, redesigned settings page, live direct-analysis guide, and several security hardenings. Requires PHP 7.1+.

常见问题:

Does it actually work?

Yes. For the kind of spam that plagues almost every site — automated, mass-sent — the typical experience after activation is that it simply stops: every message now costs the sender real computing power, which breaks the economics of sending thousands of them. That result has held up across years of production use. And the protection is actively maintained: when a new generation of protocol-aware bots learned to reuse a solved challenge across many submissions, version 5.0 closed that route with single-use, signed tokens. For the rare rest — targeted spam written by humans — the flag-and-inbox workflow keeps you in control instead of promising magic.

Will my visitors notice anything?

No. There is nothing to see, click or solve. The proof-of-work runs in the background while the visitor fills in the form and is typically finished in milliseconds — long before they hit Send.

Do I need an account or API keys?

No. Unlike reCAPTCHA, hCaptcha or Turnstile there is no external service involved — no keys, no registration, no third-party scripts, no rate limits.

Will it slow down my site?

No. The plugin ships a few kilobytes of JavaScript, loads no external resources and causes no layout shift. The computation happens on the visitor's device in the background; the server-side check is a single fast lookup.

Does it work with caching plugins?

Yes. The challenge token is fetched via Ajax at runtime, so fully cached pages stay protected. One thing to know: right after installing or updating, clear your page cache once so the plugin's JavaScript is included everywhere.

Which forms are supported?

All public forms — including hand-coded and custom ones. The plugin recognizes submissions by their signature (the request's characteristic fields and actions) instead of integrating with specific form plugins, so it is not limited to a fixed list. WordPress core, WooCommerce and the several dozen builders listed above come pre-configured; any other form is added without code in under a minute via direct analysis mode: submit it once, click save.

What data is stored? Is it GDPR compliant?

Everything stays on your server: no cookies, no sessions, no tracking, no external requests. IP addresses are only stored as SHA-256 hashes, and password fields are never stored with saved messages. That means no consent banner is needed for the spam protection — friendly to GDPR (DSGVO, RGPD) and similar privacy laws.

Does it protect WooCommerce?

Yes: checkout, login, registration, password reset, comments and product reviews are covered out of the box.

What spam does it stop — and what not?

Every submission has to pay for itself with a small proof-of-work computation. This makes mass spam economically expensive and silently filters out low-effort bots — the vast majority of spam. Like any anti-spam solution (including CAPTCHAs), it cannot fully prevent targeted, low-volume spam sent by a determined human or a bot that invests real computing power per message; for those rare cases, use the flag-instead-of-block option and the spam inbox to keep an eye on what comes through.

Submissions are incorrectly treated as spam

  1. Right after installation this is usually a caching issue: the proof-of-work JavaScript is not yet included in cached pages. Clear the cache on your webserver (or caching plugin) and in your browser.
  2. JavaScript might crash due to an incompatibility with another plugin. Press F12 on the affected page and check the browser console for errors — and please report the issue in the support forum; such reports are usually addressed within a day.

Neither messages nor spam show up in the inbox

  1. Activate the Analysis mode
  2. Submit the affected form and look for the captured entry in the Analytic Box
  3. Open the entry and add it to the protection scope
  4. If the submission does not appear there either, please post in the support forum

After updating, (almost) every submission is flagged as spam

The protection works by having the visitor's browser silently solve a small puzzle before a form is submitted. If that puzzle is never solved, a genuine submission looks exactly like a bot, so it gets flagged. Right after an update there are three common reasons for this, all quick to rule out:

  1. Stale server code / OPcache. The update changed the database schema, but your server may still be running the previous version's PHP code from its OPcache — the two no longer match. Flush the OPcache (restart PHP-FPM, or use your host's "Flush OPcache" button), then clear any page/object cache. 5.1 also tries to do this automatically on update, but some hosts still need it done once by hand.
  2. A cached page serving the old script. If a full-page cache is serving pre-update HTML, browsers load the previous version's script against the new server. Purge your page cache (and CDN) once after updating.
  3. A reverse proxy / CDN without Trusted Proxies set. If your site sits behind Cloudflare, a load balancer or similar and the plugin sees the proxy's IP instead of the visitor's, the check cannot line up. Set your proxy's address under Settings → Trusted proxies.
To confirm which one it is: open the affected page, press F12 → Console, and look for a warning from "gdpr-recaptcha"; on the Network tab, check that the get_stamp request returns clean JSON (no PHP notice/HTML before it). Sharing that in the support forum pins it down immediately.

Problems with Borlabs Script Blocker

When you use the Borlabs Script Blocker to scan for JavaScript, the scan does not work properly while this plugin is active. Deactivate this plugin for the scan and reactivate it afterwards.

Still stuck?

  1. Check the browser console (F12) on the problematic page for messages
  2. Post in the support forum with as many details as possible — issues are usually fixed quickly
  3. If the protection does not work on a specific form, a short note with the form plugin's name is enough to get it looked at

更新日志:

5.2.0 5.1.1 Security release. Fixes the three reported vulnerabilities and, after a full internal review, several related hardenings across the message-management area. * Security (SQL injection): admin-defined spam-analysis patterns are now escaped before they are interpolated into the LIKE conditions of the message queries. Closes an authenticated (Editor+) SQL injection via the pattern key/value (CVE-2026-16094, CVE-2026-16146). * Security (stored XSS): the form "action" value shown on the Spam/Messages admin pages is now JavaScript-escaped inside the inline submit handlers, not only HTML-attribute-escaped, so a quote in a captured action can no longer break out into script (CVE-2026-16145). A second highlighting sink in the detail view that re-decoded escaped values is now built via DOM text nodes, so captured content can never execute there either. * Security (access control / CSRF): every message action — viewing, moving, deleting (including "delete all") and saving patterns / action lists — now verifies its nonce before acting and requires the manage_options capability. Previously the "delete all" path ran without a verified nonce or capability, and the whole message area was reachable with edit_pages. NOTE: managing captured messages is now limited to administrators. * Security (log injection): the Fail2Ban integration now strictly sanitises the login name and strips line breaks, so a crafted login can no longer forge log lines / ban arbitrary IPs; it also logs the validated client IP instead of the raw remote address. * Hardening: consistent unslashing/sanitising of admin-AJAX input; guards against malformed unauthenticated requests that could raise PHP errors on the spam-check path; and, on multisite, the Fail2Ban log path can only be set by super admins (with path-traversal rejected). 5.1 This release brings stronger anti-spam layers to every site, alongside important reliability fixes. * New: gibberish detection — obvious keyboard-mash and random-string submissions are recognised and filtered, language-neutrally, while legitimate codes (VAT ids, serials, order numbers, product names) are left untouched. * New: repeat-sender ("echo") lock — once a message is classified as spam, its core values (sender, linked domain, phone, long-text hash) are briefly remembered as one-way hashes with a short lifetime, so the same sender is caught again on any form and any IP. It can be switched off, and its remembered values reset, on the settings page; registered users' and admins' addresses are excluded so an injected spam mail can never lock them out of login or password reset. * New: an adaptive solve-time re-challenge makes implausibly fast (likely non-browser) solves pay more, without ever hard-blocking a genuine visitor. * New: form builders you activate AFTER installing the plugin are now covered automatically (previously only builders present at install time were). A one-time notice lets you review and confirm any that were already active but not yet covered — your own custom entries, and anything you removed, are never touched. * Fix: on a small number of sites, every submission could be flagged as spam. The browser-side puzzle is now resilient — a stray PHP notice, a byte-order mark or a proxy error page in the get_stamp response no longer aborts it, and if the request cannot be made at all it falls back to the token already embedded in the page. * Fix: a password field without a name attribute could abort the script's setup on some themes/builders; hardened so it can no longer break token injection into Ajax form submissions. * Fix: the challenge-renew timer is now clamped to a sane minimum, so an empty/zero "Time Window" option can no longer cause rapid background requests to admin-ajax. * Fix: the invisible token is no longer added to GET forms (e.g. a theme's search box), so searching no longer appends a long "gdpr_pow_token=..." to the URL. POST forms are unaffected and stay protected. * Compatibility: a third-party script that wraps fetch/XHR before the visitor first interacts is no longer overwritten by the plugin. * Hardening: after an update the plugin proactively invalidates the PHP OPcache for its own files, reducing the chance of old code running against the new database schema. On some hosts an OPcache flush / PHP-FPM restart may still be needed once — see the FAQ. 5.0 4.1.2 4.1.1 4.1 4.0 3.8.1 3.8 3.7.3 3.7.2 3.7.1 3.7 3.6.10 3.6.9 3.6.8 3.6.7 3.6.6 3.6.5 3.6.4 3.6.3 3.6.2 3.6.1 3.6