WPBruiser (formerly GoodBye Captcha) is an anti-spam and security plugin based on algorithms that identify spam bots without any annoying and hard to read captcha images.
WPBruiser completely eliminates spam-bot signups, spam comments, even brute force attacks, the second you install it on your Wordpress website. It is completely invisible to the end-user - no need to ever fill out a Captcha or other "human-detection" field ever again - and it just works!
Unlike other anti-spam plugins, which detect spam comments and signups after the fact and move them to your spam folder, which you then have to delete - using up not only your website's resources, but your time as well, WPBruiser prevents the bots from leaving spam in the first place. The result is that your site is not only spam free, it's faster and more secure.
In addition, WPBruiser is completely self-contained and does not need to connect to any outside service. Your logins remain yours, 100%.
WPBruiser fights Brute Force attacks and eliminates spam-bots on comments, signup pages as well as login and password reset pages. At the click of a button, you can decide which forms to protect.
Summary of WPBruiser features
- Standard WordPress Login form integration
- Standard WordPress Register form integration
- Standard WordPress Forgot Password form integration
- Standard WordPress Comments form integration
- Ability to set the maximum number of characters for each comment field
- Logging with the ability to enable/disable it
- Automatically Block IP Addresses
- Automatically purge logs older than a certain number of days
- Manually white-list trusted IP Address (IPV4 and IPV6)
- Manually block/unblock IP Addresses (IPV4 and IPV6)
- Properly detects client IP Address when using CloudFlare, Incapsula, Cloudfront, RackSpace, Sucuri CloudProxy, AWS ELB
- Provides statistics, reports, maps and charts with all blocked spam attempts
- No requests to external APIs
- Can be switched to "Test Mode" - for testing
- Compatible with WordPress Multisite - network admin interface ready
- Compatible with cache plugins (WP Super Cache, W3 Total Cache, ZenCache, WP Fastest Cache and others)
- Invisible for end users (works in the background)
- Does not affect page loading times
Brute Force Protection
- Automatically detects Brute Force attacks
- Ability to automatically block IP Addresses
- Prevents User Enumeration
- Ability to block most dangerous IP addresses involved in brute force attacks
- Ability to block most dangerous Anonymous Proxy IP addresses including TOR Networks, TOR Nodes and TOR Exit Points
- Ability to Completely Disable XML-RPC service - it seamlessly works with Jetpack plugin activated
- Ability to Disable XML-RPC Pingbacks
- Email notifications when a Brute Force Attack is detected
WPBruiser Available Extensions
WPBruiser is integrated with the most popular plugins
Contact Forms Extensions
Membership Extensions
eCommerce Extensions
Email Subscriptions Extensions
View all WPBruiser Extensions
WPBruiser is also integrated with the following plugins:
Technical support
If you notice any problems by using this plugin, please notify us and we will investigate and fix the issues. Ideally your request should contain: URL of the website (if your site is public), Php version, WordPress version and all the steps in order to replicate the issue (if you are able to reproduce it somehow)
Donate
If you find this plugin useful, please consider making a small
donation. Thank you
3.1.43
- Fixed PHP 7.4 warnings
- Refreshed Country IPs
- Refreshed WebAttackers IPs
- Refreshed Proxy IPs
- Refreshed Incapsula, Amazon and Cloudflare trusted IPs ranges
3.1.40
Fixes
- Ajax call javascript error
3.1.39
- Refreshed Country IPs
- Refreshed WebAttackers IPs
- Refreshed Proxy IPs
- Refreshed Incapsula, Amazon and Cloudflare trusted IPs ranges
3.1.38
Fixes
- Compatibility with Mailchimp for WordPress
-
PHP 7.4 warnings
Improvements
-
Refreshed Country IPs
- Refreshed WebAttackers IPs
- Refreshed Proxy IPs
- Refreshed Incapsula, Amazon and Cloudflare trusted IPs ranges
3.1.37
Improvements
- Refreshed Country IPs
- Refreshed WebAttackers IPs
- Refreshed Proxy IPs
- Refreshed Incapsula, Amazon and Cloudflare trusted IPs ranges
3.1.36
Fixes
- Compatibility with latest JetPack Contact Form
3.1.35
Improvements
- Refreshed Country IPs
- Refreshed WebAttackers IPs
- Refreshed Proxy IPs
- Refreshed Incapsula, Amazon and Cloudflare trusted IPs ranges
3.1.34
Improvements
- Refreshed Incapsula, Amazon and Cloudflare trusted IPs ranges
3.1.33
Fixes
- The plugin does not have a valid header issue
3.1.32
Improvements
- Refreshed Incapsula, Amazon and Cloudflare trusted IPs ranges
3.1.31
Improvements
- Refreshed Country IPs
- Refreshed WebAttackers IPs
- Refreshed Proxy IPs
- Refreshed Incapsula, Amazon and Cloudflare trusted IPs ranges
3.1.30
- Fixed fatal error when using PHP 5.3.x
3.1.29
Refreshed Incapsula, Amazon and Cloudflare trusted IPs ranges
3.1.28
Fixes
3.1.27
Improvements
- Refreshed Incapsula, Amazon and Cloudflare trusted IPs ranges
3.1.26
Improvements
- Refreshed Country IPs
- Refreshed WebAttackers IPs
- Refreshed Proxy IPs
- Compatibility with WordPress 5.1
3.1.22
3.1.21
Improvements
- Refreshed Country IPs
- Refreshed WebAttackers IPs
- Refreshed Proxy IPs
3.1.19
- Fixed compatibility with UM 2.X
3.1.18
- Fixed PHP 7.1.x warnings and compatibility with PHP 7.2
3.1.15
Fixes
3.1.14
Improvements
3.1.12
Fixes
-
PHP7 warnings
Improvements
-
Refreshed Country IPs
- Refreshed WebAttackers IPs
- Refreshed Proxy IPs
3.1.11
3.1.9
3.1.6
Improvements
-
Added integration with Ultra Community Membership plugin
Fixes
-
A plugin vulnerability reported by Wordfence team
3.1.4
Fixes
-
PHP7 warnings
Improvements
-
Refreshed Country IPs
- Refreshed WebAttackers IPs
- Refreshed Proxy IPs
3.1.3
Improvements
- Prevent oEmbed and WP Rest API user enumeration.
3.1.1
Fixes
- Compatibility with MailChimp for WP version 4.0.4 and up.
3.1
Fixes
- Compatibility with MailChimp for WP version 4.0.6 and up
- Compatibility with WordPress MU Domain Mapping plugin
- Fixed Password reset protection for WooCommerce
- Refreshed Country IPs
3.0.15
Improvements
- Compatibility with Avada theme
- Refreshed Country IPs
- Refreshed WebAttackers IPs
- Refreshed Proxy IPs
3.0.14
Fixes
- Fixed the issue when protection for WooCommerce registration form was conflicting with protection for Standard WordPress registration
3.0.12
- Refreshed Country IPs
- Refreshed WebAttackers IPs
- Refreshed Proxy IPs
Improvements
- Improved loading speed
- Improved detection algorithm
3.0.11
Improvements
- Improved proxy detection feature
3.0.10
- Refreshed Country IPs
- Refreshed WebAttackers IPs
- Refreshed Proxy IPs
Additions
- Ability to register trusted proxy headers
- Email Notification when a user with Admin Capabilities has signed in
New Premium Extensions
3.0.9
Fixing repository issues
3.0.7
- Refreshed Country IPs
- Refreshed WebAttackers IPs
- Refreshed Proxy IPs
3.0.6
Fixed corrupted files from WordPress Repository
3.0.5
3.0.4
Fixes
3.0.3
Fixes
- Compatibility with Query Monitor plugin
- Block Web Attackers IPs and Block Anonymous Proxy IPs options are getting deactivated
- Refreshed WebAttackers IPs
- Refreshed Proxy IPs
3.0.2
- Removed jQuery dependency
- Added protection for Ultimate Member Modal Login
- Compatibility with WordPress 4.5 for Max Comments Fields Length
- Refreshed Country IPs
- Refreshed WebAttackers IPs
- Refreshed Proxy IPs
3.0.1
Improvements
- Ability to set up the Fields Maximum Length for each comment form field
- Added Extensions page
- Added
languages
folder to support translations
- Added a new filter
wpbruiser-scripts-in-head
- to explicitly render WPBruiser's script in head or footer
3.0
- Added IPv4 to country lookup
Introducing premium extensions
2.2.2
- Removed the MaxMind GeoIP Databases due to the licensing terms violation
2.2.1
- Fixed MySql error reported by WHSajid
2.2.0
- Fixed issue when WPBruiser blocks post requests from some Amazon proxy servers
- Fixed blocked content extra slashes
- Improved Brute Force attacks detection
- Refreshed dangerous IPs lists
2.1.0
- Now GoodByeCaptcha is WPBruiser
- Fixed Disable Trackbacks/Pingbacks issue reported by sixer
- Added compatibility with WP Deferred JavaScripts plugin
- Fixed warning notice reported by Sucuri
2.0.1
Fixes
- Compatibility with Login With Ajax plugin
- Compatibility with Google Apps Login plugin
- Compatibility with WP-Rocket plugin
- Compatibility with Autoptimize plugin
- Compatibility with Theme My Login plugin
2.0
Additions
- New admin interface
- Network admin interface
- Brute-Force protection
- White-list IPs
- Black-list IPs
- WordPress tweaks