| 开发者 | robertvahhi |
|---|---|
| 更新时间 | 2026年9月23日 07:27 |
| PHP版本: | 7.2 及以上 |
| WordPress版本: | 7.0 |
| 版权: | GPLv2 or later |
| 版权网址: | 版权信息 |
No. The plugin protects your forms the moment you activate it, on the anonymous free tier. An account only adds analytics and higher limits.
A browser verification token, your site host name (or your secret key if you connect an account), and standard HTTPS request metadata go to the TrustSig Edge service. The "External services" section above has the full disclosure, including links to the Terms of Service and Privacy Policy.
In Challenge mode, the default, a visitor whose token is missing sees a brief "please wait" page that re-verifies the browser and then continues the original request on its own. Monitor mode never blocks. Enforce mode is the strictest and can block visitors who have JavaScript disabled.
Yes. Forms are signed with a server-issued nonce and the SDK fills in the token client-side, so cached pages stay protected.
By default, yes: the check runs once when a protected page loads, so the token is ready before any submission. If you would rather not verify visitors who never touch a form, turn on "Scan on submit only" under Advanced, Scan timing. The check then runs at the first interaction with a form, or at submission, in which case the submission is held for about a second, verified, and continued automatically. Protection is the same either way.
Settings, TrustSig, Tools shows a private recovery URL that bypasses all checks once. You can also add your IP to the whitelist.
Yes, GPLv2 or later.
_wpcf7 field, WPForms via wpforms[id]) and process it before the page loads. TrustSig only guarded their REST and AJAX endpoints, so bots that replay the rendered HTML form were never checked and never logged. These submissions are now verified on the same Contact Form 7 and WPForms toggles.trustsig_log_retention_days). The total count on the dashboard still includes pruned rows.