{"id":356691,"date":"2026-09-30T12:26:18","date_gmt":"2026-09-30T12:26:18","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/bluefairy-anti-spam\/"},"modified":"2026-09-30T12:25:43","modified_gmt":"2026-09-30T12:25:43","slug":"bluefairy-antispam","status":"publish","type":"plugin","link":"https:\/\/bal.wordpress.org\/plugins\/bluefairy-antispam\/","author":23552439,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.1.4","stable_tag":"1.1.4","tested":"7.1.2","requires":"6.5","requires_php":"8.1","requires_plugins":null,"header_name":"BlueFairy AntiSpam","header_author":"Blue Fairy Development","header_description":"Invisible anti-spam protection for WordPress and WooCommerce. No CAPTCHAs. No friction. Just spam-free forms.","assets_banners_color":"376a96","last_updated":"2026-09-30 12:25:43","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/wordpress.bluefairydevelopment.com\/anti-spam\/","header_author_uri":"https:\/\/wordpress.bluefairydevelopment.com","rating":0,"author_block_rating":0,"active_installs":0,"downloads":48,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.1.4":{"tag":"1.1.4","author":"bluefairydevelopment","date":"2026-09-30 12:25:43","revision":3721209}},"upgrade_notice":{"1.1.4":"<p>Security fix: WP 6.9 Abilities now enforce manage_options via permission_callback (previously only the descriptive capability key was set). Recommended upgrade for anyone on WP 6.9+.<\/p>","1.1.3":"<p>Housekeeping release: removed the empty Domain Path header that triggered a Plugin Check warning; bumped Tested up to 7.1.<\/p>","1.1.2":"<p>Bug fix: settings page fields (SFS enabled, confidence threshold, API key) were silently not saving. Upgrade immediately if you rely on the Stop Forum Spam integration.<\/p>","1.1.0":"<p>New: marking a comment as spam in admin now auto-reports to Stop Forum Spam (if enabled). New &quot;Reported to SFS&quot; tab on the log page.<\/p>","1.0.0":"<p>Initial release.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3721209,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3721209,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3721209,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3721209,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.1.4"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3721223,"resolution":"1","location":"assets","locale":"","width":596,"height":297},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3721223,"resolution":"2","location":"assets","locale":"","width":1260,"height":1180},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3721223,"resolution":"3","location":"assets","locale":"","width":1260,"height":684}},"screenshots":{"1":"Dashboard widget showing total spammers blocked.","2":"Settings page under Tools &gt; Anti-Spam.","3":"Anti-Spam log \u2014 searchable, filterable, with Reported to SFS view tab."}},"plugin_section":[262246],"plugin_tags":[2656,107,598,599,286],"plugin_category":[44,45,54],"plugin_contributors":[283692],"plugin_business_model":[],"class_list":["post-356691","plugin","type-plugin","status-publish","hentry","plugin_section-dashboard-widgets","plugin_tags-anti-spam","plugin_tags-comments","plugin_tags-honeypot","plugin_tags-spam","plugin_tags-woocommerce","plugin_category-discussion-and-community","plugin_category-ecommerce","plugin_category-security-and-spam-protection","plugin_contributors-bluefairydevelopment","plugin_committers-bluefairydevelopment"],"banners":{"banner":"https:\/\/ps.w.org\/bluefairy-antispam\/assets\/banner-772x250.png?rev=3721209","banner_2x":"https:\/\/ps.w.org\/bluefairy-antispam\/assets\/banner-1544x500.png?rev=3721209","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/bluefairy-antispam\/assets\/icon-128x128.png?rev=3721209","icon_2x":"https:\/\/ps.w.org\/bluefairy-antispam\/assets\/icon-256x256.png?rev=3721209","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/bluefairy-antispam\/assets\/screenshot-1.png?rev=3721223","caption":"Dashboard widget showing total spammers blocked."},{"src":"https:\/\/ps.w.org\/bluefairy-antispam\/assets\/screenshot-2.png?rev=3721223","caption":"Settings page under Tools &gt; Anti-Spam."},{"src":"https:\/\/ps.w.org\/bluefairy-antispam\/assets\/screenshot-3.png?rev=3721223","caption":"Anti-Spam log \u2014 searchable, filterable, with Reported to SFS view tab."}],"raw_content":"<!--section=description-->\n<p>We hate spam with a burning passion. We hate it so much we built this plugin for free.<\/p>\n\n<p><strong>BlueFairy AntiSpam<\/strong> stops bot submissions on comments, user registration, WooCommerce reviews, My Account registration, and checkout \u2014 without a single CAPTCHA in sight. No puzzles. No friction on the path to purchase. Just invisible protection working silently in the background.<\/p>\n\n<p><strong>How it works:<\/strong><\/p>\n\n<ul>\n<li><strong>Honeypot<\/strong> \u2014 A hidden field is added to your forms. Real humans never see it or fill it in. Bots do. Blocked.<\/li>\n<li><strong>Time trap<\/strong> \u2014 A cryptographically signed timestamp is embedded at page load. Submissions that arrive faster than a human can type are rejected. Bots move fast. Too fast.<\/li>\n<li><strong>Stop Forum Spam (optional)<\/strong> \u2014 Cross-reference visitor IPs and emails against the world's largest spam database. Disabled by default. You choose when to turn it on.<\/li>\n<\/ul>\n\n<p>No configuration required to get started. Activate and it works. The honeypot and time trap are on by default.<\/p>\n\n<p><strong>What it protects:<\/strong><\/p>\n\n<ul>\n<li>WordPress comments (traditional and REST API)<\/li>\n<li>WordPress user registration<\/li>\n<li>WooCommerce product reviews<\/li>\n<li>WooCommerce My Account registration<\/li>\n<li>WooCommerce shortcode checkout<\/li>\n<li>WooCommerce Block checkout<\/li>\n<\/ul>\n\n<p>Logged-in users are never challenged \u2014 no friction for your actual customers.<\/p>\n\n<h3>Third Party Services<\/h3>\n\n<p>This plugin can optionally connect to the Stop Forum Spam service (https:\/\/www.stopforumspam.com\/).<\/p>\n\n<p><strong>This feature is disabled by default.<\/strong> It must be explicitly enabled under Tools &gt; Anti-Spam.<\/p>\n\n<p>When enabled:\n* Visitor IP addresses and email addresses are sent to <code>https:\/\/api.stopforumspam.org\/api<\/code> for spam lookup.\n* If you provide an API key, blocked visitors' IP and email may be reported to <code>https:\/\/www.stopforumspam.com\/add.php<\/code>.<\/p>\n\n<p>Stop Forum Spam privacy policy: https:\/\/www.stopforumspam.com\/legal\nStop Forum Spam terms of service: https:\/\/www.stopforumspam.com\/legal<\/p>\n\n<p>No data is ever sent without your explicit opt-in.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>bluefairy-antispam<\/code> folder to <code>\/wp-content\/plugins\/<\/code><\/li>\n<li>Activate the plugin in <strong>Plugins &gt; Installed Plugins<\/strong><\/li>\n<li>Done. Honeypot and time trap are active immediately.<\/li>\n<\/ol>\n\n<p>To configure: <strong>Tools &gt; Anti-Spam<\/strong><\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"will%20this%20break%20my%20checkout%3F\"><h3>Will this break my checkout?<\/h3><\/dt>\n<dd><p>No. Real customers never interact with any trap field. The honeypot is invisible. The time trap gives 24 hours before expiry \u2014 far longer than any checkout takes.<\/p><\/dd>\n<dt id=\"do%20i%20need%20a%20stop%20forum%20spam%20account%3F\"><h3>Do I need a Stop Forum Spam account?<\/h3><\/dt>\n<dd><p>No. SFS is entirely optional and off by default. Honeypot and time trap work without it.<\/p>\n\n<p>To enable SFS checking (IP and email lookup only), turn it on in <strong>Tools &gt; Anti-Spam<\/strong> \u2014 no account needed.<\/p>\n\n<p>To also <em>report<\/em> confirmed spammers back to SFS, you need a free API key. Register at https:\/\/www.stopforumspam.com\/signup and paste your key into the SFS API key field.<\/p><\/dd>\n<dt id=\"does%20it%20work%20with%20the%20woocommerce%20block%20checkout%3F\"><h3>Does it work with the WooCommerce Block checkout?<\/h3><\/dt>\n<dd><p>Yes. The Block checkout uses the Store API, so POST-based traps don't apply \u2014 but the SFS check still runs if enabled.<\/p><\/dd>\n<dt id=\"what%20gets%20stored%3F\"><h3>What gets stored?<\/h3><\/dt>\n<dd><p>When a submission is blocked: the time, which trap fired, which form, the IP address, and a hashed (HMAC-SHA256) version of the email address. The raw email address is never stored.<\/p><\/dd>\n<dt id=\"how%20long%20are%20logs%20kept%3F\"><h3>How long are logs kept?<\/h3><\/dt>\n<dd><p>90 days by default. Configurable under <strong>Tools &gt; Anti-Spam<\/strong>.<\/p><\/dd>\n<dt id=\"when%20i%20mark%20a%20comment%20as%20spam%20in%20the%20admin%2C%20does%20the%20plugin%20report%20it%3F\"><h3>When I mark a comment as spam in the admin, does the plugin report it?<\/h3><\/dt>\n<dd><p>Yes \u2014 if Stop Forum Spam is enabled and an API key is configured, marking a comment as spam from the Comments list or post edit screen will automatically report the commenter's IP and email to SFS.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.1.4<\/h4>\n\n<ul>\n<li>Security: WP 6.9 Abilities (get-log-entries, get-stats, get-settings) now enforce manage_options at runtime via permission_callback. Previously only the descriptive capability key was set; the API treats capability as metadata, not enforcement.<\/li>\n<li>Security: get-settings ability strips sfs_api_key and hmac_secret from its response as defence in depth; a regression test guards this invariant.<\/li>\n<li>Added: real execute_callback handlers for all three abilities \u2014 they now return usable data instead of being metadata-only stubs.<\/li>\n<li>Added: Logger::get_recent_entries() and Settings::get_all() helpers used by the ability handlers.<\/li>\n<li>Fixed: dashboard widget CSS moved out of an inline  tag into an enqueued stylesheet, scoped to the WP dashboard (index.php) only.<\/li>\n<\/ul>\n\n<h4>1.1.3<\/h4>\n\n<ul>\n<li>Fixed: removed empty Domain Path header from the plugin file. The languages\/ directory was empty and excluded from the release zip, causing a Plugin Check warning.<\/li>\n<li>Compatibility: bumped Tested up to 7.1.<\/li>\n<\/ul>\n\n<h4>1.1.2<\/h4>\n\n<ul>\n<li>Fixed: SFS enabled, confidence threshold, and API key fields were silently not saving. WordPress calls add_option() instead of issuing a MySQL UPDATE when the stored value equals the default registered via register_setting(), and add_option() is a no-op when the row already exists. Removed the registered default so WordPress always takes the UPDATE path.<\/li>\n<\/ul>\n\n<h4>1.1.1<\/h4>\n\n<ul>\n<li>Fixed: Log filter (trap type, search) now persists after bulk-delete actions (was lost because filters were read from $_GET, which is empty after POST redirect).<\/li>\n<li>Fixed: Bulk-delete on the Anti-Spam Log now shows a success notice with the count of entries deleted.<\/li>\n<\/ul>\n\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>Added: when an admin marks a comment as spam from the Comments list or post edit screen, the commenter's IP and email are automatically reported to Stop Forum Spam (requires SFS enabled + API key configured).<\/li>\n<li>Added: \"Reported to SFS\" view tab on the Anti-Spam Log page so you can filter to see only submissions forwarded to Stop Forum Spam.<\/li>\n<li>Added: PHPUnit unit test suite (23 tests covering Honeypot and TimeTrap classes).<\/li>\n<\/ul>\n\n<h4>1.0.1<\/h4>\n\n<ul>\n<li>Fixed: register WP 6.9 abilities on correct action hooks to eliminate deprecation notices.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release. Honeypot, time trap, optional Stop Forum Spam integration, dashboard widget, admin log.<\/li>\n<\/ul>","raw_excerpt":"We hate spam. No CAPTCHAs. No third-party puzzles. Just invisible traps that catch bots and let real people through.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/bal.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/356691","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/bal.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/bal.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/bal.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=356691"}],"author":[{"embeddable":true,"href":"https:\/\/bal.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/bluefairydevelopment"}],"wp:attachment":[{"href":"https:\/\/bal.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=356691"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/bal.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=356691"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/bal.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=356691"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/bal.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=356691"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/bal.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=356691"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/bal.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=356691"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}