[WordPress] 外掛分享: Booker Privacy Spam Guard

首頁外掛目錄 › Booker Privacy Spam Guard
全新外掛
安裝啟用
尚無評分
2 天前
最後更新
問題解決
WordPress 6.0+ PHP 7.4+ v1.6.6 上架:2026-07-26

內容簡介

Booker Privacy Spam Guard 旨在保護 Elementor 表單和 WordPress 原生評論表單免受垃圾郵件攻擊,同時不會不必要地處理個人數據。此外掛專為 Elementor 使用者設計,提供全面的防護功能。

【主要功能】
• 隱形蜜罐欄位,隨機生成唯一名稱
• 基於時間的可行性檢查,確保數據完整性
• 伺服器端 nonce 完整性檢查
• 內容啟發式檢查,阻擋過多連結或特定關鍵字
• 基於每日輪換指紋的速率限制
• 自動封鎖重複異常的指紋

外掛標籤

開發者團隊

⬇ 下載最新版 (v1.6.6) 或搜尋安裝

① 下載 ZIP → 後台「外掛 › 安裝外掛 › 上傳外掛」
② 後台搜尋「Booker Privacy Spam Guard」→ 直接安裝(推薦)
📦 歷史版本下載

原文外掛簡介

Booker Privacy Spam Guard protects Elementor forms and the native WordPress comment form from spam without unnecessarily processing personal data. It is built specifically for Elementor users: the classic Elementor Pro Form widget gets the full feature set, and the WordPress comment form is covered as well. The new Atomic Form widget receives content checks, rate limiting, auto-ban and local proof of work based on the global default protection level; per-form honeypot and time checks are not yet available for its newer editor control system.

Invisible honeypot field with a random field name that is unique per installation
Time-based plausibility check via a signed, tamper-proof time window
Server-side nonce integrity check per form
Content heuristic: blocks entries with too many links or your own spam keywords
Rate limiting based on a pseudonymous, daily-rotating fingerprint (no raw data such as IP addresses is stored)
Automatic ban for fingerprints that repeatedly stand out (threshold and time window configurable)
Local adaptive SHA-256 proof-of-work challenge with no external service, cookies or visible puzzle
Per-form protection levels (Off / Basic / Standard / Strict)
Statistics overview with a 14-day history chart and a list of blocked requests in the WordPress admin
Ready-to-use text snippet for your privacy policy, including integration with WordPress’ built-in Privacy Policy Guide
Configurable client IP detection for sites behind a reverse proxy, load balancer or CDN (e.g. Cloudflare), with a trusted-proxy list to prevent spoofing
Cache- and CDN-friendly: the timing token and nonce are refreshed on page load from a non-cached endpoint, so full-page or edge caches never serve visitors a stale token
No cookies, no external requests, no subscription costs

The built-in local proof-of-work provider uses the challenge extension points; optional alternative providers can be registered through the same interface.
The plugin’s privacy-friendly, data-minimal design does not, on its own, make your entire website legally compliant – that depends on many other factors and remains your responsibility.

延伸相關外掛

文章
Filter
Apply Filters
Mastodon