[WordPress] 外掛分享: DigitaleZen AntiSpam Shield for CF7

首頁外掛目錄 › DigitaleZen AntiSpam Shield for CF7
WordPress 外掛 DigitaleZen AntiSpam Shield for CF7 的封面圖片
全新外掛
安裝啟用
尚無評分
20 天前
最後更新
問題解決
WordPress 6.7+ PHP 7.4+ v1.1.0 上架:2025-12-07

內容簡介

DigitaleZen AntiSpam Shield for CF7 是一款專為 Contact Form 7 設計的防垃圾郵件外掛,無需添加 CAPTCHA 或進行表單標籤配置,能有效保護表單提交,提升網站安全性。

【主要功能】
• 自動隱藏的蜜罐技術
• 每個 IP 和電子郵件的提交速率限制
• 本地自適應黑名單學習垃圾郵件信號
• 整合 Contact Form 7 垃圾郵件日誌
• 提供隱私控制和每週報告選項

外掛標籤

開發者團隊

⬇ 下載最新版 (v1.1.0) 或搜尋安裝

① 下載 ZIP → 後台「外掛 › 安裝外掛 › 上傳外掛」
② 後台搜尋「DigitaleZen AntiSpam Shield for CF7」→ 直接安裝(推薦)
📦 歷史版本下載

原文外掛簡介

DigitaleZen AntiSpam Shield for CF7 protects Contact Form 7 submissions without adding a CAPTCHA or requiring form-tag configuration.
Its checks run through Contact Form 7’s supported spam API and include:

An automatic, visually hidden honeypot.
A site-signed form token with a minimum submission time.
Per-IP and per-email rate limiting.
A local adaptive blacklist that learns site-HMAC email/IP identities only from high-confidence spam signals.
Matching against migrated or locally supplied domain, username, and keyword rules.
Contact Form 7 spam-log integration for every local decision.

Blocked-event data is stored in private WordPress database tables. The default privacy mode stores masked email and IP values together with site-specific HMAC identifiers. Events are removed automatically after 30 days by default; administrators can select a retention period from 1 to 365 days.
The local reputation threshold is deliberately conservative. Learned entries expire after 90 days without new evidence, and administrators can reset all learned reputation after a suspected false positive. The signed JSON blacklist is rebuilt locally with an atomic replacement and a verified database fallback. It contains no plaintext email or IP address.
The dashboard provides local event totals, a text-accessible chart summary, protected CSV export, local-blacklist status, privacy controls, and optional weekly email reports. Weekly reports are disabled by default.
When version 1.1.0 upgrades an existing 1.0.0 installation, it first stores a checksum-verified private backup of known legacy files, imports compatible log and blacklist data, and only then removes those files from the public uploads directory. The original private migration backups remain available for administrator-controlled deletion.
Privacy
Blocked events are stored locally in WordPress database tables and are subject to the configured retention period. The plugin registers exporters and erasers with the WordPress personal-data tools and adds suggested privacy-policy text under Settings > Privacy.
The reputation table and signed local JSON use site-specific HMAC values for email and IP identities. Those values cannot be reused as a shared cross-site blacklist. The JSON is placed in a randomized plugin directory with Apache/IIS deny rules and a blocking index file; the verified database copy remains the runtime fallback.
CSV exports are available only to administrators, require a WordPress nonce, and neutralize spreadsheet formula prefixes.
External services
This plugin does not use an external blacklist, CAPTCHA, analytics endpoint, CDN asset, or other external service. All detection, learning, storage, JSON generation, and scheduled cleanup run on the site that installed the plugin.

延伸相關外掛

文章
Filter
Mastodon