[WordPress] 外掛分享: Spambargo: Anti-Spam for Forms & Comments

首頁外掛目錄 › Spambargo: Anti-Spam for Forms & Comments
100+
安裝啟用
尚無評分
20 天前
最後更新
問題解決
WordPress 6.2+ PHP 7.4+ v2.4.9 上架:2026-08-05

內容簡介

Spambargo 是一款簡單的反垃圾郵件外掛,專為 WordPress 網站擁有者、代理商及網站建設者設計。它能有效阻擋不必要的表單提交、評論及 WooCommerce 垃圾郵件,無需第三方 CAPTCHA 服務或複雜的設置。

【主要功能】
• 阻擋包含特定關鍵字或短語的訊息
• 檢查過多連結的訊息
• 阻擋可疑的電子郵件地址
• 防止不合理快速提交的表單
• 重複提交的訪客限制
• 支援多種表單和整合

外掛標籤

開發者團隊

⬇ 下載最新版 (v2.4.9) 或搜尋安裝

① 下載 ZIP → 後台「外掛 › 安裝外掛 › 上傳外掛」
② 後台搜尋「Spambargo: Anti-Spam for Forms & Comments」→ 直接安裝(推薦)
📦 歷史版本下載

原文外掛簡介

Spambargo is a simple anti-spam plugin for WordPress site owners, agencies and website builders. It helps block unwanted form submissions, comments and WooCommerce spam without requiring a third-party CAPTCHA service or complicated setup.
It works with Elementor Pro Forms, Contact Form 7, JetFormBuilder, Ninja Forms, WooCommerce registration and checkout, WooCommerce Checkout Blocks, WordPress comments, and eligible generic lead forms.
Start with the recommended settings, add common spam rules with one click, and adjust only what your site needs. The most useful controls are shown first, while technical options stay under Advanced settings.
What can Spambargo block?

Messages containing blocked words or phrases.
Messages with too many links.
Disposable and suspicious email addresses.
Forms submitted unrealistically fast.
Repeated submissions from the same visitor.
Specific email addresses and email domains.
Specific IP addresses and IPv4 or IPv6 network ranges.
Messages written mostly in capital letters.
Clearly suspicious phone number patterns when the optional phone check is enabled.
Additional automated spam using optional browser-token and math-challenge checks.

Supported forms and integrations

Elementor Pro Forms.
Contact Form 7.
JetFormBuilder.
Ninja Forms.
WooCommerce registration and classic checkout.
WooCommerce Checkout Blocks.
WordPress comments.
Eligible generic HTML lead forms using a best-effort browser-side pre-check.

Native integrations validate submissions on the server. Generic forms without a native integration use a browser-side pre-check and require a native or custom server-side integration for protection against direct POST requests.
Simple to set up

Dashboard statistics and the main protection settings are available on one screen.
Blocked words and phrases, link limits, email checks and automatic limits appear first.
Recommendation buttons can add useful starting values without deleting existing settings.
Advanced technical controls stay collapsed until you need them.
A searchable spam log helps you understand what was blocked and why.

How protection works
Spambargo combines several lightweight checks instead of relying on a single CAPTCHA:

Literal blocked-word and phrase rules with case-insensitive matching.
Link-count and email-pattern checks.
Honeypot and minimum submission-time checks.
Atomic minute and hourly rate limits with IPv6 network grouping.
Manual email, domain, IP and CIDR block lists.
Optional phone validation, math challenge and temporary signed browser correlation token.
Trusted-proxy handling for forwarded visitor IP addresses.
Automatic log retention, streamed CSV export and batched email or webhook notifications.

Spambargo runs its checks locally on the WordPress site by default and does not require a CAPTCHA service operated by a third party.
Privacy
Spambargo does not send data to a service operated by the plugin author. All checks run on the site server by default.
When a submission is blocked, the plugin may store the IP address, email address, form identifier, block reason, optional content snippet and optional verified fingerprint hash. The content snippet can be disabled and logs are cleaned according to the configured retention period.
Optional browser correlation collects coarse screen-size buckets, timezone, language, platform, CPU-core count and touch capability. The server combines them with a random per-session identifier and returns a signed hash token stored in browser sessionStorage for up to eight hours. Raw attributes are not written to the spam log. Administrators should update their privacy notice as required by applicable law. Spambargo integrates with WordPress personal-data export and erasure tools and adds suggested text to the Privacy Policy Guide.
When a webhook URL is configured, batched blocked-submission data is sent to that administrator-selected endpoint. This is the only optional external data transfer performed by the plugin.

延伸相關外掛

文章
Filter
Mastodon