{"id":340916,"date":"2026-07-23T10:10:18","date_gmt":"2026-07-23T10:10:18","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/qweb-spam-shield\/"},"modified":"2026-07-23T14:49:57","modified_gmt":"2026-07-23T14:49:57","slug":"qweb-spam-shield","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/qweb-spam-shield\/","author":9897703,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.2","stable_tag":"1.0.2","tested":"7.0.2","requires":"5.8","requires_php":"7.4","requires_plugins":null,"header_name":"QWeb Spam Shield","header_author":"Qwebmaster","header_description":"Fast multi-layer spam protection for WordPress forms, comments, reviews, registration and WooCommerce. No account, no external calls.","assets_banners_color":"8895a3","last_updated":"2026-07-23 14:49:57","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/qwebspamshield.com","header_author_uri":"https:\/\/qwebmaster.com","rating":0,"author_block_rating":0,"active_installs":0,"downloads":38,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.2":{"tag":"1.0.2","author":"qwebmaster","date":"2026-07-23 14:49:57"}},"upgrade_notice":{"1.0.0":"<p>First public release.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3619777,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3619777,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3619777,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3619777,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.2"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3619777,"resolution":"1","location":"assets","locale":"","width":1440,"height":900},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3619777,"resolution":"2","location":"assets","locale":"","width":1440,"height":900},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3619777,"resolution":"3","location":"assets","locale":"","width":1440,"height":900},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3619777,"resolution":"4","location":"assets","locale":"","width":1440,"height":900},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3619777,"resolution":"5","location":"assets","locale":"","width":1440,"height":900},"screenshot-6.png":{"filename":"screenshot-6.png","revision":3619777,"resolution":"6","location":"assets","locale":"","width":1440,"height":900},"screenshot-7.png":{"filename":"screenshot-7.png","revision":3619777,"resolution":"7","location":"assets","locale":"","width":1440,"height":900},"screenshot-8.png":{"filename":"screenshot-8.png","revision":3619777,"resolution":"8","location":"assets","locale":"","width":1440,"height":900}},"screenshots":{"1":"Dashboard: spam blocked, held, and allowed at a glance, with recent activity and sources.","2":"Activity log: every inbound and outbound decision, with the reason it was flagged.","3":"Detection settings: tune the fast, multi-layer rules engine and the score thresholds.","4":"Integrations: turn protection on per form plugin, comments, registration, and WooCommerce.","5":"Mail Guard: rate-limit outbound email, auto-ban flooders, and hold overflow for review.","6":"Spam patterns: signatures the plugin learned from spam blocked on your own site.","7":"Privacy: review digests, data retention, and GDPR export and erase options.","8":"Setup wizard: confirm protection is live and which forms are covered."}},"plugin_section":[],"plugin_tags":[109,358,4902,599,286],"plugin_category":[45,54],"plugin_contributors":[159208],"plugin_business_model":[],"class_list":["post-340916","plugin","type-plugin","status-publish","hentry","plugin_tags-antispam","plugin_tags-contact-form","plugin_tags-no-captcha","plugin_tags-spam","plugin_tags-woocommerce","plugin_category-ecommerce","plugin_category-security-and-spam-protection","plugin_contributors-qwebmaster","plugin_committers-qwebmaster"],"banners":{"banner":"https:\/\/ps.w.org\/qweb-spam-shield\/assets\/banner-772x250.png?rev=3619777","banner_2x":"https:\/\/ps.w.org\/qweb-spam-shield\/assets\/banner-1544x500.png?rev=3619777","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/qweb-spam-shield\/assets\/icon-128x128.png?rev=3619777","icon_2x":"https:\/\/ps.w.org\/qweb-spam-shield\/assets\/icon-256x256.png?rev=3619777","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/qweb-spam-shield\/assets\/screenshot-1.png?rev=3619777","caption":"Dashboard: spam blocked, held, and allowed at a glance, with recent activity and sources."},{"src":"https:\/\/ps.w.org\/qweb-spam-shield\/assets\/screenshot-2.png?rev=3619777","caption":"Activity log: every inbound and outbound decision, with the reason it was flagged."},{"src":"https:\/\/ps.w.org\/qweb-spam-shield\/assets\/screenshot-3.png?rev=3619777","caption":"Detection settings: tune the fast, multi-layer rules engine and the score thresholds."},{"src":"https:\/\/ps.w.org\/qweb-spam-shield\/assets\/screenshot-4.png?rev=3619777","caption":"Integrations: turn protection on per form plugin, comments, registration, and WooCommerce."},{"src":"https:\/\/ps.w.org\/qweb-spam-shield\/assets\/screenshot-5.png?rev=3619777","caption":"Mail Guard: rate-limit outbound email, auto-ban flooders, and hold overflow for review."},{"src":"https:\/\/ps.w.org\/qweb-spam-shield\/assets\/screenshot-6.png?rev=3619777","caption":"Spam patterns: signatures the plugin learned from spam blocked on your own site."},{"src":"https:\/\/ps.w.org\/qweb-spam-shield\/assets\/screenshot-7.png?rev=3619777","caption":"Privacy: review digests, data retention, and GDPR export and erase options."},{"src":"https:\/\/ps.w.org\/qweb-spam-shield\/assets\/screenshot-8.png?rev=3619777","caption":"Setup wizard: confirm protection is live and which forms are covered."}],"raw_content":"<!--section=description-->\n<p>QWeb Spam Shield blocks spam across your entire site, not just your contact form, and it does it without a single CAPTCHA. No puzzles for your real visitors, no account, no API key, and no external service. Everything runs on your own server and nothing ever leaves your site.<\/p>\n\n<p>Most anti-spam plugins only watch comments or a single form. QWeb Spam Shield guards every place spam and abuse actually get in:<\/p>\n\n<ul>\n<li>Every form: Gravity Forms, Contact Form 7, WPForms, Fluent Forms, Elementor Pro Forms, Ninja Forms and Formidable, plus a universal wp_mail catch-all that automatically covers any other form plugin<\/li>\n<li>WordPress comments and WooCommerce product reviews<\/li>\n<li>User registration, so fake and bot sign-ups are stopped before an account is ever created<\/li>\n<li>WooCommerce checkout, with card-testing (carding) defenses that stop attackers from validating stolen cards on your store with waves of fake orders, and running up your payment processing fees<\/li>\n<li>Your outbound email: the built-in Mail Guard rate-limits the mail your own site sends, so a hacked form or a runaway plugin cannot blast thousands of messages and wreck your domain's sending reputation<\/li>\n<\/ul>\n\n<p>No CAPTCHA, ever. Your visitors never see a checkbox, a puzzle, or a \"click all the crosswalks\" challenge. Detection runs invisibly in the background, so genuine customers sail through and only spam is stopped.<\/p>\n\n<p>How it decides (fast, all local):<\/p>\n\n<ul>\n<li>Content signals: links in messages, gibberish, non-Latin scripts (French, German, and Spanish accents are allowed), marketing-pitch phrasing, and banned keywords matched on whole words<\/li>\n<li>Identity signals: disposable-email domains (a bundled list of about 7,900), missing MX records with typo tolerance, and role accounts<\/li>\n<li>Behavioral signals: honeypot, submission timing, and per-email or per-IP velocity for repeat offenders<\/li>\n<\/ul>\n\n<p>Built for site owners:<\/p>\n\n<ul>\n<li>A grouped spam log. A 1,000-request attack is one counted row, not 1,000, so your day-to-day spam stays visible. It is auto-cleaned by age and a row cap.<\/li>\n<li>Conservative by design. Genuine customer questions are not hard-blocked. Borderline submissions are held for review, never silently lost, and can be re-delivered.<\/li>\n<li>Comments use WordPress moderation (spam folder or moderation queue), so nothing is destroyed.<\/li>\n<li>GDPR friendly: IP anonymization, configurable retention, and support for Tools then Export or Erase Personal Data.<\/li>\n<\/ul>\n\n<p>Privacy:<\/p>\n\n<p>QWeb Spam Shield makes no external HTTP requests. It does not phone home, and it does not require a license, account, or third-party service.<\/p>\n\n<p>Need even stronger protection? Meet QWeb Spam Shield AI<\/p>\n\n<p>This free plugin is fully functional on its own and always will be. QWeb Spam Shield AI is the premium edition for sites that want the strongest protection possible. It layers a managed AI engine and a cross-site defense network on top of everything above:<\/p>\n\n<ul>\n<li>Managed AI tiebreaker. A purpose-built AI reviews only the borderline submissions the rules engine is unsure about, so you catch more real spam without ever blocking a genuine customer. There is no API key to buy or configure. It is included with your license.<\/li>\n<li>AI review of held submissions. Every held message is re-checked against your own business context, and real customer inquiries are released automatically. False positives drop close to zero, completely hands-off.<\/li>\n<li>Cross-site pattern network. The instant spam is confirmed on any protected site, every other licensed site is protected from it too, so your site benefits from attacks aimed at everyone else.<\/li>\n<li>Sharper detection that keeps improving, tuned continuously on live spam across the whole network.<\/li>\n<li>Faster, fully automatic updates delivered straight to your dashboard.<\/li>\n<li>Priority support from the team that builds it.<\/li>\n<\/ul>\n\n<p>Get QWeb Spam Shield AI at https:\/\/qwebspamshield.com<\/p>\n\n<h3>Source code and build tools<\/h3>\n\n<p>The plugin ships all of its source. The only compiled asset is the React admin app\nin admin\/build\/, generated from the human-readable source included in admin\/src\/\nwith the official WordPress build tooling:<\/p>\n\n<ol>\n<li>Run <code>npm install<\/code> in the plugin root (uses package.json, @wordpress\/scripts).<\/li>\n<li>Run <code>npm run build<\/code>. This regenerates admin\/build\/index.js and style-index.css.<\/li>\n<\/ol>\n\n<p>Everything else (PHP, the frontend honeypot script in assets\/js\/, CSS) is plain,\nunminified source. The bundled disposable-email-domain list in data\/ comes from the\npublic domain disposable-email-domains project (github.com\/disposable-email-domains).<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin to \/wp-content\/plugins\/, or install it from Plugins then Add New, and activate it.<\/li>\n<li>That is it. Protection is on by default with safe settings. Review and tune it under Spam Shield.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20it%20need%20an%20account%20or%20api%20key%3F\"><h3>Does it need an account or API key?<\/h3><\/dt>\n<dd><p>No. It runs entirely on your server with no account, no API key, and no external calls.<\/p><\/dd>\n<dt id=\"will%20it%20block%20real%20customers%3F\"><h3>Will it block real customers?<\/h3><\/dt>\n<dd><p>It is tuned to avoid that. Genuine product, order, and shipping questions pass through. Only high-confidence spam is filed away, and borderline submissions are held for review rather than deleted.<\/p><\/dd>\n<dt id=\"does%20it%20cover%20my%20form%20plugin%3F\"><h3>Does it cover my form plugin?<\/h3><\/dt>\n<dd><p>Gravity Forms, Contact Form 7, WPForms, Fluent Forms, Elementor Pro Forms, Ninja Forms, and Formidable Forms have dedicated integrations. Any other form plugin is still covered by the universal wp_mail catch-all.<\/p><\/dd>\n<dt id=\"does%20it%20work%20with%20woocommerce%3F\"><h3>Does it work with WooCommerce?<\/h3><\/dt>\n<dd><p>Yes. It covers product reviews and both the classic and block (Store API) checkout, with card-testing defenses. High-Performance Order Storage (HPOS) is supported.<\/p><\/dd>\n<dt id=\"is%20my%20data%20sent%20anywhere%3F\"><h3>Is my data sent anywhere?<\/h3><\/dt>\n<dd><p>No. The plugin makes no external requests and stores everything locally, with optional IP anonymization and content retention limits.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.2<\/h4>\n\n<ul>\n<li>Removed development files from the package (.github) and removed the Mail Guard development simulator from the plugin entirely.<\/li>\n<\/ul>\n\n<h4>1.0.1<\/h4>\n\n<ul>\n<li>Hardened database queries and input handling following plugin review feedback. Regex patterns are length-capped and unsafe shapes are refused before evaluation.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>First public release. Multi-layer rules engine. Integrations for Gravity Forms, Contact Form 7, WPForms, Fluent Forms, Elementor, Ninja Forms, Formidable, comments, registration, and WooCommerce (classic and block checkout). Universal wp_mail catch-all. Mail Guard outbound throttle. Grouped spam log. Held-submission review and re-delivery. GDPR export and erase. No external calls.<\/li>\n<\/ul>","raw_excerpt":"Stop spam on every form, comment, review, signup and WooCommerce checkout, with no CAPTCHA and no external calls. Card-testing defense built in.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/340916","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=340916"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/qwebmaster"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=340916"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=340916"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=340916"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=340916"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=340916"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=340916"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}