{"id":348743,"date":"2026-08-12T23:02:49","date_gmt":"2026-08-12T23:02:49","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/simple-spam-shield\/"},"modified":"2026-08-12T23:02:22","modified_gmt":"2026-08-12T23:02:22","slug":"onsite-spam-guard","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/onsite-spam-guard\/","author":20958773,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.1.2","stable_tag":"1.1.2","tested":"7.0.4","requires":"6.2","requires_php":"8.2","requires_plugins":null,"header_name":"Onsite Spam Guard","header_author":"Jerome Wincek","header_description":"Config-driven spam prevention for Comments, WooCommerce Reviews, and Jetpack Contact Form blocks \u2014 no external services required.","assets_banners_color":"465566","last_updated":"2026-08-12 23:02:22","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"","rating":0,"author_block_rating":0,"active_installs":0,"downloads":43,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.1.2":{"tag":"1.1.2","author":"jeromewincek","date":"2026-08-12 23:02:22"}},"upgrade_notice":{"1.1.2":"<p>Renamed to Onsite Spam Guard, plus a capability check on the spam-log bulk delete. Settings and logs carry over unchanged.<\/p>","1.1.1":"<p>Fixes legitimate Jetpack contact form submissions being wrongly flagged as spam. Recommended for anyone protecting Jetpack forms.<\/p>","1.1.0":"<p>Tabbed settings, an option to keep your data on uninstall, and multisite-wide cleanup.<\/p>","1.0.1":"<p>Adds explicit-field support to the integration API for REST\/JSON forms and prevents false rejections for content-only integrations.<\/p>","1.0.0":"<p>Initial release.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3644063,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3644063,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256},"icon.svg":{"filename":"icon.svg","revision":3644063,"resolution":false,"location":"assets","locale":false}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3644063,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3644063,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250},"banner.svg":{"filename":"banner.svg","revision":3644063,"resolution":false,"location":"assets","locale":false}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.1.2"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3644063,"resolution":"1","location":"assets","locale":"","width":2520,"height":2376},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3644063,"resolution":"2","location":"assets","locale":"","width":2520,"height":1140},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3644063,"resolution":"3","location":"assets","locale":"","width":2520,"height":972},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3644063,"resolution":"4","location":"assets","locale":"","width":2520,"height":1814}},"screenshots":{"1":"The tabbed settings page \u2014 the Guards tab, with individual guard toggles and per-guard thresholds.","2":"The Allowlist tab \u2014 allowed IPs, CIDR ranges, and emails, plus the trusted-proxy option.","3":"The Logging tab \u2014 log retention and the option to keep or delete data when the plugin is removed.","4":"The Spam Logs viewer \u2014 filter by guard and context, a user-agent column, and per-row and bulk delete actions."}},"plugin_section":[],"plugin_tags":[109,107,598,599,286],"plugin_category":[44,45,54],"plugin_contributors":[275434],"plugin_business_model":[],"class_list":["post-348743","plugin","type-plugin","status-publish","hentry","plugin_tags-antispam","plugin_tags-comments","plugin_tags-honeypot","plugin_tags-spam","plugin_tags-woocommerce","plugin_category-discussion-and-community","plugin_category-ecommerce","plugin_category-security-and-spam-protection","plugin_contributors-jeromewincek","plugin_committers-jeromewincek"],"banners":{"banner":"https:\/\/ps.w.org\/onsite-spam-guard\/assets\/banner-772x250.png?rev=3644063","banner_2x":"https:\/\/ps.w.org\/onsite-spam-guard\/assets\/banner-1544x500.png?rev=3644063","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":"https:\/\/ps.w.org\/onsite-spam-guard\/assets\/icon.svg?rev=3644063","icon":"https:\/\/ps.w.org\/onsite-spam-guard\/assets\/icon.svg?rev=3644063","icon_2x":false,"generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/onsite-spam-guard\/assets\/screenshot-1.png?rev=3644063","caption":"The tabbed settings page \u2014 the Guards tab, with individual guard toggles and per-guard thresholds."},{"src":"https:\/\/ps.w.org\/onsite-spam-guard\/assets\/screenshot-2.png?rev=3644063","caption":"The Allowlist tab \u2014 allowed IPs, CIDR ranges, and emails, plus the trusted-proxy option."},{"src":"https:\/\/ps.w.org\/onsite-spam-guard\/assets\/screenshot-3.png?rev=3644063","caption":"The Logging tab \u2014 log retention and the option to keep or delete data when the plugin is removed."},{"src":"https:\/\/ps.w.org\/onsite-spam-guard\/assets\/screenshot-4.png?rev=3644063","caption":"The Spam Logs viewer \u2014 filter by guard and context, a user-agent column, and per-row and bulk delete actions."}],"raw_content":"<!--section=description-->\n<p>Onsite Spam Guard blocks spam on the forms your visitors actually use \u2014 WordPress comments, WooCommerce product reviews, and Jetpack contact form blocks \u2014 without sending anything to a third-party service, requiring an API key, or putting a CAPTCHA in front of your users.<\/p>\n\n<p>Protection is built from a pipeline of independent <strong>guards<\/strong>. Each guard is a small, focused check (a hidden honeypot field, a submit-speed gate, a keyword filter, and so on). Guards run in priority order, and the first one to fail blocks the submission. Every guard can be toggled and tuned from a single settings page, and every block can be logged for review.<\/p>\n\n<h4>Spam guards<\/h4>\n\n<ul>\n<li><strong>Honeypot<\/strong> \u2014 a hidden field that bots fill in but humans never see.<\/li>\n<li><strong>Duplicate detection<\/strong> \u2014 rejects identical submissions sent within a short window.<\/li>\n<li><strong>Time gate<\/strong> \u2014 rejects submissions completed faster than a human could plausibly type.<\/li>\n<li><strong>Signature<\/strong> \u2014 requires a server-signed token proving the form was served by this site, deterring automated cross-site posting.<\/li>\n<li><strong>Link limit<\/strong> \u2014 flags submissions that contain too many URLs.<\/li>\n<li><strong>Keyword block<\/strong> \u2014 rejects submissions matching a configurable blocklist of words or phrases.<\/li>\n<li><strong>Behavioral analysis<\/strong> (optional) \u2014 scores mouse movement, clicks, and time on page to spot bot-like interaction.<\/li>\n<\/ul>\n\n<h4>Why you might choose it<\/h4>\n\n<ul>\n<li><strong>No external services.<\/strong> Nothing leaves your site. No accounts, no API keys, no per-submission fees.<\/li>\n<li><strong>No CAPTCHA.<\/strong> Protection is invisible to legitimate visitors.<\/li>\n<li><strong>Allowlist.<\/strong> Trusted IPs, CIDR ranges, email addresses, and email domains bypass every guard.<\/li>\n<li><strong>Logging with retention.<\/strong> Blocked submissions are recorded in a dedicated table with a paginated admin viewer, and old entries are pruned automatically on a schedule you control.<\/li>\n<li><strong>Privacy-aware.<\/strong> The plugin registers suggested privacy-policy text describing exactly what it records.<\/li>\n<li><strong>Modern, dependency-free code.<\/strong> PHP 8.2+, vanilla front-end JavaScript (no jQuery), and no runtime third-party libraries.<\/li>\n<\/ul>\n\n<h4>Works with<\/h4>\n\n<ul>\n<li>WordPress comments (always).<\/li>\n<li>WooCommerce product reviews (when WooCommerce is active).<\/li>\n<li>Jetpack contact form blocks (when Jetpack is active).<\/li>\n<\/ul>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>onsite-spam-guard<\/code> folder to <code>\/wp-content\/plugins\/<\/code>, or install it through <strong>Plugins \u2192 Add New<\/strong>.<\/li>\n<li>Activate the plugin through the <strong>Plugins<\/strong> menu in WordPress.<\/li>\n<li>Go to <strong>Spam Guard \u2192 Settings<\/strong> to choose which form types to protect and to enable or tune individual guards.<\/li>\n<li>Review anything that gets blocked under <strong>Spam Guard \u2192 Spam Logs<\/strong>.<\/li>\n<\/ol>\n\n<p>No further configuration is required \u2014 sensible defaults are applied on activation.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20this%20send%20my%20data%20to%20any%20external%20service%3F\"><h3>Does this send my data to any external service?<\/h3><\/dt>\n<dd><p>No. Every check runs on your own server. Nothing about a submission is sent anywhere outside your site.<\/p><\/dd>\n<dt id=\"will%20legitimate%20visitors%20see%20a%20captcha%20or%20extra%20step%3F\"><h3>Will legitimate visitors see a CAPTCHA or extra step?<\/h3><\/dt>\n<dd><p>No. All protection is invisible. The honeypot field is hidden, and the timing and behavioral checks happen in the background.<\/p><\/dd>\n<dt id=\"what%20does%20it%20store%2C%20and%20for%20how%20long%3F\"><h3>What does it store, and for how long?<\/h3><\/dt>\n<dd><p>When a submission is blocked (and logging is enabled), the plugin records the guard that blocked it, the form context, the reason, a short excerpt of the content, the visitor IP address, and the browser user-agent. Entries older than the retention window (default 30 days, configurable; set to 0 to keep them indefinitely) are pruned automatically. The plugin also registers suggested privacy-policy text you can add to your site's policy.<\/p><\/dd>\n<dt id=\"i%27m%20behind%20cloudflare%20or%20a%20load%20balancer%20and%20the%20wrong%20ip%20is%20logged.\"><h3>I'm behind Cloudflare or a load balancer and the wrong IP is logged.<\/h3><\/dt>\n<dd><p>By default the plugin uses the direct connection IP, because forwarded headers can be spoofed to bypass the allowlist. If your site sits behind a trusted reverse proxy, enable <strong>Trust proxy headers for IP detection<\/strong> under <strong>Spam Guard \u2192 Settings \u2192 Allowlist<\/strong>.<\/p><\/dd>\n<dt id=\"a%20legitimate%20submission%20was%20blocked.%20what%20do%20i%20do%3F\"><h3>A legitimate submission was blocked. What do I do?<\/h3><\/dt>\n<dd><p>By default a blocked comment or review is placed in the <strong>spam queue<\/strong> (Comments \u2192 Spam) rather than being rejected outright, so you can restore a false positive with one click \u2014 nothing is lost. Open <strong>Spam Guard \u2192 Spam Logs<\/strong> to see which guard blocked it and why, then loosen that guard on the settings page \u2014 for example, raise the link limit, lower the behavioral threshold, or add the sender to the allowlist. If you would rather reject blocked comments with an error message, enable that option under <strong>Spam Guard \u2192 Settings \u2192 General<\/strong>.<\/p><\/dd>\n<dt id=\"does%20it%20replace%20wordpress%27s%20built-in%20comment%20moderation%3F\"><h3>Does it replace WordPress's built-in comment moderation?<\/h3><\/dt>\n<dd><p>No \u2014 it complements it. Onsite Spam Guard's guards run <em>before<\/em> WordPress's own comment checks, and those built-ins still run underneath: the duplicate-comment check, the comment flood throttle, the <strong>Disallowed Comment Keys<\/strong> blocklist, and the \"hold a comment with this many links\" setting (all under <strong>Settings \u2192 Discussion<\/strong>). Its Keyword, Link limit, and Duplicate guards overlap those, so you can rely on either or both. What it adds on top is the honeypot, timing, signature, and behavioral checks core has no equivalent for, one settings screen with logging, and protection for WooCommerce reviews and Jetpack contact forms \u2014 not just comments.<\/p><\/dd>\n<dt id=\"does%20it%20work%20with%20caching%20plugins%3F\"><h3>Does it work with caching plugins?<\/h3><\/dt>\n<dd><p>Yes. The timing and authenticity checks use a token whose signature does not expire (unlike a WordPress nonce, which would go stale on a cached page and block legitimate visitors), so full-page caching does not produce false positives.<\/p><\/dd>\n<dt id=\"does%20removing%20the%20plugin%20clean%20up%20after%20itself%3F\"><h3>Does removing the plugin clean up after itself?<\/h3><\/dt>\n<dd><p>By default, yes \u2014 deleting the plugin (not just deactivating it) drops its database table, removes all of its options, clears its scheduled task, and purges its transients, on every site of a multisite network. If you would rather keep your settings and logs (for example, before reinstalling), turn off <strong>Delete all plugin data when this plugin is deleted<\/strong> under <strong>Spam Guard \u2192 Settings \u2192 Logging<\/strong> first.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.1.2<\/h4>\n\n<ul>\n<li>Renamed to Onsite Spam Guard. The previous name was too generic and overlapped existing plugins in the directory. Your settings and logs are unaffected by the rename.<\/li>\n<li>Security hardening: the spam-log bulk-delete action now checks the current user's capability directly, in addition to verifying the nonce.<\/li>\n<\/ul>\n\n<h4>1.1.1<\/h4>\n\n<ul>\n<li>Fixed: Jetpack contact form submissions could be wrongly flagged. The plugin inspected everything Jetpack passes its spam filter, which includes site and server metadata \u2014 the site address, the referrer, the page permalink, and request headers. Those count as links and text, so a legitimate submission containing no links of its own could still exceed the link limit, and keywords could match against the browser's user-agent string. Only what the visitor actually submitted is inspected now.<\/li>\n<li>Fixed: the sender's name and email were not read from Jetpack submissions, so the keyword guard never checked them and duplicate detection was less accurate.<\/li>\n<\/ul>\n\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>Settings are now organized into tabs (General, Guards, Allowlist, Logging) to reduce scrolling.<\/li>\n<li>New setting to control whether all plugin data is removed when the plugin is deleted (on by default).<\/li>\n<li>Uninstall now removes the plugin's table, options, transients, and scheduled task on every site of a multisite network, not just the main site.<\/li>\n<\/ul>\n\n<h4>1.0.1<\/h4>\n\n<ul>\n<li>simple_spam_shield_check() accepts the hidden honeypot\/token\/behavioral fields explicitly, so REST\/AJAX endpoints (JSON body, empty $_POST) can pass them from the request.<\/li>\n<li>The time-gate and signature guards skip rather than block when no token is supplied for a custom context, so content-only integrations are not falsely rejected. Built-in comment and review forms still require the token.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release.<\/li>\n<li>Guard pipeline: honeypot, duplicate detection, time gate, signature, link limit, keyword block, and optional behavioral analysis.<\/li>\n<li>Integrations for WordPress comments, WooCommerce product reviews, and Jetpack contact form blocks.<\/li>\n<li>Allowlist supporting IPs, CIDR ranges, email addresses, and email domains, with an optional trusted-proxy mode for IP detection.<\/li>\n<li>Blocked comments and reviews are routed to the spam queue by default (recoverable), with an option to reject them outright instead.<\/li>\n<li>Database-backed logging with a paginated admin viewer and a configurable auto-purge retention window.<\/li>\n<li>Public integration API (simple_spam_shield_check \/ simple_spam_shield_protect_selector \/ simple_spam_shield_field_markup) so other plugins can protect their own forms.<\/li>\n<li>Suggested privacy-policy content and a clean uninstall routine.<\/li>\n<li>Developed by Jerome Wincek, with engineering assistance from Anthropic's Claude.<\/li>\n<\/ul>","raw_excerpt":"Config-driven spam protection for comments, WooCommerce reviews, and Jetpack contact forms \u2014 no external services, API keys, or CAPTCHAs.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/348743","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=348743"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/jeromewincek"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=348743"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=348743"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=348743"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=348743"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=348743"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=348743"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}