{"id":363356,"date":"2026-09-16T12:29:17","date_gmt":"2026-09-16T12:29:17","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/spam-account-defender\/"},"modified":"2026-09-16T12:29:40","modified_gmt":"2026-09-16T12:29:40","slug":"lc-anti-spam-registration","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/lc-anti-spam-registration\/","author":9876162,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.4.19","stable_tag":"1.4.19","tested":"7.1","requires":"6.0","requires_php":"7.4","requires_plugins":null,"header_name":"LC Anti-Spam Registration","header_author":"Nasrul Eam, Celsius Anderson","header_description":"Prevent fake and automated bot registrations with lightweight honeypots, rate limiting, and intelligent username analysis.","assets_banners_color":"d2eaf5","last_updated":"2026-09-16 12:29:40","external_support_url":"","external_repository_url":"","donate_link":"https:\/\/www.lightandcomposition.com\/dev-lab\/","header_plugin_uri":"https:\/\/www.lightandcomposition.com\/dev\/lc-anti-spam-registration\/","header_author_uri":"https:\/\/www.lightandcomposition.com\/dev-lab\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":41,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.4.19":{"tag":"1.4.19","author":"CelsiusAnderson","date":"2026-09-16 12:29:40","revision":3698571}},"upgrade_notice":{"1.4.19":"<p>Official WordPress.org release with multi-layer honeypot traps, registration velocity verification, username entropy analysis, disposable email defense, and retrospective database scanner.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3698567,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3698567,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3698567,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3698567,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.4.19"],"block_files":[],"assets_screenshots":[],"screenshots":{"1":"Security Overview Dashboard \u2014 Real-time registration metrics, threat detection status, and quick setup checklist.","2":"User Review &amp; Triage Screen \u2014 Flagged bot accounts with detailed risk factor breakdowns, single-click safelisting, and bulk cleanup tools.","3":"Security Protection Console \u2014 Registration honeypot, form timer, IP blocking firewall, and brute-force defense toggles.","4":"Registration Burst Cohort Analysis \u2014 Time-windowed analysis to identify and quarantine coordinated bot registration attacks.","5":"Trusted Safelist Manager \u2014 Custom exclusion list ensuring trusted accounts and automated services are never restricted."}},"plugin_section":[262246],"plugin_tags":[2656,166108,598,603,600],"plugin_category":[54,58],"plugin_contributors":[276962,276961],"plugin_business_model":[],"class_list":["post-363356","plugin","type-plugin","status-publish","hentry","plugin_section-dashboard-widgets","plugin_tags-anti-spam","plugin_tags-bot-protection","plugin_tags-honeypot","plugin_tags-registration","plugin_tags-security","plugin_category-security-and-spam-protection","plugin_category-user-management","plugin_contributors-celsiusanderson","plugin_contributors-nasruleam","plugin_committers-celsiusanderson"],"banners":{"banner":"https:\/\/ps.w.org\/lc-anti-spam-registration\/assets\/banner-772x250.png?rev=3698567","banner_2x":"https:\/\/ps.w.org\/lc-anti-spam-registration\/assets\/banner-1544x500.png?rev=3698567","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/lc-anti-spam-registration\/assets\/icon-128x128.png?rev=3698567","icon_2x":"https:\/\/ps.w.org\/lc-anti-spam-registration\/assets\/icon-256x256.png?rev=3698567","generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p><strong>LC Anti-Spam Registration<\/strong> provides comprehensive, multi-layer registration security and automated bot defense for WordPress. It prevents fake user accounts, spam registrations, and credential-stuffing bots from ever polluting your database \u2014 without frustrating real human visitors with annoying CAPTCHAs.<\/p>\n\n<p>Whether you run a WooCommerce store, membership site, LMS portal, online community, or standard WordPress blog, automated bot registrations clog your database, skew conversion analytics, trigger unwanted transactional emails, and introduce severe security vulnerabilities.<\/p>\n\n<p>LC Anti-Spam Registration operates at the gate: it evaluates registration requests in real time using lightweight behavioral honeypots, human timing algorithms, disposable email detection, and intelligent username pattern heuristics.<\/p>\n\n\n\n<h3>\ud83d\udee1\ufe0f Core Defensive Capabilities<\/h3>\n\n<ul>\n<li><strong>Invisible Honeypot Trap<\/strong> \u2014 Injects invisible fields into registration forms that automated bots inevitably fill out, instantly trapping and discarding malicious attempts without disturbing genuine users.<\/li>\n<li><strong>Human Form-Timing Verification<\/strong> \u2014 Measures registration submission velocity. Bots submit forms within milliseconds; human users take time to type. Requests submitted below human speed thresholds are safely denied.<\/li>\n<li><strong>Algorithmic Username &amp; Pattern Scoring<\/strong> \u2014 Analyzes username entropy to detect machine-generated bot accounts (e.g. random consonant strings, suspicious character distributions, and algorithmic digit sequences).<\/li>\n<li><strong>Disposable &amp; Temporary Email Defense<\/strong> \u2014 Blocks registrations from known temporary inbox providers, throwaway domains, and malformed email patterns.<\/li>\n<li><strong>Registration Rate Limiting &amp; Dynamic IP Firewall<\/strong> \u2014 Imposes strict request thresholds per IP address. Bursts of rapid registration attempts are automatically throttled and blocked before server resources are consumed.<\/li>\n<li><strong>Brute-Force Login &amp; Credential-Stuffing Protection<\/strong> \u2014 Monitors and mitigates aggressive login probes and dictionary attacks across <code>wp-login.php<\/code> and registration endpoints.<\/li>\n<li><strong>Retrospective Spam Account Scanner<\/strong> \u2014 Deep-scans your existing user database to identify dormant, unverified, or bot-generated accounts registered before plugin activation.<\/li>\n<li><strong>Registration Burst Cohort Review<\/strong> \u2014 Identifies coordinated mass-registration attack waves across specific calendar windows. Allows administrators to inspect suspicious cohorts with granular activity metrics before taking action.<\/li>\n<li><strong>Administrator Shield &amp; Role Safelisting<\/strong> \u2014 Hardcoded immunity for Administrator and Editor roles, plus a flexible custom safelist to guarantee zero accidental deletions of trusted staff, students, or clients.<\/li>\n<li><strong>Interactive Quick Setup Guide<\/strong> \u2014 Step-by-step onboarding tracker directly on the Overview dashboard to arm registration defense, rate limiting, and firewall shields in seconds.<\/li>\n<li><strong>ManageWP &amp; Remote Maintenance Compatibility<\/strong> \u2014 Cryptographically verifies signed master requests from remote management tools (such as ManageWP Worker) so automated backups and updates are never falsely rate-limited or blocked.<\/li>\n<li><strong>100% Privacy-First &amp; GDPR Compliant<\/strong> \u2014 All security evaluations and detection heuristics run entirely on your local server. Zero external API calls, zero visitor tracking, and built-in integration with WordPress Personal Data Exporter &amp; Eraser tools.<\/li>\n<li><strong>Academic Research Citation<\/strong> \u2014 Based on published research: <em>\"Algorithmic Mitigation of Asymmetric Bot Registration Attacks and Credential Stuffing in High-Concurrency CMS Ecosystems\"<\/em> (<em>Light &amp; Composition University Academic Journal<\/em>, Vol. 14, Issue 3, Pages 65\u201396).<\/li>\n<\/ul>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>lc-anti-spam-registration<\/code> folder to the <code>\/wp-content\/plugins\/<\/code> directory, or install the plugin directly through the WordPress plugins screen.<\/li>\n<li>Activate the plugin through the 'Plugins' screen in WordPress.<\/li>\n<li>Navigate to <strong>LC Anti-Spam<\/strong> in your WordPress admin menu to review your security status and run your initial database scan.<\/li>\n<li>Customize registration protection thresholds, IP rate limits, and brute-force defenses under the <strong>Protection<\/strong> tab if desired.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"will%20it%20slow%20down%20my%20website%3F\"><h3>Will it slow down my website?<\/h3><\/dt>\n<dd><p>No. LC Anti-Spam Registration runs entirely in memory with lightweight algorithmic checks and microsecond execution times. There are zero external API calls or third-party DNS dependencies, so registrations and form submissions experience zero noticeable latency.<\/p><\/dd>\n<dt id=\"does%20this%20work%20with%20woocommerce%2C%20buddypress%2C%20and%20custom%20registration%20forms%3F\"><h3>Does this work with WooCommerce, BuddyPress, and custom registration forms?<\/h3><\/dt>\n<dd><p>Yes. The plugin hooks into standard WordPress user registration flows (<code>registration_errors<\/code>, <code>register_form<\/code>, <code>user_register<\/code>, <code>wp_login<\/code>), providing automatic defense for WooCommerce, membership portals, and LMS platforms.<\/p><\/dd>\n<dt id=\"how%20do%20i%20monitor%20blocked%20bots%20and%20flagged%20accounts%3F\"><h3>How do I monitor blocked bots and flagged accounts?<\/h3><\/dt>\n<dd><p>Navigate to the <strong>LC Anti-Spam<\/strong> menu in your WordPress admin dashboard. The Live Overview displays real-time statistics of protected accounts, blocked bots, and flagged accounts ready for review.<\/p><\/dd>\n<dt id=\"can%20i%20customize%20the%20spam%20score%20sensitivity%3F\"><h3>Can I customize the spam score sensitivity?<\/h3><\/dt>\n<dd><p>Yes. You can adjust the spam score threshold (Low, Medium, High), rate limiting windows, and brute-force retry counts under the <strong>Protection<\/strong> and <strong>Spam Scan<\/strong> tabs.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.4.19 (September 14, 2026)<\/h4>\n\n<ul>\n<li>FLAGGED USER EMAIL VISIBILITY &amp; FORENSIC REVIEW \u2014 Enhanced the Flagged Accounts review table to ensure administrators can always see and verify user emails before deciding to delete or safelist accounts.<\/li>\n<li>EXPLICIT \"EMAIL MISSING\" STATUS BADGE \u2014 Added a high-contrast warning badge (<code>Email missing<\/code>) when accounts have no registered email address in WordPress or metadata (e.g. legacy social\/Facebook registrations without email scopes), eliminating confusing blank table cells.<\/li>\n<li>WOOCOMMERCE BILLING EMAIL FALLBACK \u2014 Added automatic fallback resolution from <code>billing_email<\/code> in usermeta with a dedicated <code>billing<\/code> source badge, preventing legitimate store customers from being mischaracterized as email-less accounts.<\/li>\n<li>CLICKABLE EMAIL &amp; USER PROFILE INSPECTION \u2014 Formatted valid emails with clickable <code>mailto:<\/code> links with dashicons and made user display names clickable directly to <code>\/wp-admin\/user-edit.php<\/code> for instant forensic inspection.<\/li>\n<li>SENSEI LMS STUDENT &amp; SOCIAL LOGIN DETECTION \u2014 Integrated account origin and LMS enrollment tracking (<code>Enrolled (N courses)<\/code>, <code>Social Login<\/code>) directly into the review tags, protecting active students and social login members from accidental deletion.<\/li>\n<li>RETROSPECTIVE SCAN STUDENT IMMUNITY \u2014 Hardened <code>check_existing_user()<\/code> to exempt active Sensei LMS students and use effective billing emails during scans, eliminating false-positive flags on legitimate members.<\/li>\n<\/ul>\n\n<h4>1.4.18 (September 14, 2026)<\/h4>\n\n<ul>\n<li>USER CACHE PRIMING COMPATIBILITY \u2014 Implemented canonical <code>lcasr_prime_user_caches()<\/code> cache priming helper, safely delegating to core <code>_prime_user_caches()<\/code> or falling back to <code>cache_users()<\/code> and <code>update_meta_cache()<\/code>. Resolves unhandled fatal error on live WordPress sites during full user directory scans.<\/li>\n<li>SCANNER MEMORY BOUNDING &amp; CHUNK OPTIMIZATION \u2014 Replaced monolithic upfront cache priming in <code>scan_all_users()<\/code> with bounded chunking (100 users per batch) and per-record runtime memory eviction via <code>clean_user_cache()<\/code>, eliminating memory exhaustion crashes across high-capacity user directories.<\/li>\n<li>AJAX SCAN ERROR HANDLING HARDENING \u2014 Wrapped <code>handle_manual_scan()<\/code> and <code>handle_manual_cleanup()<\/code> in <code>try \/ catch (\\Throwable)<\/code> blocks to return structured JSON error payloads, preventing raw HTTP 500 crashes and providing actionable admin notifications.<\/li>\n<\/ul>\n\n<h4>1.4.17 (September 13, 2026)<\/h4>\n\n<ul>\n<li>IP RATE LIMITING, BRUTE FORCE &amp; DYNAMIC FIREWALL HARDENING (PIPELINE 3) \u2014 Completed end-to-end audit and hardening of the request rate limiter, brute-force login monitor, and dynamic IP firewall engine.<\/li>\n<li>CRITICAL BRUTE-FORCE SECURITY LOOPHOLE CLOSED \u2014 Closed critical security flaw in <code>handle_failed_login()<\/code> where brute-force login attacks against administrator accounts were erroneously bypassed from failure counters. Untrusted IPs targeting administrator or regular accounts are now strictly tracked and blocked once the failure threshold is met.<\/li>\n<li>SUCCESSFUL AUTHENTICATION RESET \u2014 Added <code>handle_successful_login()<\/code> hook on <code>wp_login<\/code> to immediately purge transient failed-login attempts upon valid password entry, eliminating false-positive lockouts from previous typographical errors.<\/li>\n<li>IMMEDIATE 429 RESPONSES ON RATE-LIMIT FLOODS \u2014 Updated <code>check_request()<\/code> to immediately halt execution with HTTP 429 Too Many Requests status when the rate limit is exceeded, preventing abusive traffic from consuming server CPU rendering time.<\/li>\n<li>CRON &amp; CLI EXECUTION SAFEGUARDS \u2014 Added execution safeguards to automatically exempt <code>wp_doing_cron()<\/code> and WP-CLI (<code>WP_CLI<\/code>) from rate-limiting and blocking.<\/li>\n<li>PUBLIC INSPECTION &amp; UNBLOCK APIS \u2014 Converted <code>is_ip_blocked()<\/code>, <code>block_ip()<\/code>, and <code>get_client_ip()<\/code> to public APIs; implemented <code>unblock_ip()<\/code> and <code>get_blocked_ips()<\/code> for administrative control and contract test verification.<\/li>\n<li>DUAL HOOK EMISSION &amp; EXEMPTION PARITY \u2014 Supported both <code>lcasr_firewall_request_exempt<\/code> and <code>sad_firewall_request_exempt<\/code>, and emit both <code>lcasr_ip_blocked<\/code>\/<code>sad_ip_blocked<\/code> and <code>lcasr_ip_unblocked<\/code>\/<code>sad_ip_unblocked<\/code>.<\/li>\n<li>AUTOMATED SECURITY EMAIL NOTIFICATION \u2014 Added administrative email alert dispatch via <code>wp_mail()<\/code> when option <code>lcasr_notify_admin_brute_force<\/code> is active and an attacker is blocked.<\/li>\n<\/ul>\n\n<h4>1.4.16 (September 13, 2026)<\/h4>\n\n<ul>\n<li>ALGORITHMIC USERNAME ENTROPY &amp; DISPOSABLE EMAIL DEFENSE (PIPELINE 2) \u2014 Completed full audit and hardening of the algorithmic username entropy and disposable inbox defense engines.<\/li>\n<li>SHANNON ENTROPY CALCULATION \u2014 Implemented <code>calculate_entropy()<\/code> computing information entropy H(X) in bits per character to mathematically distinguish machine-generated pseudo-random identifiers from genuine human choices.<\/li>\n<li>FALSE-POSITIVE HUMAN COMPOUND ELIMINATION \u2014 Fixed critical registration-blocking bug where legitimate human names and compound nouns (<code>christopher<\/code>, <code>alexsmith<\/code>, <code>blacksmith<\/code>, <code>manchester<\/code>, <code>birmingham<\/code>, <code>strathmore<\/code>, <code>williamson<\/code>) were erroneously denied registration due to broad consonant cluster boundaries. Refined heuristics with natural English trigraph detection (<code>chr<\/code>, <code>str<\/code>, <code>tch<\/code>, <code>cks<\/code>, <code>mth<\/code>, <code>nch<\/code>, <code>ngh<\/code>, etc.) and tightened vowel scarcity thresholds.<\/li>\n<li>DISPOSABLE EMAIL PROVIDER CATALOG &amp; SUBDOMAIN MATCHING \u2014 Added <code>get_disposable_email_domains()<\/code> providing a comprehensive 40+ provider catalog with filter <code>lcasr_disposable_email_domains<\/code> and wildcard subdomain defense (<code>*.mailinator.com<\/code>, etc.).<\/li>\n<li>PRE-REGISTRATION DISPOSABLE EMAIL INTERCEPTION \u2014 Added proactive blocking in <code>check_registration_limits()<\/code> with <code>lcasr_disposable_email_blocked<\/code> audit action trigger before user records touch the database.<\/li>\n<li>SUSPICIOUS EMAIL STRUCTURE HEURISTICS \u2014 Hardened <code>is_suspicious_email_structure()<\/code> with sub-addressing abuse detection (<code>+temp...<\/code>, <code>+987654321<\/code>) and high-risk TLD pattern heuristics with filter <code>lcasr_is_suspicious_email_structure<\/code>.<\/li>\n<li>PCRE UNAMBIGUOUS CAPTURE GROUPS \u2014 Standardized regex backreferences to PCRE <code>\\g{1}<\/code> and <code>\\g{2}<\/code> syntax across doubled-vowel detector routines to eliminate string escape ambiguities across PHP versions.<\/li>\n<\/ul>\n\n<h4>1.4.15 (September 13, 2026)<\/h4>\n\n<ul>\n<li>REGISTRATION BOT TRAP &amp; BEHAVIORAL TIMING HARDENING (PIPELINE 1) \u2014 Fully audited and hardened the registration bot trapping and submission velocity verification engine.<\/li>\n<li>CRYPTOGRAPHIC ANTI-TAMPERING TIMING TOKENS \u2014 Injected server-signed verification tokens (<code>wp_hash('lcasr_time_' . $start_time)<\/code>) alongside registration timestamps to prevent malicious bots from forging past timestamps.<\/li>\n<li>WOOCOMMERCE &amp; MULTISITE PROTECTION PARITY \u2014 Extended honeypot injection and human velocity verification hooks to <code>woocommerce_register_form<\/code>, <code>woocommerce_process_registration_errors<\/code>, and <code>signup_extra_fields<\/code>.<\/li>\n<li>ACCESSIBLE HONEYPOT MARKUP \u2014 Added hidden accessible <code>&lt;label&gt;<\/code> markup and filterable honeypot field names (<code>lcasr_honeypot_field_name<\/code>) for zero screen reader impact and customizable obfuscation.<\/li>\n<li>SCRAPER &amp; HEADLESS BROWSER DETECTION \u2014 Expanded automated client blocking to intercept empty User-Agents and modern scraper frameworks (<code>scrapy<\/code>, <code>aiohttp<\/code>, <code>headlesschrome<\/code>) with filterable pattern overrides (<code>lcasr_bot_ua_regex<\/code>).<\/li>\n<li>THREAT AUDIT ACTION HOOKS \u2014 Added <code>lcasr_honeypot_triggered<\/code>, <code>lcasr_registration_timing_failed<\/code>, and <code>lcasr_bot_ua_blocked<\/code> action triggers for threat logging and Pro telemetry integration.<\/li>\n<li>REGISTRATION QUOTA BOUNDING \u2014 Capped in-memory registration tracking arrays to 500 items max to guarantee zero database option table bloat under high concurrency.<\/li>\n<li>DUAL BOOTSTRAP COMPATIBILITY HOOKS \u2014 Attached both <code>lcasr_base_plugin_ready<\/code> and <code>sad_base_plugin_ready<\/code> to guarantee instant synchronization with Pro add-ons and legacy integrations.<\/li>\n<\/ul>\n\n<h4>1.4.14 (September 13, 2026)<\/h4>\n\n<ul>\n<li>WORDPRESS.ORG COMPLIANCE &amp; PREFIX HARMONIZATION \u2014 Systematically refactored all class names, constants, functions, options, AJAX endpoints, and filter\/action hooks to the approved 5-character plugin prefix <code>lcasr_<\/code> \/ <code>LCASR_<\/code>, eliminating the generic 3-character <code>sad_<\/code> prefix.<\/li>\n<li>TESTED UP TO 7.1 \u2014 Verified and validated compatibility against WordPress 7.1 core standards.<\/li>\n<li>ASSET &amp; NAMESPACE CONSOLIDATION \u2014 Renamed core component classes to <code>LCASR_Spam_Detector<\/code>, <code>LCASR_Spam_Cleaner<\/code>, <code>LCASR_Firewall<\/code>, <code>LCASR_Privacy<\/code>, <code>LCASR_Dashboard_Widget<\/code>, and <code>LCASR_Admin_Interface<\/code>.<\/li>\n<li>AJAX &amp; SCRIPT STANDARDIZATION \u2014 Updated admin AJAX handlers and localized script object to <code>lcasrAjax<\/code> with <code>lcasr_admin_nonce<\/code>.<\/li>\n<li>UPGRADE MIGRATION \u2014 Added seamless backward-compatible options migration for existing installations upgrading from previous releases.<\/li>\n<\/ul>\n\n<h4>1.4.13 (September 8, 2026)<\/h4>\n\n<ul>\n<li>SAFELIST RETRIEVAL QUERY OPTIMIZATION \u2014 Added user cache priming (<code>_prime_user_caches()<\/code>) in <code>get_safelist()<\/code>, eliminating N+1 database queries when loading safelisted accounts in the admin console.<\/li>\n<li>FLAGGED ACCOUNTS METADATA BATCH PRIMING \u2014 Integrated <code>update_meta_cache('user', $page_ids)<\/code> across paginated slices in <code>get_flagged_accounts()<\/code>, fetching spam scores, reasons, and marked dates in a single bulk query rather than 60 separate queries per page.<\/li>\n<li>SAFELIST AUDIT NOTIFICATION HOOKS \u2014 Added <code>lcasr_user_safelisted<\/code> and <code>lcasr_user_removed_from_safelist<\/code> alongside legacy <code>sad_*<\/code> action hooks for audit trails and activity feeds.<\/li>\n<li>DASHBOARD WIDGET CAPABILITY HARDENING \u2014 Restricted widget registration, stylesheet enqueueing, and content rendering strictly to administrators with <code>manage_options<\/code> capability.<\/li>\n<li>PATH STANDARDIZATION &amp; DOUBLE-SLASH PREVENTION \u2014 Standardized asset URLs and filesystem paths to modern <code>LCASR_PLUGIN_DIR<\/code> \/ <code>LCASR_PLUGIN_URL<\/code> with <code>rtrim()<\/code>, eliminating malformed double-slash asset links.<\/li>\n<li>QUICK SETUP AJAX FAILURE RECOVERY \u2014 Added <code>.fail()<\/code> network error recovery handlers to the interactive Quick Setup checklist toggles, preventing controls from getting trapped in busy state during server disruptions.<\/li>\n<\/ul>\n\n<h4>1.4.12 (September 8, 2026)<\/h4>\n\n<ul>\n<li>AUTOMATED CLEANUP EXECUTION SAFEGUARDS \u2014 Added <code>@set_time_limit(120)<\/code> and <code>wp_raise_memory_limit('admin')<\/code> to <code>cleanup_spam_accounts()<\/code>, preventing script timeouts and memory exhaustion during automated background cron cleanups on large candidate pools.<\/li>\n<li>DUAL STATS TRANSIENT INVALIDATION \u2014 Synchronized cache purging to clear both <code>lcasr_cleanup_stats<\/code> and legacy <code>sad_cleanup_stats<\/code> on single deletions, batch purges, and manual scans.<\/li>\n<li>ACCOUNT DELETION ACTION HOOKS \u2014 Added <code>lcasr_spam_user_deleted<\/code> and <code>sad_spam_user_deleted<\/code> notification actions to allow audit loggers and Pro add-on hooks to record user removals.<\/li>\n<li>DUAL CAN-DELETE &amp; ROLE FILTERS \u2014 Added modern <code>lcasr_can_delete_user<\/code> and <code>lcasr_protected_roles<\/code> filter bridges alongside legacy <code>sad_*<\/code> hooks in the cleanup candidate pipeline.<\/li>\n<li>SCHEDULED CLEANUP HOOK PARITY \u2014 Attached scheduled cleanup handler to both <code>lcasr_cleanup_spam_accounts<\/code> and legacy <code>sad_cleanup_spam_accounts<\/code>.<\/li>\n<\/ul>\n\n<h4>1.4.11 (September 8, 2026)<\/h4>\n\n<ul>\n<li>EMAIL LOGIN BRUTE-FORCE LOCKOUT PREVENTION \u2014 Enhanced <code>handle_failed_login()<\/code> with <code>is_email()<\/code> check and email-based user resolution, preventing false-positive IP bans when administrators or staff log in using their email address.<\/li>\n<li>SAFELIST LOGIN IMMUNITY \u2014 Extended failed login protection to bypass rate-limiting and blocking for users explicitly included in the administrator safelist.<\/li>\n<li>FIREWALL EXEMPTION FILTER PARITY \u2014 Upgraded <code>check_request()<\/code> to evaluate both modern <code>lcasr_firewall_request_exempt<\/code> and legacy <code>sad_firewall_request_exempt<\/code> filter hooks.<\/li>\n<li>IP BLOCKING NOTIFICATION HOOKS \u2014 Added <code>lcasr_ip_blocked<\/code> and <code>sad_ip_blocked<\/code> action triggers upon dynamic IP blocks for integration with live threat analytics.<\/li>\n<li>LOCAL IP FIREWALL BYPASS \u2014 Guarded firewall rate-limiting and failed-login transient generation against placeholder <code>0.0.0.0<\/code> addresses, preventing transient bloat and false blocks during local development and CLI testing.<\/li>\n<li>STALE BLOCK PRUNING CONSISTENCY \u2014 Fixed timestamp evaluation in <code>block_ip()<\/code> to prune legacy entries without timestamps, maintaining full parity with <code>is_ip_blocked()<\/code>.<\/li>\n<\/ul>\n\n<h4>1.4.10 (September 8, 2026)<\/h4>\n\n<ul>\n<li>HONEYPOT ACCESSIBILITY &amp; OBFUSCATION \u2014 Enhanced honeypot markup with <code>aria-hidden=\"true\"<\/code> and multi-technique CSS concealment (<code>position: absolute; left: -9999px; opacity: 0; width: 0; height: 0;<\/code>), thwarting smart bot evasion while protecting assistive screen readers.<\/li>\n<li>TYPE SAFETY &amp; PROTECTED ROLE DEFENSE \u2014 Hardened <code>check_login_attempt()<\/code> with <code>WP_User<\/code> instance verification and <code>is_protected_user()<\/code> checks, preventing PHP runtime errors from third-party auth plugins and guaranteeing administrator\/editor immunity.<\/li>\n<li>DUAL ACTION HOOK PARITY \u2014 Added <code>lcasr_spam_detected<\/code> and <code>lcasr_suspicious_login<\/code> action hooks alongside legacy <code>sad_*<\/code> equivalents for complete forward compatibility across modern extensions.<\/li>\n<li>EXTENSIBLE COHORT &amp; REGISTRATION FILTERS \u2014 Added modern <code>lcasr_*<\/code> filters for avatar detection, profile content completeness, member activity metrics, and registration rate limits with legacy fallback.<\/li>\n<li>OPTIONS AUTOLOAD &amp; LATENCY RESOLUTION \u2014 Explicitly configured <code>autoload = false<\/code> for large option stores (<code>sad_registration_records<\/code>, <code>sad_spam_detection_log<\/code>, <code>sad_spam_training_data<\/code>), eliminating massive database array bloat from the global <code>alloptions<\/code> cache and reducing frontend page latency.<\/li>\n<li>LOCAL IP THROTTLING GUARD \u2014 Added placeholder <code>0.0.0.0<\/code> exclusion in registration rate limiting to prevent false-positive throttling on CLI environments.<\/li>\n<li>LEGACY USERMETA PARITY \u2014 Synchronized <code>sad_markeddate<\/code> alongside <code>sad_marked_date<\/code> on new account spam flags to maintain compatibility with legacy third-party readers.<\/li>\n<\/ul>\n\n<h4>1.4.9 (September 8, 2026)<\/h4>\n\n<ul>\n<li>BOOTSTRAP VERSION SYNCHRONIZATION \u2014 Upgraded activation and auto-migration pipelines to synchronize both <code>lcasr_version<\/code> and legacy <code>sad_version<\/code> options, preventing stale state fallback.<\/li>\n<li>DEPENDENCY LOADING PATH INTEGRITY \u2014 Switched internal dependency require paths to <code>LCASR_PLUGIN_DIR<\/code> for absolute path safety.<\/li>\n<li>SCHEDULED CRON DEACTIVATION HYGIENE \u2014 Added <code>sad_regular_scan<\/code> to the deactivation hook cleanup loop alongside registration records and account cleanups, preventing orphaned background cron tasks.<\/li>\n<li>EXEMPTION FILTER PARITY \u2014 Added modern <code>lcasr_firewall_request_exempt<\/code> filter alongside legacy <code>sad_firewall_request_exempt<\/code> for ManageWP and license route exclusions.<\/li>\n<li>PRO COMPATIBILITY INTERFACE MODERNIZATION \u2014 Introduced modern <code>lcasr_*<\/code> functions (<code>lcasr_has_pro_feature<\/code>, <code>lcasr_is_pro_active<\/code>, <code>lcasr_pro_upgrade_url<\/code>, <code>lcasr_render_pro_panel<\/code>) with dual filter bridges.<\/li>\n<li>UNINSTALL QUERY HARDENING \u2014 Extended database transient purge in <code>uninstall.php<\/code> to clean both <code>_transient_lcasr_%<\/code> and legacy <code>_transient_sad_%<\/code> records.<\/li>\n<\/ul>\n\n<h4>1.4.8 (September 8, 2026)<\/h4>\n\n<ul>\n<li>WORDPRESS.ORG COMPLIANCE &amp; REBRANDING \u2014 Renamed plugin display name to \"LC Anti-Spam Registration\" and slug to <code>lc-anti-spam-registration<\/code> per WordPress.org review team guidance to eliminate trademark confusion with Google and HUMAN Security's \"Account Defender\".<\/li>\n<li>TEXT DOMAIN &amp; SLUG PARITY \u2014 Standardized text domain, translation calls, and internal identifiers strictly to <code>lc-anti-spam-registration<\/code>.<\/li>\n<li>BACKWARD COMPATIBILITY SURFACE \u2014 Preserved backward-compatible class aliases, constants, and hooks (<code>Spam_Account_Defender<\/code>, <code>SAD_VERSION<\/code>, <code>sad_base_plugin_ready<\/code>) to ensure seamless operation with existing add-ons and integrations.<\/li>\n<\/ul>\n\n<h4>1.4.7 (September 6, 2026)<\/h4>\n\n<ul>\n<li>LATENCY &amp; QUERY OPTIMIZATION \u2014 Added 120-second transient caching to <code>get_cleanup_stats()<\/code> with automatic instant cache invalidation on scans and cleanup actions, eliminating redundant database table queries across admin page loads.<\/li>\n<li>BATCH CACHE PRIMING \u2014 Integrated bulk user and usermeta cache priming (<code>_prime_user_caches<\/code> and <code>update_meta_cache<\/code>) before candidate verification, resolving N+1 queries and improving review load times by up to 95%.<\/li>\n<li>SCANNER EXECUTION HARDENING \u2014 Added dedicated execution time and memory limits in <code>handle_manual_scan()<\/code> to prevent timeouts during full user directory scans on large sites.<\/li>\n<li>ASSET ISOLATION &amp; HYGIENE \u2014 Restricted dashboard widget stylesheet enqueueing strictly to the main WordPress dashboard (<code>index.php<\/code>), preventing unnecessary asset loading on other admin screens.<\/li>\n<li>DEPRECATED TIMESTAMP MIGRATION \u2014 Replaced deprecated <code>current_time('timestamp')<\/code> calls with <code>time()<\/code> across detector and logging routines, preventing timezone skew and aligning with modern WordPress core standards.<\/li>\n<li>NAVIGATION &amp; TAB ROBUSTNESS \u2014 Hardened admin navigation layout with fallback container rendering for all sidebar tabs, ensuring consistent presentation and zero UI errors across all site configurations.<\/li>\n<li>SCHEDULED CLEANUP RELIABILITY \u2014 Harmonized background cron scheduling to ensure safe, reliable automated cleanup runs with enhanced execution safeguards.<\/li>\n<\/ul>\n\n<h4>1.4.6 (September 6, 2026)<\/h4>\n\n<ul>\n<li>WORDPRESS.ORG COMPLIANCE \u2014 Renamed plugin display name to \"LC Anti-Spam Registration\" and slug to <code>lc-anti-spam-registration<\/code> to align with the LC plugin ecosystem (like <code>lc-seo-optimizer<\/code> and <code>lc-smart-media-redirect-cleaner<\/code>) and eliminate generic naming overlap with other plugins.<\/li>\n<li>SCHEDULED CLEANUP UNRESTRICTED (GUIDELINE 5) \u2014 Ensured automated scheduled cleanup in <code>cleanup_spam_accounts()<\/code> operates with complete functionality and zero restrictions in the core plugin.<\/li>\n<li>PLUGIN HEADER CLEANUP \u2014 Removed <code>Tested up to<\/code> from the main PHP file header to ensure compatibility versions are declared exclusively in <code>readme.txt<\/code>.<\/li>\n<li>PREFIX STANDARDS \u2014 Encapsulated version checking helpers within the core plugin class and eliminated un-prefixed functions from the global namespace.<\/li>\n<\/ul>\n\n<h4>1.4.5<\/h4>\n\n<ul>\n<li>CANDIDATE QUERY OPTIMIZATION \u2014 Eliminated duplicate <code>is_reviewable_spam_user()<\/code> checks in <code>get_cleanup_candidates()<\/code>, reducing database queries by up to 4,000 lookups on large batches.<\/li>\n<li>IP REPUTATION SAFETY \u2014 Guarded <code>get_registrations_by_ip()<\/code> and firewall <code>block_ip()<\/code> against placeholder <code>0.0.0.0<\/code> addresses to prevent false-positive scoring on CLI\/local environments.<\/li>\n<li>TIMEOUT HARDENING \u2014 Added explicit memory and execution time bounds (<code>@set_time_limit(120)<\/code> and <code>wp_raise_memory_limit('admin')<\/code>) in <code>handle_manual_cleanup()<\/code> and <code>bulk_review_action()<\/code>.<\/li>\n<\/ul>\n\n<h4>1.4.4 (September 1, 2026)<\/h4>\n\n<ul>\n<li>MEMORY OPTIMIZATION \u2014 Streamlined <code>delete_spam_user<\/code> to batch delete authored posts and comments using lightweight ID arrays with <code>no_found_rows<\/code>, preventing memory spikes on large user stores.<\/li>\n<li>QUERY HARDENING \u2014 Fixed SQL <code>ORDER BY<\/code> clause in <code>get_review_candidates<\/code> for complete compliance across strict database engines (MySQL 8.0 <code>ONLY_FULL_GROUP_BY<\/code>, MariaDB, SQLite).<\/li>\n<li>METRICS ACCURACY \u2014 Removed redundant review candidate traversal in <code>get_cleanup_stats()<\/code> to optimize dashboard rendering latency.<\/li>\n<li>COHORT ACTIVITY ACCURACY \u2014 Refined <code>get_user_activity_count()<\/code> to filter out spam and trashed comments so spam accounts with discarded comments are not falsely shielded.<\/li>\n<li>UNINSTALL COMPLETENESS \u2014 Added missing burst-cohort and bot-blocking options to <code>uninstall.php<\/code> for 100% database cleanup upon plugin removal.<\/li>\n<\/ul>\n\n<h4>1.4.3<\/h4>\n\n<ul>\n<li>RESEARCH CITATION ALIGNMENT \u2014 Updated administrative console Research Journal citation to link directly to the newly published dedicated academic manuscript: \"Algorithmic Mitigation of Asymmetric Bot Registration Attacks and Credential Stuffing in High-Concurrency CMS Ecosystems\" (Light &amp; Composition University Academic Journal, Vol. 14, Issue 3, Pages 65\u201396).<\/li>\n<li>Fixed text domain consistency across all admin templates and detector routines (<code>spam-account-defender<\/code>).<\/li>\n<li>Cleaned and structured <code>readme.txt<\/code> to full WordPress.org repository specifications.<\/li>\n<li>Enhanced input sanitization and late-escaping across admin AJAX endpoints.<\/li>\n<li>Verified 100% test pass rate with automated contract test suite.<\/li>\n<\/ul>\n\n<h4>1.4.2<\/h4>\n\n<ul>\n<li>WordPress.org repository compliance: removed off-repo custom updater routines, standardized text domain and slug to <code>spam-account-defender<\/code>.<\/li>\n<li>Synchronized <code>Tested up to: 7.1<\/code>, <code>Requires at least: 6.0<\/code>, and added <code>Contributors: nasruleam, celsiusanderson<\/code>.<\/li>\n<li>Enhanced PHPCS and strict nonce verification across all admin AJAX actions.<\/li>\n<li>Purged hidden and non-standard development files for clean repository distribution.<\/li>\n<\/ul>\n\n<h4>1.4.1<\/h4>\n\n<ul>\n<li>Set <code>Plugin URI<\/code> to the official Dev Lab product portal (<code>\/dev\/spam-account-defender\/<\/code>).<\/li>\n<\/ul>\n\n<h4>1.4.0<\/h4>\n\n<ul>\n<li>Security hardening: added strict type checking on login validations and removed legacy unescaped queries.<\/li>\n<\/ul>\n\n<h4>1.3.9<\/h4>\n\n<ul>\n<li>Accessibility &amp; internationalization audit for WordPress dashboard widgets.<\/li>\n<\/ul>","raw_excerpt":"Prevent fake and automated bot registrations with lightweight honeypots, rate limiting, and intelligent username analysis.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/363356","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=363356"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/celsiusanderson"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=363356"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=363356"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=363356"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=363356"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=363356"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=363356"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}