{"id":341941,"date":"2026-09-01T07:56:18","date_gmt":"2026-09-01T07:56:18","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/elastic-spam-shield\/"},"modified":"2026-09-01T08:48:35","modified_gmt":"2026-09-01T08:48:35","slug":"spamify","status":"publish","type":"plugin","link":"https:\/\/es-ec.wordpress.org\/plugins\/spamify\/","author":23532320,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.0","stable_tag":"1.0.0","tested":"7.1","requires":"5.8","requires_php":"7.4","requires_plugins":null,"header_name":"Spamify - Elastic Spam Shield","header_author":"arslanwp","header_description":"Self-contained spam &amp; email validation for WordPress forms: syntax + optional mailbox checks, honeypot, rate limiting, and CAPTCHA.","assets_banners_color":"efeffc","last_updated":"2026-09-01 08:48:35","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/spamify-pro.github.io","header_author_uri":"https:\/\/profiles.wordpress.org\/arslanwp\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":71,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"arslanwp","date":"2026-09-01 08:48:35","revision":3675688}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3675590,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3675590,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256},"icon.svg":{"filename":"icon.svg","revision":3675590,"resolution":false,"location":"assets","locale":false}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3675662,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3675662,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.0"],"block_files":[],"assets_screenshots":[],"screenshots":[]},"plugin_section":[262246],"plugin_tags":[2656,358,2182,1178,599],"plugin_category":[54],"plugin_contributors":[278616,278617],"plugin_business_model":[],"class_list":["post-341941","plugin","type-plugin","status-publish","hentry","plugin_section-dashboard-widgets","plugin_tags-anti-spam","plugin_tags-contact-form","plugin_tags-email-validation","plugin_tags-protection","plugin_tags-spam","plugin_category-security-and-spam-protection","plugin_contributors-arslanwp","plugin_contributors-wparslan","plugin_committers-arslanwp"],"banners":{"banner":"https:\/\/ps.w.org\/spamify\/assets\/banner-772x250.png?rev=3675662","banner_2x":"https:\/\/ps.w.org\/spamify\/assets\/banner-1544x500.png?rev=3675662","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":"https:\/\/ps.w.org\/spamify\/assets\/icon.svg?rev=3675590","icon":"https:\/\/ps.w.org\/spamify\/assets\/icon.svg?rev=3675590","icon_2x":false,"generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p>Spamify is a lightweight, self-contained email spam and validation plugin for WordPress forms. It scores every submitted email address and blocks or flags the ones that look fake, invalid, or abusive \u2014 without sending your visitors' data to any tracking service.<\/p>\n\n<p>Out of the box the plugin runs entirely on your own server. It never sends your data to the plugin author or to any analytics or tracking service, and it does not require an account or a licence key. One optional feature \u2014 live mailbox verification \u2014 reaches out to the recipient's own mail server, and it is turned <strong>off by default<\/strong> (see <em>External Services<\/em> below).<\/p>\n\n<p><strong>Detection layers:<\/strong><\/p>\n\n<ul>\n<li><strong>Syntax<\/strong> \u2013 Validates the email format and catches gibberish, keyboard-mash, and obviously fake addresses. Runs locally, always on.<\/li>\n<li><strong>SMTP mailbox verification<\/strong> <em>(optional, off by default)<\/em> \u2013 Connects to the recipient domain's mail server and asks whether the mailbox exists. No message is ever sent.<\/li>\n<\/ul>\n\n<p><strong>Bot protection &amp; security (all local, all free):<\/strong><\/p>\n\n<ul>\n<li><strong>Honeypot &amp; timing<\/strong> \u2013 Hidden decoy fields plus a minimum form-fill time catch automated submissions.<\/li>\n<li><strong>Rate limiting<\/strong> \u2013 Throttle how many submissions a single IP can make within a rolling window.<\/li>\n<li><strong>CAPTCHA<\/strong> <em>(optional)<\/em> \u2013 Invisible Cloudflare Turnstile or Google reCAPTCHA v3, using your own free provider keys.<\/li>\n<li><strong>Allowlist<\/strong> \u2013 Always let trusted domains, exact email addresses, or IP \/ CIDR ranges through.<\/li>\n<li><strong>Hide login<\/strong> <em>(optional)<\/em> \u2013 Move wp-login.php to an address of your choice and serve a 404 (or a redirect) at the old one <strong>and at \/wp-admin\/<\/strong> (WordPress normally bounces logged-out visitors from \/wp-admin\/ to the login screen, which would give the secret address away), so brute-force bots have nothing to hammer. Every login, logout, lost-password and registration link \u2014 including the ones inside WordPress emails \u2014 is rewritten for you. Multisite compatible: each site in a network keeps its own address, subdirectory installs get the slug under their own folder, and a single <code>SPAMIFY_HIDE_LOGIN_SLUG<\/code> constant in wp-config.php can enforce one address network-wide.<\/li>\n<\/ul>\n\n<p><strong>Privacy &amp; administration:<\/strong><\/p>\n\n<ul>\n<li><strong>GDPR tools<\/strong> \u2013 Automatic daily log purge by retention window, plus optional IP anonymisation.<\/li>\n<li><strong>Site Health<\/strong> \u2013 Built-in WordPress Site Health checks for logging, DNS, and mailbox verification.<\/li>\n<li><strong>Setup wizard<\/strong> \u2013 A guided first-run wizard to get protected in about a minute.<\/li>\n<li><strong>Dashboard &amp; logs<\/strong> \u2013 See what was blocked, flagged, and allowed, with per-day charts.<\/li>\n<\/ul>\n\n<p><strong>Supported forms:<\/strong><\/p>\n\n<ul>\n<li>WordPress core (registration, comments, profile update, lost password, multisite signup)<\/li>\n<li>Contact Form 7<\/li>\n<li>WPForms<\/li>\n<li>Jetpack Forms<\/li>\n<li>Elementor Forms<\/li>\n<\/ul>\n\n<h3>Upgrade to Pro<\/h3>\n\n<p>Spamify is free forever on WordPress.org \u2014 everything described above runs standalone, with no account, licence key, or nag screens required.<\/p>\n\n<p><strong><a href=\"https:\/\/spamify-pro.github.io\/\">Spamify Pro<\/a><\/strong> adds the rest of the detection engine and site-wide protection tools for busier or higher-traffic sites:<\/p>\n\n<ul>\n<li><strong>Disposable domain blocking<\/strong> \u2013 100,000+ throwaway and temporary-inbox providers, refreshed automatically.<\/li>\n<li><strong>IP threat intel &amp; DNSBL<\/strong> \u2013 matches the sender's IP against aggregated abuse feeds and DNS blocklists.<\/li>\n<li><strong>VPN \/ proxy \/ Tor detection<\/strong> \u2013 flags anonymised traffic from VPNs, open proxies, Tor exit nodes and datacenter ranges.<\/li>\n<li><strong>Content analysis<\/strong> \u2013 link stuffing, spam keywords, homoglyph and Unicode obfuscation.<\/li>\n<li><strong>Behavioural reputation<\/strong> \u2013 per-sender history layered on top of honeypot and timing.<\/li>\n<li><strong>Custom rules<\/strong> \u2013 your own if-this-then-that logic on any field or signal.<\/li>\n<li><strong>Network firewall<\/strong> \u2013 VPN\/Tor\/ASN blocking with escalating temporary bans.<\/li>\n<li><strong>Geo report &amp; country blocking<\/strong> \u2013 a world map of where blocked spam comes from, powered by a free offline database.<\/li>\n<li><strong>Uptime monitor &amp; deliverability tools<\/strong> \u2013 scheduled URL checks, bulk email-list verification, and an SPF\/DKIM\/DMARC checker.<\/li>\n<li><strong>More integrations<\/strong> \u2013 WooCommerce, Gravity Forms, Ninja Forms, Fluent Forms, newsletter opt-ins, and a universal connector for any form.<\/li>\n<\/ul>\n\n<p>Plans start at $49\/year for up to 3 sites, with Agency and Lifetime options for larger portfolios. <strong><a href=\"https:\/\/spamify-pro.github.io\/#pricing\">Buy Spamify Pro \u2192<\/a><\/strong><\/p>\n\n<h3>External Services<\/h3>\n\n<p>Spamify is self-contained by default. Two <strong>optional<\/strong> features connect to an external service only after you explicitly enable and configure them. Neither sends any data to the plugin author, and neither is active on a fresh install.<\/p>\n\n<p><strong>1. SMTP mailbox verification (optional, disabled by default)<\/strong><\/p>\n\n<p>When you turn on <em>SMTP Verification<\/em> (Settings \u2192 Advanced Filters), the plugin opens a direct connection to the mail server (MX host) of the <strong>recipient email address's own domain<\/strong> and performs an SMTP handshake to check whether the mailbox exists. What is sent: the email address being validated, sent only to that address's own mail provider, and only at the moment a form containing that address is submitted or checked. No email message is ever sent, and no data is sent to the plugin author or to any third-party service. Because each address is verified against its own provider's server, there is no single service, account, terms of service, or privacy policy involved. Leave this feature off if you prefer that submitted addresses are never contacted.<\/p>\n\n<p><em>Outbound-port connectivity probe.<\/em> Many hosts block outbound port 25, which makes mailbox verification impossible. To detect this, the plugin makes a one-off TCP connection to a well-known public mail server \u2014 by default Google's inbound MX, <code>gmail-smtp-in.l.google.com<\/code> on port 25 \u2014 and closes it immediately <strong>without sending any data<\/strong>. Only a yes\/no \"is port 25 open\" result is kept (cached for up to a week). This probe runs when SMTP verification is enabled, and when you open the Advanced settings tab or the Tools \u2192 Site Health screen (so the status can be shown). No personal data is transmitted. You can change or disable the probe host with the <code>spamify_port25_probe_host<\/code> filter.<\/p>\n\n<p><strong>2. CAPTCHA verification (optional, disabled by default)<\/strong><\/p>\n\n<p>If you enable CAPTCHA (Settings \u2192 Bot Protection) and enter your own provider keys, the visitor's CAPTCHA token is sent to your chosen provider's verification endpoint so the provider can confirm the visitor is human:<\/p>\n\n<ul>\n<li><strong>Cloudflare Turnstile<\/strong> \u2013 token sent to <code>https:\/\/challenges.cloudflare.com\/turnstile\/v0\/siteverify<\/code>. Terms: https:\/\/www.cloudflare.com\/website-terms\/ \u2014 Privacy: https:\/\/www.cloudflare.com\/privacypolicy\/<\/li>\n<li><strong>Google reCAPTCHA v3<\/strong> \u2013 token sent to <code>https:\/\/www.google.com\/recaptcha\/api\/siteverify<\/code>. Terms: https:\/\/policies.google.com\/terms \u2014 Privacy: https:\/\/policies.google.com\/privacy<\/li>\n<\/ul>\n\n<p>Only the CAPTCHA token and the visitor IP are sent, only on form submission, and only if you have configured a provider. This feature is off until you supply keys.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>spamify<\/code> folder to the <code>\/wp-content\/plugins\/<\/code> directory, or install it through the Plugins screen in WordPress.<\/li>\n<li>Activate the plugin through the <strong>Plugins<\/strong> menu in WordPress.<\/li>\n<li>Open <strong>Spamify<\/strong> in the admin menu and follow the setup wizard to configure protection.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20this%20plugin%20send%20any%20data%20to%20your%20servers%3F\"><h3>Does this plugin send any data to your servers?<\/h3><\/dt>\n<dd><p>No. Spamify never contacts the plugin author's servers, and it sends no data to any analytics or tracking service. It runs on your own site. The only outbound connections are those described in <em>External Services<\/em> \u2014 SMTP mailbox verification and its port-25 connectivity probe (verification is off by default), and CAPTCHA verification (off until you add your own keys).<\/p><\/dd>\n<dt id=\"is%20smtp%20verification%20required%3F\"><h3>Is SMTP verification required?<\/h3><\/dt>\n<dd><p>No. It is off by default. The plugin still validates syntax and protects your forms with the honeypot, timing, rate-limiting, allowlist, and CAPTCHA features without it.<\/p><\/dd>\n<dt id=\"which%20php%20version%20is%20required%3F\"><h3>Which PHP version is required?<\/h3><\/dt>\n<dd><p>PHP 7.4 or higher.<\/p><\/dd>\n<dt id=\"why%20are%20some%20submissions%20marked%20%22unverifiable%22%3F\"><h3>Why are some submissions marked \"unverifiable\"?<\/h3><\/dt>\n<dd><p>Many hosts block outbound port 25, and many mail servers greylist or use catch-all addresses, so a mailbox cannot always be confirmed. By default these are flagged for review rather than blocked; you can change this in Settings.<\/p><\/dd>\n<dt id=\"is%20there%20a%20pro%20version%3F\"><h3>Is there a Pro version?<\/h3><\/dt>\n<dd><p>Yes. <a href=\"https:\/\/spamify-pro.github.io\/\">Spamify Pro<\/a> adds the rest of the detection engine (disposable-domain blocking, IP threat intel, VPN\/Tor detection, content analysis, custom rules), a network firewall, a geo report, deliverability tools, and integrations for WooCommerce, Gravity Forms, Ninja Forms and Fluent Forms. The free version on WordPress.org is fully functional on its own and is not a limited trial. See <a href=\"https:\/\/spamify-pro.github.io\/\">spamify-pro.github.io<\/a> or <strong><a href=\"https:\/\/spamify-pro.github.io\/#pricing\">Buy Spamify Pro<\/a><\/strong>.<\/p><\/dd>\n<dt id=\"i%20hid%20my%20login%20page%20and%20locked%20myself%20out.%20what%20now%3F\"><h3>I hid my login page and locked myself out. What now?<\/h3><\/dt>\n<dd><p>Add <code>define( 'SPAMIFY_HIDE_LOGIN_DISABLE', true );<\/code> to your wp-config.php. wp-login.php works normally again, and you can change or switch off the setting from Protection \u2192 Hide login.<\/p><\/dd>\n<dt id=\"does%20hiding%20the%20login%20work%20on%20multisite%3F\"><h3>Does hiding the login work on multisite?<\/h3><\/dt>\n<dd><p>Yes. Every site in the network sets its own address on its own Protection screen, and on a subdirectory network the address lives under that site's folder (example.com\/team\/secret-login\/). To use one address everywhere, add <code>define( 'SPAMIFY_HIDE_LOGIN_SLUG', 'secret-login' );<\/code> to wp-config.php. wp-signup.php and wp-activate.php stay reachable so registration and activation keep working. The feature needs pretty permalinks.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release.<\/li>\n<li>Feature: Hide login \u2014 serve wp-login.php from a custom address and answer the old one, plus \/wp-admin\/ for logged-out visitors, with the theme's 404 page, a home-page redirect, or a URL of your choice. All generated login\/logout\/lost-password\/registration links are rewritten automatically.<\/li>\n<li>Multisite: per-site login addresses, subdirectory-network aware matching, network-level links resolve against the main site, and an optional <code>SPAMIFY_HIDE_LOGIN_SLUG<\/code> constant enforces one address across the whole network.<\/li>\n<li>Major: syntax validation, optional SMTP mailbox verification (off by default), honeypot &amp; timing, per-IP rate limiting, allowlist, invisible CAPTCHA (bring your own keys), GDPR log tools, Site Health checks, and a setup wizard. Integrations for WordPress core forms, Contact Form 7, WPForms, Jetpack Forms, and Elementor Forms.<\/li>\n<\/ul>","raw_excerpt":"Self-contained email validation and spam protection for WordPress forms. Syntax + optional mailbox checks, honeypot, rate limiting and CAPTCHA.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/es-ec.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/341941","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/es-ec.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/es-ec.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/es-ec.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=341941"}],"author":[{"embeddable":true,"href":"https:\/\/es-ec.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/arslanwp"}],"wp:attachment":[{"href":"https:\/\/es-ec.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=341941"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/es-ec.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=341941"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/es-ec.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=341941"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/es-ec.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=341941"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/es-ec.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=341941"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/es-ec.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=341941"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}