ActiveLayer Anti-Spam
Anti-Spam Protection Without CAPTCHAs ActiveLayer is an intelligent anti-spam solution that stops contact form spam, comment spam, and registration spam without CAPTCHAs, puzzles, or extra steps for your visitors. Your forms stay fast and frictionless while unwanted messages get caught automatically. Your time and attention are expensive — stop spending them on spam. ActiveLayer protects popular form builders like WPForms, Contact Form 7, Gravity Forms, Elementor Forms, Fluent Forms, WS Form, and FunnelKit Funnel Builder, plus native WordPress comments, WooCommerce (product reviews and customer registration), Easy Digital Downloads (store reviews and customer registration), AffiliateWP, MemberPress, and BuddyPress / BuddyBoss signup forms, all from a single plugin. With 18 integrations, you manage all your spam protection from one settings page. Create a free account and get started Zero Friction Spam Filtering Most anti-spam tools either show visitors a CAPTCHA or make every form wait while the check runs. ActiveLayer takes a different approach. Async integrations complete immediately while background checks run through Action Scheduler; registration and inline-blocking integrations can run a synchronous check when spam must be stopped before an account, entry, or affiliate record is created. This keeps normal form workflows fast while still allowing high-risk signup flows to block spam inline. If a submission is clean, notifications are sent as normal. If it is flagged, notifications are suppressed or the signup is blocked depending on the integration. Intelligent Spam Detection ActiveLayer analyzes submission patterns, content reputation, behavioral signals, and environment data to catch both automated bots and human bad actors with high accuracy. Unlike simple honeypot or keyword-blocklist approaches, ActiveLayer uses multiple signals to make smarter decisions about every submission. Optional behavioral tracking monitors how users interact with your forms — keystrokes, mouse movements, touch events, and scroll patterns. Environment detection identifies headless browsers and automated tools. These client-side signals are sent alongside form data for deeper analysis. Per-Form Control and Sync Mode You decide exactly which forms to protect. ActiveLayer protects all supported forms and WooCommerce surfaces by default after your API key is connected — you can disable protection per form if needed. This gives you granular control over every contact form, registration form, or comment section on your site. Sync Mode lets supported integrations wait for the API verdict before the submission completes, so spam can be blocked inline. By default, ActiveLayer runs checks asynchronously for maximum speed. Turn Sync Mode on when you prefer inline blocking and can tolerate a small added latency on submissions. Fail-Safe by Design If the ActiveLayer API is temporarily unavailable, your forms keep working. ActiveLayer is designed to fail open — it restores provider defaults, preserves every submission, and retries background checks automatically when connectivity returns. No lost submissions, no blocked emails, no broken forms. Automatic retries handle transient failures. A built-in watchdog checks queue health every 15 minutes and shows admin notices when pending items build up or Action Scheduler is unavailable. You always know the status of your protection. Full Visibility Dashboard See exactly what is happening with your form protection at a glance. The ActiveLayer dashboard shows submission totals, spam caught, accuracy rates, queue health, and integration status — all in one place. Filter submissions by status or provider, and use bulk actions to recheck, mark as clean or junk, or trash items you no longer need. Every submission is logged in a custom database table. You can review verdicts, recheck past submissions with a fresh API call, and override any decision. Debug logging (opt-in, PII-redacted) gives you even deeper insight when troubleshooting. Who Is ActiveLayer For? Small Business Websites Protect your contact forms and inquiry forms without adding friction for potential customers. Async form submissions from real visitors go through instantly while junk gets caught behind the scenes. Bloggers and Publishers Stop comment spam on your posts without requiring readers to solve CAPTCHAs or prove they are human. ActiveLayer checks comments in the background and can auto-approve clean ones or auto-mark detected spam. Agencies Managing Multiple Sites One plugin covers WPForms, Contact Form 7, Gravity Forms, Elementor Forms, Fluent Forms, Formidable Forms, WooCommerce, and more — every integration managed from one settings page. No need to configure separate anti-spam tools for each form builder or WooCommerce surface your clients use. E-commerce and Service Businesses Keep inquiry and support forms clean while maintaining a fast, professional user experience. Async checks keep contact forms moving quickly, while registration gates can block spam accounts inline. WooCommerce stores get dedicated protection for product reviews and My Account customer registration — and the checkout itself is never gated, so spam protection can’t get in the way of a sale. Membership Sites and Online Communities Running a community on BuddyPress or BuddyBoss Platform? ActiveLayer hooks the public signup form and blocks spam registrations before they create fake accounts — no extra CAPTCHA in front of your real members, no manual moderation queue to babysit. The integration covers both free BuddyPress and BuddyBoss Platform with a dedicated admin toggle for each. Full ActiveLayer Feature List Async processing – Background queue via Action Scheduler for supported async integrations No CAPTCHA required – Invisible protection with zero friction for visitors WPForms integration – Per-form enable, async checks with email replay, optional sync-save strategy Contact Form 7 integration – Synchronous checks, field mapping via activelayer:* tags, per-form control Gravity Forms integration – Entry-based spam detection with per-form control and notification management Elementor Forms integration – Protect Elementor Pro form widgets with per-form spam filtering Fluent Forms integration – Per-form spam detection with email notification handling Formidable Forms integration – Notification interception and replay, sync fallback option Forminator integration – Form submission interception with per-form toggles and notification management Ninja Forms integration – Email action capture, clean verdict replay, spam suppression SureForms integration – Spam protection for SureForms with per-form control WS Form integration – Synchronous spam blocking before WS Form saves entries or runs actions, with per-form control WordPress Comments protection – Auto-approve clean comments, auto-spam detected ones, fail-open restore WooCommerce Reviews protection – Score every product review on submission, with optional verified-owner bypass, logged-in-user bypass, and high-confidence auto-delete WooCommerce Registration protection – Block bot signups on the My Account registration form before the account is created (the checkout flow is never gated, so it can’t block a purchase) BuddyPress signup protection – Block spam registrations on the public /register/ page; sync check fires after BuddyPress’s own validation and writes the block message next to the username field BuddyBoss Platform signup protection – Same sync gate against the BuddyBoss Platform signup form, with automatic xprofile-name fallback because BuddyBoss auto-generates the username from the email AffiliateWP registration protection – Block bot affiliate signups before the affiliate and WordPress user are created; sync check fires after AffiliateWP’s own validation MemberPress registration protection – Block bot membership signups before the account is created; free, free-trial, and fully-discounted signups are gated by default, while paid checkouts are never blocked (opt in to gate those too) FunnelKit Funnel Builder integration – Synchronous spam blocking for opt-in forms before FunnelKit runs email, CRM contact, and webhook actions, with per-form control Easy Digital Downloads integration – Spam protection for product reviews and the standalone customer registration form; the EDD checkout is never gated, so it can’t block a purchase Silent discard for high-confidence spam – Optional hard-delete of comments and WooCommerce reviews that exceed a configurable spam score threshold (default 95), skipping spam-folder storage entirely Per-form toggles – Protection enabled by default per form; disable on individual forms as needed Sync Mode – Optional synchronous spam checks for inline blocking on supported integrations Dashboard analytics – Submission totals, spam caught, accuracy rates, queue health at a glance Submissions management – Filter by status and provider, bulk recheck, mark clean or spam, trash Fail-open architecture – Forms keep working if the API is temporarily unavailable Automatic retries – Failed submissions are re-queued and retried automatically Queue watchdog – 15-minute health checks with admin notices for stalled queues Behavioral signal collection – Keystroke, mouse, touch, and scroll tracking for deeper analysis Environment detection – Identifies headless browsers and automated submission tools Debug logging – Opt-in ring buffer (last 200 entries), PII-redacted, view and clear in admin Bulk recheck – Re-queue past submissions for fresh API verdicts anytime Default protection – Forms protected by default after API connection; disable per form if needed. Sanitized logging, masked secrets, hashed emails Integrations WPForms (Lite and Pro) Contact Form 7 Gravity Forms Elementor Forms (Pro) Fluent Forms Formidable Forms Forminator Ninja Forms SureForms WS Form WordPress Comments (built-in) WooCommerce (product reviews and customer registration) BuddyPress (public signup form) BuddyBoss Platform (public signup form) AffiliateWP (affiliate registration form) MemberPress (membership registration form) FunnelKit Funnel Builder (opt-in forms) Easy Digital Downloads (product reviews and customer registration) External services This plugin connects to the ActiveLayer API to analyze form submissions and comments for spam. It is the core service that powers all spam detection — without it, the plugin cannot classify submissions. ActiveLayer API What it does: Provides spam detection verdicts (clean or spam) for form submissions and comments. When data is sent: Each time a protected form submission, comment, review, or registration is checked, the submission data is sent to the API for analysis. Depending on the integration, this can happen through the background queue or during a synchronous inline-blocking check. What data is sent: * Submission content (name, email, message, URL if provided) * IP address and user agent of the submitter * Form metadata (form ID, form name, provider name) * Site URL and WordPress locale * Behavioral and environment signals (if enabled in settings) Service provider: ActiveLayer (activelayer.com) * Terms of Service * Privacy Policy
Top keywords
- form37×2.37%
- spam34×2.18%
- forms33×2.11%
- activelayer19×1.22%
- protection19×1.22%
- integration17×1.09%
- registration17×1.09%
- submission14×0.90%
- per-form11×0.70%
- submissions11×0.70%
- api10×0.64%
- checks10×0.64%
Kitgenix CAPTCHA for Cloudflare Turnstile
Kitgenix CAPTCHA for Cloudflare Turnstile adds Cloudflare Turnstile CAPTCHA and anti-spam protection to WordPress, WooCommerce and a wide range of form, membership, community and ecommerce plugins. Challenges are not treated as a client-side decoration: submitted Turnstile tokens are verified server-side with Cloudflare before a protected action is accepted. The plugin is designed for site owners who want to reduce automated login attempts, fake registrations, comment spam, bot-driven checkout abuse and unwanted form submissions while using Cloudflare’s privacy-oriented Turnstile challenge rather than a traditional image CAPTCHA. Configuration, integration controls, diagnostics and local verification metrics are managed inside WordPress. The only service required for CAPTCHA functionality is Cloudflare Turnstile itself; no Kitgenix verification proxy is used. Learn more about Kitgenix WordPress plugins at Kitgenix. Supported WordPress and Plugin Integrations The codebase contains dedicated integrations for: WordPress login. WordPress registration. Lost-password and password-reset flows. WordPress comments. Custom login forms produced with wp_login_form(). WooCommerce login, registration, lost password, checkout and related account flows supported by the integration. Easy Digital Downloads. Elementor forms. Contact Form 7. WPForms. Gravity Forms. Fluent Forms. Formidable Forms. Forminator. Ninja Forms. Jetpack Forms. JetFormBuilder. Kadence Forms. MailPoet. bbPress. BuddyPress. wpDiscuz. Ultimate Member. MemberPress. Paid Memberships Pro. Kitgenix Plugin Score integration points included in the codebase. Each integration is loaded conditionally and can use integration-specific display/validation behaviour rather than forcing one generic hook onto every form system. Server-Side Turnstile Verification The browser obtains a Turnstile response token from Cloudflare’s official widget. When a protected form is submitted, the plugin sends that token to Cloudflare’s official Siteverify endpoint using the WordPress HTTP API. The protected action is allowed only when the verification result satisfies the integration’s validation flow. This server-side step is important because simply placing a widget in the browser is not sufficient protection on its own. The plugin tracks the most recent verification response, error codes and latency for diagnostics and can record aggregate verification metrics locally. Setup Verification for Login-Sensitive Forms Login, registration and other account-sensitive protections can be gated behind a setup-verification state. The administrator can verify the configured Site Key and Secret Key before those protections are treated as ready. This reduces the risk of enabling a broken key pair on a login screen and accidentally locking legitimate administrators or customers out of the site. Site and secret keys can be supplied from plugin settings or from supported environment variables/constants, allowing security-conscious deployments to keep the secret outside the normal WordPress options table. Replay Protection Turnstile tokens are intended to be short lived and single use. The plugin includes optional replay protection that hashes accepted tokens and temporarily remembers that hash. A token that is submitted again during the replay window can be rejected rather than being accepted repeatedly. The replay window is filterable for developers. Stored replay information is a hash/temporary value, not the raw challenge token itself. Honeypot and Layered Anti-Spam Controls An optional honeypot can be rendered alongside Turnstile. This adds a second low-friction signal for simple bots that fill fields a normal visitor never sees. The plugin also supports whitelisting logic so trusted requests can bypass the challenge where appropriate. Whitelist decisions can take account of configured rules and developer filters rather than hard-coding one bypass mechanism for every site. Trusted Proxy and Client IP Handling Sites may sit behind Cloudflare, another reverse proxy or a load balancer. The client-IP component can be configured to trust proxy headers only when the request path matches the trusted-proxy configuration. This avoids blindly believing spoofable forwarding headers from arbitrary visitors. Administrators can also choose whether the resolved visitor IP is included in the Siteverify request to Cloudflare. A developer filter is available to change that behaviour when required by a site’s privacy or infrastructure policy. Widget Appearance and Placement The plugin supports central defaults plus integration-level overrides for Turnstile appearance. Depending on the supported integration, administrators can control options such as theme, size, appearance and language, and can choose placement behaviour where the integration exposes more than one suitable hook. A manual shortcode is also registered: [kitgenix_turnstile] The shortcode is useful when the site owner needs to render the widget in a supported custom workflow. Rendering a widget alone does not automatically secure arbitrary custom PHP processing; custom form handlers must still validate the submitted token server-side. Diagnostics, Metrics and Site Health The plugin includes diagnostics for configuration and verification health, local counters for passed/failed checks, latency information, recent verification events and integration-level metrics. Site Health integration can surface configuration or connectivity issues to administrators. Developer Mode adds additional troubleshooting detail without changing the fundamental requirement that live submissions be verified correctly when protection is active. Settings Portability Settings can be exported and imported for controlled migration between WordPress installations. The transfer system is designed for plugin configuration rather than for exporting visitor submissions or unrelated site data. Performance and Script Loading The public Cloudflare Turnstile script is loaded only for pages/contexts where the plugin determines that a Turnstile widget may be needed. The loader includes duplicate-script detection so multiple integrations do not intentionally enqueue several copies of the same Turnstile API script. Public assets are kept separate from the admin interface, and admin-only diagnostics/settings code does not need to run as part of every anonymous form request. Privacy and Data Flow Turnstile is an external service provided by Cloudflare, so challenge rendering and server-side verification necessarily communicate with Cloudflare. The plugin itself stores configuration and limited diagnostic/aggregate verification data locally. It does not require a Kitgenix account and does not send form contents to Kitgenix for verification. The exact Cloudflare data flow, WordPress.org Hub request and Google Fonts admin request are documented in the External Services section below. Common Uses Protect a WordPress login page from automated credential attacks. Reduce spam registrations on WordPress or WooCommerce. Add anti-bot verification to WooCommerce checkout and account forms. Protect Elementor and popular WordPress form plugins with one central Turnstile configuration. Add a challenge to membership, forum and community registration/login flows. Replace more intrusive CAPTCHA experiences with Cloudflare Turnstile while keeping server-side validation. Developer Notes Shortcode [kitgenix_turnstile] Main settings option kitgenix_captcha_for_cloudflare_turnstile_settings Useful filters Script and display: kitgenix_captcha_for_cloudflare_turnstile_script_url kitgenix_turnstile_freshness_ms kitgenix_turnstile_inline_style Verification: kitgenix_turnstile_siteverify_url kitgenix_turnstile_siteverify_timeout kitgenix_turnstile_siteverify_sslverify kitgenix_turnstile_siteverify_http_args kitgenix_turnstile_send_remoteip kitgenix_turnstile_remote_ip kitgenix_turnstile_token_from_request kitgenix_turnstile_error_codes kitgenix_turnstile_error_message kitgenix_turnstile_replay_message kitgenix_turnstile_skip_wp_login_validation Replay protection: kitgenix_turnstile_replay_ttl Whitelisting and proxy handling: kitgenix_turnstile_is_whitelisted kitgenix_turnstile_trust_headers kitgenix_turnstile_trusted_proxies Operational alerts: kitgenix_turnstile_alert_window_seconds kitgenix_turnstile_alert_failure_spike_min_failures kitgenix_turnstile_alert_failure_spike_failure_rate kitgenix_turnstile_alert_http_error_min_failures Developer logging action: kitgenix_turnstile_dev_log The plugin also exposes context-specific error-message filtering through kitgenix_captcha_for_cloudflare_turnstile_{context}_turnstile_error_message. Privacy and Local Data The plugin stores its configuration in the WordPress database. Depending on enabled features it also stores local operational data such as setup-verification state, aggregate integration metrics, the recent event log and replay-protection transients. The recent event log is limited to 50 events and contains operational fields such as time, integration, success/failure, error codes and Siteverify latency. It does not store raw form submissions, the raw Turnstile response token, the visitor’s raw IP address or the request URL in that log. Turnstile itself is an external Cloudflare service and receives data when a widget is loaded and when the server validates a token. See External Services below. External Services This plugin relies on third-party services for specific functionality. These connections are documented here so site owners can make an informed decision before enabling and using the plugin. Cloudflare Turnstile Cloudflare Turnstile is the CAPTCHA / bot-verification service that provides the plugin’s core protection. A Cloudflare account and Turnstile Site Key / Secret Key are required. When a protected widget is rendered, the visitor’s browser loads Cloudflare Turnstile from: https://challenges.cloudflare.com/turnstile/v0/api.js The browser communicates with Cloudflare as part of the Turnstile challenge. As with normal web requests, Cloudflare can receive network/request information such as the visitor’s IP address and browser/request metadata, and Turnstile evaluates browser signals to generate a verification token. When a protected form is submitted, the WordPress server sends a POST request to: https://challenges.cloudflare.com/turnstile/v0/siteverify By default, that request contains: The configured Turnstile Secret Key The Turnstile response token The visitor IP address as Cloudflare’s optional remoteip parameter when an address is available The remoteip value can be disabled by developers with the kitgenix_turnstile_send_remoteip filter. Cloudflare documentation: https://developers.cloudflare.com/turnstile/ Cloudflare Terms: https://www.cloudflare.com/website-terms/ Cloudflare Privacy Policy: https://www.cloudflare.com/privacypolicy/ WordPress.org Plugin API The shared Kitgenix Hub in wp-admin uses WordPress core’s plugins_api() functionality to request public WordPress.org plugin-directory information such as plugin details, active-install counts, ratings and media. These requests occur on Kitgenix administration screens. The plugin supplies WordPress.org plugin slugs to WordPress core; the outbound request itself is handled by WordPress and can include normal HTTP request metadata generated by WordPress. Responses are cached locally with WordPress transients to reduce repeat requests. WordPress.org: https://wordpress.org/ WordPress.org Privacy Policy: https://wordpress.org/about/privacy/ Google Fonts The Kitgenix administration stylesheet imports the Inter and Manrope font families from Google Fonts. This occurs on Kitgenix plugin administration screens, not as part of the Turnstile verification request itself. Loading those font resources causes the administrator’s browser to connect to Google-hosted domains such as fonts.googleapis.com and fonts.gstatic.com, which can receive normal request information such as IP address and browser headers. Google Fonts: https://fonts.google.com/ Google Privacy Policy: https://policies.google.com/privacy Google Terms: https://policies.google.com/terms Trademark Notice Cloudflare and Cloudflare Turnstile are trademarks or services of Cloudflare, Inc. This plugin is independently developed by Kitgenix and is not affiliated with or endorsed by Cloudflare, Inc. WordPress and WooCommerce trademarks belong to their respective owners. References are descriptive and identify supported integrations. Support Development Kitgenix CAPTCHA for Cloudflare Turnstile is free software. If the plugin is useful to you, you can support continued maintenance and development through the Donate link shown on the WordPress.org plugin page. More WordPress plugins and development resources are available from Kitgenix.