SilentShield – Captcha & Anti-Spam for WordPress (CF7, WPForms, Elementor, WooCommerce)
SilentShield is a unified captcha and anti-spam plugin for WordPress. It works with the most popular form builders and protects login, registration, and comment forms – without slowing your site. Why choose SilentShield? – Invisible defense – Captcha, honeypot, and blacklists working silently. – Instant results – Install, activate, and stop spam. – Universal support – Works with Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms, Forminator, Kadence, WooCommerce, and more. – Privacy-first – No cookies, no tracking, fully GDPR / DSGVO compliant. SilentShield doesn’t just protect forms. It protects your time, your customers, your business. Core Features Invisible Captcha (Arithmetic, Honeypot, Image) Smart IP Blocking & Blacklists Spam filters for links, code & keywords Whitelisting for admins & customers GDPR-ready, no cookies, no tracking Supported Form Plugins & Integrations SilentShield protects forms from all major WordPress form builders and core features: Form Builders: – Contact Form 7 (CF7) – WPForms / WPForms Lite – Elementor Pro Forms (classic widget and v4 “atomic” forms) – Gravity Forms – Fluent Forms – Formidable Forms – Ninja Forms – Forminator – JetFormBuilder – Kadence Blocks (Advanced Form) – Jetpack Forms (contact form block and shortcode) – Avada (Fusion Builder) Forms Newsletter: – MC4WP – Mailchimp for WordPress (signup forms) WooCommerce: – Checkout – block (the default for new shops since WooCommerce 8.3) – Checkout – classic (incl. PayPal Payments) – Login – Registration – Lost password – Account details WordPress Core: – Login form (wp-login.php) – Registration form – Lost password form – Comment forms (including WooCommerce product reviews) Communities & Forums: – bbPress (new topics and replies) – BuddyPress (member registration) Donations: – GiveWP (classic donation form; the visual-builder form is not yet covered) Other: – Ultimate Member (Login & Registration) – WP Job Manager (Job Applications) Each integration can be enabled or disabled individually under Settings > Extended. Protection Layers SilentShield uses 10+ protection mechanisms working together: Captcha – Arithmetic math, honeypot, or image-based captcha JavaScript Protection – Detects submissions from bots without JS support Browser Detection – Validates User-Agent strings Timer Protection – Blocks submissions faster than a human can type Multiple Submission Protection – Prevents rapid duplicate submissions IP Rate Limiting – Limits requests per IP and time window IP Blacklist – Block known bad IPs Content Rules – Limit URLs, block BBCode, keyword blacklist Gibberish Detection – Recognises submissions filled with random characters, the kind a bot writes when it only needs the form to go through. Unlike every other check it does not depend on the sender’s browser, so a bot driving a real browser cannot pass it by playing along. Starts in observation mode and blocks nothing until you switch it on. Whitelist – Skip validation for admins, logged-in users, or specific emails/IPs SilentShield API – Cloud-based spam detection (silentshield.io) The Promise SilentShield is not “just another plugin.” It’s an invisible wall against the background noise of the internet. Activate once – and your forms are human again. Want more? SilentShield API Everything above is free and stays free. No feature is held back, no submission limit, no account needed. What the free plugin cannot do is recognise a bot that behaves like a person — one driving a real browser, solving the captcha, typing at human speed. Rules can only catch what looks wrong, and those do not. The SilentShield API answers that with behaviour analysis and browser fingerprinting, scored in the cloud, and it usually decides without showing anyone a captcha at all. Switch it on and the local protections stay exactly where they are as a fallback — if the API is ever unreachable, your forms are still protected. There is a free plan and a trial, and you can see what it would have caught before you pay for anything: turn on Comparison Mode and the plugin logs what the API would have decided, alongside what your local rules actually did. 👉 Plans and free trial at silentshield.io Privacy & Telemetry No cookies, no user tracking. Encrypted IP storage (max. 2 months, only for spam defense). Every transmission described below is optional and can be switched off in the plugin settings. The plugin’s built-in Privacy page shows which of these are active on your site, what that means, and gives you ready-made privacy-policy snippets in 25 languages. 1. Plugin statistics (setting “Telemetry”) Anonymous, no personal data, sent at most once a day: – plugin_slug, plugin_version – snapshot_date – settings_json (anonymized config – only boolean/integer flags, no free-text) – features_json (enabled features) – created_at, first_seen, last_seen – counters_json (spam events) – wp_version, php_version, locale 2. AI-crawler observation (setting “Observe AI crawlers”, on by default; SILENTSHIELD_OBSERVER to force off) Sent only for requests identified as an AI crawler — never for your human visitors. Delivered after the page has already been sent to the visitor: – ua (the crawler’s User-Agent), ip, path (without query string), method – The IP address is pseudonymised on the server (daily keyed hash) and never stored in the clear. 3. Blocked-request reports (only with “Block AI crawlers (enforce)” on; follows the observation setting above) Same fields as (2), plus the outcome (deny / throttle), for every request enforcement turned away. Note that a block rule which is not restricted to a specific crawler can also catch a human visitor — that request is then reported in the same way. 4. Form assessment (only with the SilentShield API enabled) See the API snippet on the plugin’s Privacy page for the full description.
Top keywords
- forms16×1.86%
- form15×1.75%
- silentshield13×1.51%
- api7×0.81%
- captcha7×0.81%
- ip7×0.81%
- only7×0.81%
- block6×0.70%
- browser5×0.58%
- human5×0.58%
- protection5×0.58%
- registration5×0.58%
Form Enhancer for Fluent Forms
A lightweight add-on that extends Fluent Forms and Fluent SMTP with new fields, admin tools, and features to boost form functionality without the bloat. Other form plugins might be added in the future. The free version gives your forms fields that check themselves: EU VAT numbers against VIES, Czech and Slovak company numbers (IČO) against the ARES and FinStat business registries, IBAN and Czech/Slovak bank accounts offline by checksum, a confirm field for emails or passwords, and a Unique ID that stamps every submission with your own reference number. No API keys, no accounts, no per-lookup fees. Need more? Blocking free and disposable email providers, email verification by one-time code, “Other” options on radio and checkbox fields, Ecomail newsletter sync, per-user entry limits and entry duplication are PRO features — see everything PRO adds. Check out all the features and documentation at formenhancer.com. Features available in the FREE version Input fields Bank Account (IBAN / CZ / SK) – Validates IBANs (all countries) and Czech and Slovak domestic account numbers (prefix-number/bank code) offline using checksums, and shows the bank name for known Czech and Slovak bank codes once the number checks out. Each field can accept both formats or be pinned to IBAN only or domestic only. No external service involved. Confirm Field – A confirmation field that validates if its value matches another field (useful for confirming emails, passwords, etc.). Czech & Slovak Identification Numbers (IČO) – Three new fields for Czech, Slovak, and combined Czech/Slovak IČO—complete with validation via ARES and FinStat on submission. EU VAT Number – Field for entering EU VAT numbers, with automatic validation through the VIES service. Unique ID – Stamps every submission with a configurable reference number: a prefix/suffix around a zero-padded sequential counter, or a random token. The counter is race-safe, so two submissions at the same moment never draw the same number, and the value works in email notifications, PDFs and webhooks like any other field. Functions Apply Block Editor Submit Button Style – Applies the same styling as Gutenberg’s button block to all Fluent Forms submit buttons. Enhanced Admin Approval – Automatically notify users by email when their submission is waiting for approval—includes the same message shown on the form. Disable Captchas for Logged-in Users – Turn off reCAPTCHA, hCaptcha, and Turnstile for logged-in users—perfect for smoother user flows or running automated tests on live sites. Store a single IP – Store just one IP address per submission to avoid issues with Mailchimp and similar integrations caused by multiple IPs. Webhook Debug Log – When a Fluent Forms Pro webhook feed fails, the full request and response (headers and body) are captured and shown right in the entry’s API Calls log — no more guessing what was actually sent. Integrations ACF/SCF Field Type – Adds a “Fluent Form” field type to Advanced Custom Fields and Secure Custom Fields, allowing you to select Fluent Forms in the Field Groups – returns either ID or Form object. ⭐ PRO version (starting at 15 USD) By upgrading to PRO version you’re directly supporting the ongoing development of Form Enhancer. Your license keeps the project alive and independent. Input fields Checkbox with “Other” Option – Let users tick multiple choices or add their own response via a custom text or textarea “Other” input (text or textarea). Radio with “Other” Option – Let users pick from preset options or let them write their own response using a flexible “Other” field (text or textarea). Enhanced Email Field – Block free email providers (like Gmail or Yahoo) together with disposable addresses or restrict specific domains to collect only valid business emails. Email Verification (OTP) – Require visitors to confirm a 6-digit code sent to their email address before the form can be submitted, so every lead is a real, reachable mailbox. Rate-limited and enforced server-side. Integrations Ecomail – Sync your newsletter subscription easily, from forms to your lists. Features Duplicate Entry – Quickly duplicate form entries directly from the entries list using bulk actions. An optional setting locks the status of duplicated entries so it can’t be changed by accident. Per-User Entry Limits – Limit form submissions per logged-in user (or IP address) per day, week, month, or year. Adds combined period options like “Per User – Per Day” to the native “Limit Number of Entries” restriction — Fluent Forms itself only offers per-user OR per-period limits, never both at once. FluentSMTP – Telegram Notification on Failure – Get instantly notified in your Telegram channel if a form submission fails to send via FluentSMTP.