SilentShield – Captcha & Anti-Spam for WordPress (CF7, WPForms, Elementor, WooCommerce)
SilentShield is a unified captcha and anti-spam plugin for WordPress. It works with the most popular form builders and protects login, registration, and comment forms – without slowing your site. Why choose SilentShield? – Invisible defense – Captcha, honeypot, and blacklists working silently. – Instant results – Install, activate, and stop spam. – Universal support – Works with Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms, Forminator, Kadence, WooCommerce, and more. – Privacy-first – No cookies, no tracking, fully GDPR / DSGVO compliant. SilentShield doesn’t just protect forms. It protects your time, your customers, your business. Core Features Invisible Captcha (Arithmetic, Honeypot, Image) Smart IP Blocking & Blacklists Spam filters for links, code & keywords Whitelisting for admins & customers GDPR-ready, no cookies, no tracking Supported Form Plugins & Integrations SilentShield protects forms from all major WordPress form builders and core features: Form Builders: – Contact Form 7 (CF7) – WPForms / WPForms Lite – Elementor Pro Forms (classic widget and v4 “atomic” forms) – Gravity Forms – Fluent Forms – Formidable Forms – Ninja Forms – Forminator – JetFormBuilder – Kadence Blocks (Advanced Form) – Jetpack Forms (contact form block and shortcode) – Avada (Fusion Builder) Forms Newsletter: – MC4WP – Mailchimp for WordPress (signup forms) WooCommerce: – Checkout – block (the default for new shops since WooCommerce 8.3) – Checkout – classic (incl. PayPal Payments) – Login – Registration – Lost password – Account details WordPress Core: – Login form (wp-login.php) – Registration form – Lost password form – Comment forms (including WooCommerce product reviews) Communities & Forums: – bbPress (new topics and replies) – BuddyPress (member registration) Donations: – GiveWP (classic donation form; the visual-builder form is not yet covered) Other: – Ultimate Member (Login & Registration) – WP Job Manager (Job Applications) Each integration can be enabled or disabled individually under Settings > Extended. Protection Layers SilentShield uses 10+ protection mechanisms working together: Captcha – Arithmetic math, honeypot, or image-based captcha JavaScript Protection – Detects submissions from bots without JS support Browser Detection – Validates User-Agent strings Timer Protection – Blocks submissions faster than a human can type Multiple Submission Protection – Prevents rapid duplicate submissions IP Rate Limiting – Limits requests per IP and time window IP Blacklist – Block known bad IPs Content Rules – Limit URLs, block BBCode, keyword blacklist Gibberish Detection – Recognises submissions filled with random characters, the kind a bot writes when it only needs the form to go through. Unlike every other check it does not depend on the sender’s browser, so a bot driving a real browser cannot pass it by playing along. Starts in observation mode and blocks nothing until you switch it on. Whitelist – Skip validation for admins, logged-in users, or specific emails/IPs SilentShield API – Cloud-based spam detection (silentshield.io) The Promise SilentShield is not “just another plugin.” It’s an invisible wall against the background noise of the internet. Activate once – and your forms are human again. Want more? SilentShield API Everything above is free and stays free. No feature is held back, no submission limit, no account needed. What the free plugin cannot do is recognise a bot that behaves like a person — one driving a real browser, solving the captcha, typing at human speed. Rules can only catch what looks wrong, and those do not. The SilentShield API answers that with behaviour analysis and browser fingerprinting, scored in the cloud, and it usually decides without showing anyone a captcha at all. Switch it on and the local protections stay exactly where they are as a fallback — if the API is ever unreachable, your forms are still protected. There is a free plan and a trial, and you can see what it would have caught before you pay for anything: turn on Comparison Mode and the plugin logs what the API would have decided, alongside what your local rules actually did. 👉 Plans and free trial at silentshield.io Privacy & Telemetry No cookies, no user tracking. Encrypted IP storage (max. 2 months, only for spam defense). Every transmission described below is optional and can be switched off in the plugin settings. The plugin’s built-in Privacy page shows which of these are active on your site, what that means, and gives you ready-made privacy-policy snippets in 25 languages. 1. Plugin statistics (setting “Telemetry”) Anonymous, no personal data, sent at most once a day: – plugin_slug, plugin_version – snapshot_date – settings_json (anonymized config – only boolean/integer flags, no free-text) – features_json (enabled features) – created_at, first_seen, last_seen – counters_json (spam events) – wp_version, php_version, locale 2. AI-crawler observation (setting “Observe AI crawlers”, on by default; SILENTSHIELD_OBSERVER to force off) Sent only for requests identified as an AI crawler — never for your human visitors. Delivered after the page has already been sent to the visitor: – ua (the crawler’s User-Agent), ip, path (without query string), method – The IP address is pseudonymised on the server (daily keyed hash) and never stored in the clear. 3. Blocked-request reports (only with “Block AI crawlers (enforce)” on; follows the observation setting above) Same fields as (2), plus the outcome (deny / throttle), for every request enforcement turned away. Note that a block rule which is not restricted to a specific crawler can also catch a human visitor — that request is then reported in the same way. 4. Form assessment (only with the SilentShield API enabled) See the API snippet on the plugin’s Privacy page for the full description.
Top keywords
- forms16×1.86%
- form15×1.75%
- silentshield13×1.51%
- api7×0.81%
- captcha7×0.81%
- ip7×0.81%
- only7×0.81%
- block6×0.70%
- browser5×0.58%
- human5×0.58%
- protection5×0.58%
- registration5×0.58%
OpenPorte Spam Protection
OpenPorte is a free and open-source plugin that protects WordPress forms from spam using a lightweight Proof-of-Work challenge instead of CAPTCHAs. The goal is to make spam expensive for bots while keeping the experience almost invisible for legitimate visitors and respecting their privacy. For site owners, OpenPorte offers an easy to configure and deploy modern spam protection under their control. For the site users, it offers an accessible, transparent and privacy-friendly alternative to CAPTCHAs. OpenPorte is built around the open-source ALTCHA widget. Some highlights: CAPTCHA-free spam protection Fully open source (GPL) Self-hosted – no mandatory external service Designed to be accessible and privacy-friendly Compatible with existing ALTCHA integrations Easy migration for users of ALTCHA Spam Protection v1 (≤ 1.26.3) For the list of contributors, refer to our GitHub project: Contributors. AI-assisted development AI-assisted project. Architecture, security decisions, and final review are mine; AI tools (Claude, Mistral, and others) help with drafting code, tests, translations, and documentation — without them, one person couldn’t keep this fork alive. Background The original ALTCHA Spam Protection WordPress plugin (v1) was open source (GPLv2). Its authors have since released a version 2/3 which is no longer open source. They no longer maintain the open source project and recommend that users migrate to v2/v3. See the official project at https://altcha.org for their offering. OpenPorte started as a fork and continues the v1 line as free software (GPLv2 or later) for users who want to stay on a fully open-source, self-hosted solution. It is a faithful fork: existing v1 installations can switch to OpenPorte and keep their settings (see Upgrading). Compatibility OpenPorte is backward-compatible with ALTCHA Spam Protection v1 plugin: Your existing settings are migrated automatically on activation. The [altcha] shortcode keeps working (alongside the new [openporte]). The altcha_* filters and actions keep firing as deprecated aliases. Custom API Mode has been verified against GateCHA, an open source server implementing the creation and verification of ALTCHA challenges. See the Deprecations section for the full list of compatibility aliases and what they map to. Upgrading From the original ALTCHA v1 plugin Deactivate the old ALTCHA plugin, then install and activate OpenPorte. Your existing configuration is detected and copied into the OpenPorte settings on first activation; the original ALTCHA settings are left untouched, so you can roll back to ALTCHA v1 without losing anything. Do not run both plugins at the same time. From ALTCHA v2/v3 If your site was already moved to ALTCHA v2/v3 (for example by the automatic 3.0.0 update), your original v1 settings are normally still in the database: the v2/v3 upgrade neither migrates nor removes them. Deactivate ALTCHA, then install and activate OpenPorte — it finds and imports the v1 settings, even when the v1 plugin itself has long been deleted. Settings made in v2/v3 are not read. Deprecations The following ALTCHA-era identifiers are kept as aliases for backward compatibility and are scheduled for removal in a future release: The [altcha] shortcode — use [openporte]. The altcha/v1 REST namespace — use openporte/v1. The altcha_* filters and actions — now firing through WordPress’ deprecated hook mechanism; use the openporte_* equivalents. The AltchaPlugin class and the ALTCHA_VERSION / ALTCHA_WIDGET_VERSION constants — use OpenPortePlugin and the OPENPORTE_* constants. Integrations targeting paid-only third-party plugins; affected users should migrate to the official ALTCHA v2/v3 plugin. The “Custom HTML” integration (auto-configuration of hand-written tags) — place the [openporte] shortcode instead. You can re-enable it for now under Settings → OpenPorte → Integrations. Privacy No cookies, no tracking OpenPorte prioritizes user privacy by avoiding the use of cookies and fingerprinting techniques. No external service This plugin remains fully contained within your WordPress installation, eliminating any reliance on external services. Modes of Operation OpenPorte verifies submissions in one of two modes, selected in the settings (API Mode): Self-hosted (default) — a proof-of-work challenge is issued and verified by your own WordPress site through the REST API. Fully self-contained, with no external service and no additional setup beyond enabling the integrations you need. Custom — point the Challenge URL at your own ALTCHA-compatible backend (for example a self-hosted ALTCHA Sentinel, or GateCHA). Submissions are verified with your site’s shared secret. The paid altcha.org regional SaaS classifier offered by earlier versions has been removed; both remaining modes are free and self-hostable. REST API This plugin requires the WordPress REST API. If you are using any “Disable REST API” plugins, ensure that the endpoint /altcha/v1/challenge (marked for deprecation) and /openporte/v1/challenge are allowed. Supported Integrations CoBlocks Contact Form 7 Elementor Pro Forms (deprecated — paid plugin, see Deprecations) Formidable Forms Forminator GravityForms HTML Forms wpDiscuz WPForms WordPress Login, Register, Password reset WordPress Comments WooCommerce Many other plugins and your own content (via the [openporte] shortcode, or the deprecated [altcha] alias) Source Code All source code for the plugin, and the ALTCHA widget is available on GitHub. In the repository, you’ll also find versions of non-minified JavaScript and CSS assets: Plugin: https://github.com/openporte/openporte ALTCHA Widget: https://github.com/altcha-org/altcha