{"id":147547,"date":"2021-10-11T11:10:06","date_gmt":"2021-10-11T11:10:06","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/captcha-for-contact-form-7\/"},"modified":"2026-08-27T08:41:45","modified_gmt":"2026-08-27T08:41:45","slug":"captcha-for-contact-form-7","status":"publish","type":"plugin","link":"https:\/\/sah.wordpress.org\/plugins\/captcha-for-contact-form-7\/","author":16900441,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"2.15.4","stable_tag":"2.15.4","tested":"7.0.4","requires":"5.2","requires_php":"7.4","requires_plugins":null,"header_name":"SilentShield \u2013 Captcha & Anti-Spam for WordPress (CF7, WPForms, Elementor, WooCommerce)","header_author":"Forge12 Interactive GmbH","header_description":"This plugin allows you to add a captcha to your contact form 7 forms.","assets_banners_color":"888ccc","last_updated":"2026-08-27 08:41:45","external_support_url":"","external_repository_url":"","donate_link":"https:\/\/www.paypal.com\/donate?hosted_button_id=MGZTVZH3L5L2G","header_plugin_uri":"https:\/\/www.forge12.com\/product\/wordpress-captcha\/","header_author_uri":"https:\/\/www.forge12.com","rating":4.7,"author_block_rating":0,"active_installs":10000,"downloads":269676,"num_ratings":21,"support_threads":6,"support_threads_resolved":6,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.10.0":{"tag":"1.10.0","author":"forge12","date":"2023-04-25 09:34:47","revision":2903780},"1.11.0":{"tag":"1.11.0","author":"forge12","date":"2023-05-03 10:49:31","revision":2907428},"1.11.2":{"tag":"1.11.2","author":"forge12","date":"2023-08-10 11:55:46","revision":2951475},"1.11.3":{"tag":"1.11.3","author":"forge12","date":"2023-08-10 12:05:19","revision":2951482},"1.11.4":{"tag":"1.11.4","author":"forge12","date":"2023-08-18 08:49:31","revision":2955256},"1.11.5":{"tag":"1.11.5","author":"forge12","date":"2023-08-24 08:56:01","revision":2957739},"1.11.6":{"tag":"1.11.6","author":"forge12","date":"2023-10-01 13:03:11","revision":2973510},"1.11.7":{"tag":"1.11.7","author":"forge12","date":"2023-12-01 11:27:25","revision":3004191},"1.11.8":{"tag":"1.11.8","author":"forge12","date":"2023-12-01 11:30:40","revision":3004195},"1.11.92":{"tag":"1.11.92","author":"forge12","date":"2024-04-03 13:00:20","revision":3063719},"1.12.0":{"tag":"1.12.0","author":"forge12","date":"2024-04-10 06:19:03","revision":3068193},"1.12.1":{"tag":"1.12.1","author":"forge12","date":"2024-04-10 06:44:50","revision":3068210},"1.2":{"tag":"1.2","author":"forge12","date":"2022-01-01 15:35:43","revision":2651572},"1.2.1":{"tag":"1.2.1","author":"forge12","date":"2022-01-24 09:54:28","revision":2663064},"1.2.2":{"tag":"1.2.2","author":"forge12","date":"2022-01-24 10:23:28","revision":2663104},"1.4.1":{"tag":"1.4.1","author":"forge12","date":"2022-04-08 09:37:48","revision":2706914},"1.4.2":{"tag":"1.4.2","author":"forge12","date":"2022-04-08 10:15:33","revision":2706948},"1.4.3":{"tag":"1.4.3","author":"forge12","date":"2022-04-13 07:29:15","revision":2708968},"1.4.4":{"tag":"1.4.4","author":"forge12","date":"2022-04-13 07:32:54","revision":2708972},"1.4.5":{"tag":"1.4.5","author":"forge12","date":"2022-05-26 08:58:48","revision":2731569},"1.4.6":{"tag":"1.4.6","author":"forge12","date":"2022-07-05 07:44:05","revision":2751947},"1.4.7":{"tag":"1.4.7","author":"forge12","date":"2022-07-10 13:51:19","revision":2754198},"1.4.8":{"tag":"1.4.8","author":"forge12","date":"2022-08-24 14:53:25","revision":2774986},"1.4.9":{"tag":"1.4.9","author":"forge12","date":"2022-09-30 15:46:01","revision":2792571},"1.4.91":{"tag":"1.4.91","author":"forge12","date":"2022-10-03 11:54:57","revision":2793408},"1.4.92":{"tag":"1.4.92","author":"forge12","date":"2022-10-06 13:12:34","revision":2795132},"1.4.93":{"tag":"1.4.93","author":"forge12","date":"2022-11-06 13:00:01","revision":2812934},"1.5":{"tag":"1.5","author":"forge12","date":"2022-12-09 14:14:53","revision":2831203},"1.5.1":{"tag":"1.5.1","author":"forge12","date":"2022-12-11 14:27:57","revision":2831827},"1.5.3":{"tag":"1.5.3","author":"forge12","date":"2023-01-03 12:45:19","revision":2842802},"1.6":{"tag":"1.6","author":"forge12","date":"2023-01-04 10:48:31","revision":2843370},"1.6.1":{"tag":"1.6.1","author":"forge12","date":"2023-01-21 14:29:08","revision":2852274},"1.6.2":{"tag":"1.6.2","author":"forge12","date":"2023-01-21 14:40:00","revision":2852287},"1.6.3":{"tag":"1.6.3","author":"forge12","date":"2023-02-15 12:24:24","revision":2865695},"1.6.4":{"tag":"1.6.4","author":"forge12","date":"2023-02-16 10:56:39","revision":2866289},"1.6.5":{"tag":"1.6.5","author":"forge12","date":"2023-02-16 11:09:41","revision":2866300},"1.6.6":{"tag":"1.6.6","author":"forge12","date":"2023-03-29 10:15:12","revision":2889076},"1.7.1":{"tag":"1.7.1","author":"forge12","date":"2023-04-14 10:11:47","revision":2899085},"1.7.2":{"tag":"1.7.2","author":"forge12","date":"2023-04-14 10:14:09","revision":2899088},"1.7.2.1":{"tag":"1.7.2.1","author":"forge12","date":"2023-04-14 13:03:23","revision":2899163},"1.8":{"tag":"1.8","author":"forge12","date":"2023-04-16 12:28:40","revision":2899717},"1.9":{"tag":"1.9","author":"forge12","date":"2023-04-20 13:28:18","revision":2901828},"1.9.1":{"tag":"1.9.1","author":"forge12","date":"2023-04-24 10:39:23","revision":2903247},"2.0.0":{"tag":"2.0.0","author":"forge12","date":"2024-06-10 12:43:06","revision":3100559},"2.0.1":{"tag":"2.0.1","author":"forge12","date":"2024-06-10 12:52:09","revision":3100569},"2.0.2":{"tag":"2.0.2","author":"forge12","date":"2024-06-10 13:20:36","revision":3100590},"2.0.3":{"tag":"2.0.3","author":"forge12","date":"2024-06-11 13:49:44","revision":3101230},"2.0.4":{"tag":"2.0.4","author":"forge12","date":"2024-06-13 12:29:12","revision":3102293},"2.0.5":{"tag":"2.0.5","author":"forge12","date":"2024-06-17 10:38:24","revision":3103502},"2.0.6":{"tag":"2.0.6","author":"forge12","date":"2024-07-10 07:08:52","revision":3115306},"2.0.61":{"tag":"2.0.61","author":"forge12","date":"2024-07-10 07:18:11","revision":3115314},"2.0.62":{"tag":"2.0.62","author":"forge12","date":"2024-07-21 12:33:30","revision":3122741},"2.0.63":{"tag":"2.0.63","author":"forge12","date":"2024-07-21 12:41:17","revision":3122745},"2.0.64":{"tag":"2.0.64","author":"forge12","date":"2024-07-23 06:24:38","revision":3123565},"2.0.65":{"tag":"2.0.65","author":"forge12","date":"2024-08-14 09:43:35","revision":3135436},"2.0.66":{"tag":"2.0.66","author":"forge12","date":"2024-10-28 08:16:47","revision":3176711},"2.0.68":{"tag":"2.0.68","author":"forge12","date":"2024-11-18 10:42:31","revision":3191109},"2.0.681":{"tag":"2.0.681","author":"forge12","date":"2024-11-18 11:23:46","revision":3191162},"2.0.682":{"tag":"2.0.682","author":"forge12","date":"2024-11-18 12:56:54","revision":3191249},"2.0.7":{"tag":"2.0.7","author":"forge12","date":"2025-01-14 08:49:58","revision":3222090},"2.0.700":{"tag":"2.0.700","author":"forge12","date":"2025-01-14 08:52:02","revision":3222094},"2.0.701":{"tag":"2.0.701","author":"forge12","date":"2025-01-16 07:10:25","revision":3223394},"2.0.702":{"tag":"2.0.702","author":"forge12","date":"2025-01-16 14:41:33","revision":3223647},"2.1.0":{"tag":"2.1.0","author":"forge12","date":"2025-02-05 08:55:08","revision":3235225},"2.1.1":{"tag":"2.1.1","author":"forge12","date":"2025-02-05 09:03:49","revision":3235231},"2.1.2":{"tag":"2.1.2","author":"forge12","date":"2025-02-05 09:06:55","revision":3235236},"2.10.0":{"tag":"2.10.0","author":"forge12","date":"2026-08-03 12:21:48","revision":3632878},"2.11.0":{"tag":"2.11.0","author":"forge12","date":"2026-08-05 04:31:22","revision":3634812},"2.12.0":{"tag":"2.12.0","author":"forge12","date":"2026-08-05 09:53:59","revision":3635179},"2.12.1":{"tag":"2.12.1","author":"forge12","date":"2026-08-06 12:48:41","revision":3636617},"2.13.0":{"tag":"2.13.0","author":"forge12","date":"2026-08-07 11:41:06","revision":3637790},"2.14.0":{"tag":"2.14.0","author":"forge12","date":"2026-08-10 07:18:07","revision":3640120},"2.15.1":{"tag":"2.15.1","author":"forge12","date":"2026-08-13 08:21:00","revision":3644623},"2.15.2":{"tag":"2.15.2","author":"forge12","date":"2026-08-14 11:43:58","revision":3647278},"2.15.3":{"tag":"2.15.3","author":"forge12","date":"2026-08-14 14:51:27","revision":3647584},"2.15.4":{"tag":"2.15.4","author":"forge12","date":"2026-08-27 08:41:45","revision":3668376},"2.2.0":{"tag":"2.2.0","author":"forge12","date":"2025-06-23 12:31:55","revision":3316332},"2.2.1":{"tag":"2.2.1","author":"forge12","date":"2025-06-26 10:58:03","revision":3318193},"2.2.2":{"tag":"2.2.2","author":"forge12","date":"2025-06-26 11:55:16","revision":3318225},"2.2.3":{"tag":"2.2.3","author":"forge12","date":"2025-07-28 06:30:20","revision":3335139},"2.2.4":{"tag":"2.2.4","author":"forge12","date":"2025-09-20 14:30:50","revision":3365014},"2.2.41":{"tag":"2.2.41","author":"forge12","date":"2025-09-21 09:58:42","revision":3365201},"2.2.42":{"tag":"2.2.42","author":"forge12","date":"2025-09-21 10:01:24","revision":3365205},"2.2.43":{"tag":"2.2.43","author":"forge12","date":"2025-09-22 08:15:17","revision":3365621},"2.2.44":{"tag":"2.2.44","author":"forge12","date":"2025-09-22 09:31:09","revision":3365670},"2.2.45":{"tag":"2.2.45","author":"forge12","date":"2025-09-22 10:45:24","revision":3365712},"2.2.46":{"tag":"2.2.46","author":"forge12","date":"2025-09-23 09:26:02","revision":3366339},"2.2.47":{"tag":"2.2.47","author":"forge12","date":"2025-09-23 09:57:08","revision":3366356},"2.2.48":{"tag":"2.2.48","author":"forge12","date":"2025-09-23 10:23:59","revision":3366373},"2.2.49":{"tag":"2.2.49","author":"forge12","date":"2025-09-30 16:01:04","revision":3370575},"2.2.50":{"tag":"2.2.50","author":"forge12","date":"2025-10-01 13:50:49","revision":3371136},"2.2.51":{"tag":"2.2.51","author":"forge12","date":"2025-10-02 11:39:27","revision":3371738},"2.2.52":{"tag":"2.2.52","author":"forge12","date":"2025-10-04 10:17:26","revision":3372782},"2.2.53":{"tag":"2.2.53","author":"forge12","date":"2025-10-24 10:09:00","revision":3383925},"2.2.54":{"tag":"2.2.54","author":"forge12","date":"2025-11-12 13:14:44","revision":3394349},"2.2.55":{"tag":"2.2.55","author":"forge12","date":"2025-11-13 13:10:04","revision":3395063},"2.2.56":{"tag":"2.2.56","author":"forge12","date":"2025-11-17 10:20:51","revision":3397071},"2.2.57":{"tag":"2.2.57","author":"forge12","date":"2025-11-18 08:59:12","revision":3397865},"2.2.58":{"tag":"2.2.58","author":"forge12","date":"2025-11-25 12:51:03","revision":3402534},"2.2.581":{"tag":"2.2.581","author":"forge12","date":"2025-11-25 14:41:37","revision":3402613},"2.2.59":{"tag":"2.2.59","author":"forge12","date":"2025-11-25 14:44:54","revision":3402615},"2.2.60":{"tag":"2.2.60","author":"forge12","date":"2025-12-21 12:29:18","revision":3424685},"2.2.61":{"tag":"2.2.61","author":"forge12","date":"2025-12-23 08:43:44","revision":3425962},"2.3.0":{"tag":"2.3.0","author":"forge12","date":"2026-02-11 07:56:43","revision":3458729},"2.3.1":{"tag":"2.3.1","author":"forge12","date":"2026-02-11 08:01:38","revision":3458735},"2.3.2":{"tag":"2.3.2","author":"forge12","date":"2026-02-18 11:09:02","revision":3464252},"2.3.3":{"tag":"2.3.3","author":"forge12","date":"2026-02-19 09:25:15","revision":3464905},"2.3.4":{"tag":"2.3.4","author":"forge12","date":"2026-02-20 08:23:45","revision":3465568},"2.3.5":{"tag":"2.3.5","author":"forge12","date":"2026-02-20 11:14:16","revision":3465732},"2.6.5":{"tag":"2.6.5","author":"forge12","date":"2026-03-23 16:01:07","revision":3489202},"2.6.6":{"tag":"2.6.6","author":"forge12","date":"2026-03-24 07:29:51","revision":3489679},"2.6.7":{"tag":"2.6.7","author":"forge12","date":"2026-03-25 09:05:52","revision":3490673},"2.6.8":{"tag":"2.6.8","author":"forge12","date":"2026-03-25 12:56:34","revision":3490942},"2.7.3":{"tag":"2.7.3","author":"forge12","date":"2026-06-11 08:14:56","revision":3568478},"2.7.5":{"tag":"2.7.5","author":"forge12","date":"2026-06-25 13:11:58","revision":3586212},"2.7.6":{"tag":"2.7.6","author":"forge12","date":"2026-06-26 05:10:22","revision":3586767}},"upgrade_notice":[],"ratings":{"1":1,"2":1,"3":0,"4":0,"5":19},"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3135000,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3135000,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544-500.png":{"filename":"banner-1544-500.png","revision":2651582,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772-250.png":{"filename":"banner-772-250.png","revision":2651582,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.10.0","1.11.0","1.11.2","1.11.3","1.11.4","1.11.5","1.11.6","1.11.7","1.11.8","1.11.92","1.12.0","1.12.1","1.2","1.2.1","1.2.2","1.4.1","1.4.2","1.4.3","1.4.4","1.4.5","1.4.6","1.4.7","1.4.8","1.4.9","1.4.91","1.4.92","1.4.93","1.5","1.5.1","1.5.3","1.6","1.6.1","1.6.2","1.6.3","1.6.4","1.6.5","1.6.6","1.7.1","1.7.2","1.7.2.1","1.8","1.9","1.9.1","2.0.0","2.0.1","2.0.2","2.0.3","2.0.4","2.0.5","2.0.6","2.0.61","2.0.62","2.0.63","2.0.64","2.0.65","2.0.66","2.0.68","2.0.681","2.0.682","2.0.7","2.0.700","2.0.701","2.0.702","2.1.0","2.1.1","2.1.2","2.10.0","2.11.0","2.12.0","2.12.1","2.13.0","2.14.0","2.15.1","2.15.2","2.15.3","2.15.4","2.2.0","2.2.1","2.2.2","2.2.3","2.2.4","2.2.41","2.2.42","2.2.43","2.2.44","2.2.45","2.2.46","2.2.47","2.2.48","2.2.49","2.2.50","2.2.51","2.2.52","2.2.53","2.2.54","2.2.55","2.2.56","2.2.57","2.2.58","2.2.581","2.2.59","2.2.60","2.2.61","2.3.0","2.3.1","2.3.2","2.3.3","2.3.4","2.3.5","2.6.5","2.6.6","2.6.7","2.6.8","2.7.3","2.7.5","2.7.6"],"block_files":[],"assets_screenshots":{"screenshot-1.jpg":{"filename":"screenshot-1.jpg","revision":3490940,"resolution":"1","location":"assets","locale":"","width":1521,"height":861},"screenshot-10.jpg":{"filename":"screenshot-10.jpg","revision":3490940,"resolution":"10","location":"assets","locale":"","width":1245,"height":595},"screenshot-11.jpg":{"filename":"screenshot-11.jpg","revision":3490940,"resolution":"11","location":"assets","locale":"","width":1254,"height":593},"screenshot-12.jpg":{"filename":"screenshot-12.jpg","revision":3490940,"resolution":"12","location":"assets","locale":"","width":1253,"height":1209},"screenshot-2.jpg":{"filename":"screenshot-2.jpg","revision":3490940,"resolution":"2","location":"assets","locale":"","width":1258,"height":597},"screenshot-3.jpg":{"filename":"screenshot-3.jpg","revision":3490940,"resolution":"3","location":"assets","locale":"","width":1253,"height":1038},"screenshot-4.jpg":{"filename":"screenshot-4.jpg","revision":3490940,"resolution":"4","location":"assets","locale":"","width":1248,"height":1093},"screenshot-5.jpg":{"filename":"screenshot-5.jpg","revision":3490940,"resolution":"5","location":"assets","locale":"","width":1254,"height":895},"screenshot-6.jpg":{"filename":"screenshot-6.jpg","revision":3490940,"resolution":"6","location":"assets","locale":"","width":1236,"height":1220},"screenshot-7.jpg":{"filename":"screenshot-7.jpg","revision":3490940,"resolution":"7","location":"assets","locale":"","width":1262,"height":911},"screenshot-8.jpg":{"filename":"screenshot-8.jpg","revision":3490940,"resolution":"8","location":"assets","locale":"","width":1247,"height":733},"screenshot-9.jpg":{"filename":"screenshot-9.jpg","revision":3490940,"resolution":"9","location":"assets","locale":"","width":690,"height":1148}},"screenshots":{"1":"IP Protection settings","2":"Spam protection in comments","3":"Contact Form 7 integration","4":"Avada Forms integration","5":"Image Captcha example","6":"Arithmetic Captcha example","7":"Honeypot Captcha example"}},"plugin_section":[262246],"plugin_tags":[362,1152,239509,598,2419],"plugin_category":[44],"plugin_contributors":[172866],"plugin_business_model":[],"class_list":["post-147547","plugin","type-plugin","status-publish","hentry","plugin_section-dashboard-widgets","plugin_tags-captcha","plugin_tags-contact-form-7","plugin_tags-fluentform","plugin_tags-honeypot","plugin_tags-spam-protection","plugin_category-discussion-and-community","plugin_contributors-forge12","plugin_committers-forge12","plugin_support_reps-forge12marc"],"banners":{"banner":"https:\/\/ps.w.org\/captcha-for-contact-form-7\/assets\/banner-772-250.png?rev=2651582","banner_2x":"https:\/\/ps.w.org\/captcha-for-contact-form-7\/assets\/banner-1544-500.png?rev=2651582","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/captcha-for-contact-form-7\/assets\/icon-128x128.png?rev=3135000","icon_2x":"https:\/\/ps.w.org\/captcha-for-contact-form-7\/assets\/icon-256x256.png?rev=3135000","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/captcha-for-contact-form-7\/assets\/screenshot-1.jpg?rev=3490940","caption":"IP Protection settings"},{"src":"https:\/\/ps.w.org\/captcha-for-contact-form-7\/assets\/screenshot-2.jpg?rev=3490940","caption":"Spam protection in comments"},{"src":"https:\/\/ps.w.org\/captcha-for-contact-form-7\/assets\/screenshot-3.jpg?rev=3490940","caption":"Contact Form 7 integration"},{"src":"https:\/\/ps.w.org\/captcha-for-contact-form-7\/assets\/screenshot-4.jpg?rev=3490940","caption":"Avada Forms integration"},{"src":"https:\/\/ps.w.org\/captcha-for-contact-form-7\/assets\/screenshot-5.jpg?rev=3490940","caption":"Image Captcha example"},{"src":"https:\/\/ps.w.org\/captcha-for-contact-form-7\/assets\/screenshot-6.jpg?rev=3490940","caption":"Arithmetic Captcha example"},{"src":"https:\/\/ps.w.org\/captcha-for-contact-form-7\/assets\/screenshot-7.jpg?rev=3490940","caption":"Honeypot Captcha example"},{"src":"https:\/\/ps.w.org\/captcha-for-contact-form-7\/assets\/screenshot-8.jpg?rev=3490940","caption":""},{"src":"https:\/\/ps.w.org\/captcha-for-contact-form-7\/assets\/screenshot-9.jpg?rev=3490940","caption":""},{"src":"https:\/\/ps.w.org\/captcha-for-contact-form-7\/assets\/screenshot-10.jpg?rev=3490940","caption":""},{"src":"https:\/\/ps.w.org\/captcha-for-contact-form-7\/assets\/screenshot-11.jpg?rev=3490940","caption":""},{"src":"https:\/\/ps.w.org\/captcha-for-contact-form-7\/assets\/screenshot-12.jpg?rev=3490940","caption":""}],"raw_content":"<!--section=description-->\n<p>SilentShield is a <strong>unified captcha and anti-spam plugin for WordPress<\/strong>.\nIt works with the most popular form builders and protects login, registration, and comment forms \u2013 without slowing your site.<\/p>\n\n<p><strong>Why choose SilentShield?<\/strong>\n- <strong>Invisible defense<\/strong> \u2013 Captcha, honeypot, and blacklists working silently.\n- <strong>Instant results<\/strong> \u2013 Install, activate, and stop spam.\n- <strong>Universal support<\/strong> \u2013 Works with Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms, Forminator, Kadence, WooCommerce, and more.\n- <strong>Privacy-first<\/strong> \u2013 No cookies, no tracking, fully GDPR \/ DSGVO compliant.<\/p>\n\n<p>SilentShield doesn't just protect forms.\nIt protects your time, your customers, your business.<\/p>\n\n\n\n<h3>Core Features<\/h3>\n\n<ul>\n<li>Invisible Captcha (Arithmetic, Honeypot, Image)<\/li>\n<li>Smart IP Blocking &amp; Blacklists<\/li>\n<li>Spam filters for links, code &amp; keywords<\/li>\n<li>Whitelisting for admins &amp; customers<\/li>\n<li>GDPR-ready, no cookies, no tracking<\/li>\n<\/ul>\n\n\n\n<h3>Supported Form Plugins &amp; Integrations<\/h3>\n\n<p>SilentShield protects forms from all major WordPress form builders and core features:<\/p>\n\n<p><strong>Form Builders:<\/strong>\n- Contact Form 7 (CF7)\n- WPForms \/ WPForms Lite\n- Elementor Pro Forms (classic widget and v4 \"atomic\" forms)\n- Gravity Forms\n- Fluent Forms\n- Formidable Forms\n- Ninja Forms\n- Forminator\n- JetFormBuilder\n- Kadence Blocks (Advanced Form)\n- Jetpack Forms (contact form block and shortcode)\n- Avada (Fusion Builder) Forms<\/p>\n\n<p><strong>Newsletter:<\/strong>\n- MC4WP \u2013 Mailchimp for WordPress (signup forms)<\/p>\n\n<p><strong>WooCommerce:<\/strong>\n- Checkout \u2013 block (the default for new shops since WooCommerce 8.3)\n- Checkout \u2013 classic (incl. PayPal Payments)\n- Login\n- Registration\n- Lost password\n- Account details<\/p>\n\n<p><strong>WordPress Core:<\/strong>\n- Login form (wp-login.php)\n- Registration form\n- Lost password form\n- Comment forms (including WooCommerce product reviews)<\/p>\n\n<p><strong>Communities &amp; Forums:<\/strong>\n- bbPress (new topics and replies)\n- BuddyPress (member registration)<\/p>\n\n<p><strong>Donations:<\/strong>\n- GiveWP (classic donation form; the visual-builder form is not yet covered)<\/p>\n\n<p><strong>Other:<\/strong>\n- Ultimate Member (Login &amp; Registration)\n- WP Job Manager (Job Applications)<\/p>\n\n<p>Each integration can be enabled or disabled individually under <strong>Settings &gt; Extended<\/strong>.<\/p>\n\n\n\n<h3>Protection Layers<\/h3>\n\n<p>SilentShield uses <strong>10+ protection mechanisms<\/strong> working together:<\/p>\n\n<ol>\n<li><strong>Captcha<\/strong> \u2013 Arithmetic math, honeypot, or image-based captcha<\/li>\n<li><strong>JavaScript Protection<\/strong> \u2013 Detects submissions from bots without JS support<\/li>\n<li><strong>Browser Detection<\/strong> \u2013 Validates User-Agent strings<\/li>\n<li><strong>Timer Protection<\/strong> \u2013 Blocks submissions faster than a human can type<\/li>\n<li><strong>Multiple Submission Protection<\/strong> \u2013 Prevents rapid duplicate submissions<\/li>\n<li><strong>IP Rate Limiting<\/strong> \u2013 Limits requests per IP and time window<\/li>\n<li><strong>IP Blacklist<\/strong> \u2013 Block known bad IPs<\/li>\n<li><strong>Content Rules<\/strong> \u2013 Limit URLs, block BBCode, keyword blacklist<\/li>\n<li><strong>Gibberish Detection<\/strong> \u2013 Recognises submissions filled with random characters, the kind a bot writes when it only needs the form to go through. Unlike every other check it does not depend on the sender's browser, so a bot driving a real browser cannot pass it by playing along. Starts in observation mode and blocks nothing until you switch it on.<\/li>\n<li><strong>Whitelist<\/strong> \u2013 Skip validation for admins, logged-in users, or specific emails\/IPs<\/li>\n<li><strong>SilentShield API<\/strong> \u2013 Cloud-based spam detection (<a href=\"https:\/\/silentshield.io\/?utm_source=wp-org&amp;utm_medium=readme&amp;utm_campaign=feature-list\">silentshield.io<\/a>)<\/li>\n<\/ol>\n\n\n\n<h3>The Promise<\/h3>\n\n<p>SilentShield is not \"just another plugin.\"\nIt's an invisible wall against the background noise of the internet.<\/p>\n\n<p>Activate once \u2013 and your forms are human again.<\/p>\n\n\n\n<h3>Want more? SilentShield API<\/h3>\n\n<p>Everything above is free and stays free. No feature is held back, no submission limit, no account needed.<\/p>\n\n<p>What the free plugin cannot do is recognise a bot that behaves like a person \u2014 one driving a real browser, solving the captcha, typing at human speed. Rules can only catch what looks wrong, and those do not.<\/p>\n\n<p>The <strong>SilentShield API<\/strong> answers that with behaviour analysis and browser fingerprinting, scored in the cloud, and it usually decides without showing anyone a captcha at all. Switch it on and the local protections stay exactly where they are as a fallback \u2014 if the API is ever unreachable, your forms are still protected.<\/p>\n\n<p>There is a free plan and a trial, and you can see what it would have caught before you pay for anything: turn on Comparison Mode and the plugin logs what the API <em>would<\/em> have decided, alongside what your local rules actually did.<\/p>\n\n<p>\ud83d\udc49 <a href=\"https:\/\/silentshield.io\/pricing?utm_source=wp-org&amp;utm_medium=readme&amp;utm_campaign=upsell-section\">Plans and free trial at silentshield.io<\/a><\/p>\n\n\n\n<h3>Privacy &amp; Telemetry<\/h3>\n\n<ul>\n<li>No cookies, no user tracking.<\/li>\n<li>Encrypted IP storage (max. 2 months, only for spam defense).<\/li>\n<li>Every transmission described below is optional and can be switched off in the plugin settings.<\/li>\n<li>The plugin's built-in Privacy page shows which of these are active on your site, what that means, and gives you ready-made privacy-policy snippets in 25 languages.<\/li>\n<\/ul>\n\n<p><strong>1. Plugin statistics<\/strong> (setting \"Telemetry\")\nAnonymous, no personal data, sent at most once a day:\n- <code>plugin_slug<\/code>, <code>plugin_version<\/code>\n- <code>snapshot_date<\/code>\n- <code>settings_json<\/code> (anonymized config \u2013 only boolean\/integer flags, no free-text)\n- <code>features_json<\/code> (enabled features)\n- <code>created_at<\/code>, <code>first_seen<\/code>, <code>last_seen<\/code>\n- <code>counters_json<\/code> (spam events)\n- <code>wp_version<\/code>, <code>php_version<\/code>, <code>locale<\/code><\/p>\n\n<p><strong>2. AI-crawler observation<\/strong> (setting \"Observe AI crawlers\", on by default; <code>SILENTSHIELD_OBSERVER<\/code> to force off)\nSent only for requests identified as an AI crawler \u2014 never for your human visitors. Delivered after the page has already been sent to the visitor:\n- <code>ua<\/code> (the crawler's User-Agent), <code>ip<\/code>, <code>path<\/code> (without query string), <code>method<\/code>\n- The IP address is pseudonymised on the server (daily keyed hash) and never stored in the clear.<\/p>\n\n<p><strong>3. Blocked-request reports<\/strong> (only with \"Block AI crawlers (enforce)\" on; follows the observation setting above)\nSame fields as (2), plus the outcome (<code>deny<\/code> \/ <code>throttle<\/code>), for every request enforcement turned away. Note that a block rule which is not restricted to a specific crawler can also catch a human visitor \u2014 that request is then reported in the same way.<\/p>\n\n<p><strong>4. Form assessment<\/strong> (only with the SilentShield API enabled)\nSee the API snippet on the plugin's Privacy page for the full description.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload to <code>\/wp-content\/plugins\/<\/code>.<\/li>\n<li>Activate via WordPress \"Plugins\" menu.<\/li>\n<li>Configure protection settings under <strong>Settings &gt; SilentShield<\/strong>.<\/li>\n<\/ol>\n\n<p>For detailed setup instructions, see <a href=\"docs\/installation.md\">docs\/installation.md<\/a>.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"will%20this%20stop%20all%20spam%3F\"><h3>Will this stop all spam?<\/h3><\/dt>\n<dd><p>Not all, but it drastically reduces it. SilentShield combines multiple detection layers (captcha, honeypot, IP blocking, JavaScript detection, timer, content rules) for maximum coverage.<\/p><\/dd>\n<dt id=\"is%20it%20gdpr%20compliant%3F\"><h3>Is it GDPR compliant?<\/h3><\/dt>\n<dd><p>Yes \u2013 no cookies, no tracking, only anonymized data. IPs are stored encrypted for max 2 months (only for spam defense). See the Privacy section below.<\/p><\/dd>\n<dt id=\"do%20i%20need%20coding%20skills%3F\"><h3>Do I need coding skills?<\/h3><\/dt>\n<dd><p>No. Everything is managed via WordPress Dashboard.<\/p><\/dd>\n<dt id=\"does%20it%20work%20with%20woocommerce%20paypal%20payments%3F\"><h3>Does it work with WooCommerce PayPal Payments?<\/h3><\/dt>\n<dd><p>Yes. SilentShield automatically injects JavaScript protection timestamps into PayPal checkout requests. Both PayPal Standard Buttons and Card Fields are supported.<\/p><\/dd>\n<dt id=\"can%20i%20customize%20the%20captcha%20appearance%3F\"><h3>Can I customize the captcha appearance?<\/h3><\/dt>\n<dd><p>Yes. Choose from 3 built-in templates, customize the label and placeholder text, and select a reload icon color (black\/white). Developers can further customize the output via filters.<\/p><\/dd>\n<dt id=\"can%20i%20disable%20specific%20protection%20layers%3F\"><h3>Can I disable specific protection layers?<\/h3><\/dt>\n<dd><p>Yes. Every protection mechanism (captcha, timer, JavaScript, browser, IP, rules, etc.) can be individually enabled or disabled.<\/p><\/dd>\n<dt id=\"how%20do%20i%20whitelist%20my%20admin%20users%3F\"><h3>How do I whitelist my admin users?<\/h3><\/dt>\n<dd><p>Under <strong>Settings &gt; Extended &gt; Whitelist<\/strong>, enable \"Whitelist Admin Users\" and\/or \"Whitelist Logged-In Users\". You can also whitelist specific emails and IPs.<\/p><\/dd>\n<dt id=\"what%20data%20does%20telemetry%20collect%20and%20why%3F\"><h3>What data does telemetry collect and why?<\/h3><\/dt>\n<dd><p>SilentShield includes <strong>optional anonymous telemetry<\/strong> (opt-out).\nThis helps us understand which features are used, so we can improve usability and remove unused complexity.<\/p>\n\n<p><strong>We are a small independent team<\/strong> \u2013 we don't earn money with this plugin, and we don't sell or share data.\nTelemetry is used <strong>only for optimization and maintenance purposes<\/strong>.<\/p><\/dd>\n<dt id=\"where%20is%20the%20full%20documentation%3F\"><h3>Where is the full documentation?<\/h3><\/dt>\n<dd><p>See the <a href=\"docs\/\">docs\/<\/a> directory in the plugin folder for complete documentation of all settings, hooks, REST API, and developer reference.<\/p>\n\n<\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>2.15.4<\/h4>\n\n<ul>\n<li>Fix [Elementor, JetFormBuilder, Avada, Gravity Forms, Ultimate Member]: <strong>With the SilentShield API switched on, every genuine submission on these five was refused as a bot.<\/strong> The API decides using a token the plugin puts into the form, and on these five integrations that field was never added \u2014 so nothing arrived, and a submission with no token is refused by design. The visitor filled in the form correctly, pressed Send, and was told it looked automated. Where the API was the only protection in use, the effect was worse still: the plugin then placed nothing at all in the form, so the page looked as though no protection were installed while the server refused everything that came from it. The field is now added on all five, the same way it always was on the other twenty-one integrations. If you use one of these five together with the API, this restores your forms; nothing needs to be configured. Sites not using the API were never affected, and neither were Contact Form 7, WPForms, WooCommerce or any of the other integrations.<\/li>\n<li>Fix [JetFormBuilder]: Settings made for a single JetFormBuilder form applied only when a submission was checked, not when the form was drawn. A protection switched on for one particular form was therefore expected by the check but never placed in the form \u2014 and every submission of that form was refused, with no way to tell from the page why. Both halves now read the same settings. Only forms with their own settings under Forms were affected; sites using the same settings everywhere were not.<\/li>\n<\/ul>\n\n<h4>2.15.3<\/h4>\n\n<ul>\n<li>Fix [Privacy]: <strong>The plugin's own settings screens loaded a font from Google's servers.<\/strong> Opening any SilentShield page in the WordPress admin fetched the \"Inter\" typeface from <code>fonts.googleapis.com<\/code>, and a request to Google's servers carries the IP address of whoever made it. On a plugin whose purpose is data protection this should never have been the case, and under the GDPR it is the kind of transfer that needs a legal basis nobody had established. The font now ships inside the plugin and is loaded from your own server; not a single request leaves your site any more. Only administrators opening SilentShield's settings were affected \u2014 never visitors, and never anyone filling in one of your forms, because the file was only ever loaded inside the admin area. Nothing changes in how the settings look, and nothing needs to be configured. The font has been part of the plugin since version 2.10.0, so any site running that version or later was affected; if your data protection documentation lists the services your site contacts, this entry can be removed from it.<\/li>\n<\/ul>\n\n<h4>2.15.2<\/h4>\n\n<ul>\n<li>Fix [Protection]: <strong>On some hosts, every form submission failed with a server error.<\/strong> The gibberish detection used PHP's <code>mbstring<\/code> extension, which is optional and which WordPress itself does not require \u2014 it supplies replacements for the two functions it needs and no more. Where the extension was missing, the check ran until it reached a function nobody had replaced and stopped the request dead. The visitor pressed Send and got an error page; no email arrived, and nothing in the plugin's own logs said why. It made no difference that the detection ships in monitoring mode and was not entitled to reject anything: it never got as far as a verdict. The check no longer uses the extension at all. Separately, the gibberish detection can now no longer end a submission by failing, whatever the reason \u2014 if it cannot finish, the submission is let through and the reason is written to the log. Only hosts without <code>mbstring<\/code> were affected; sites where forms have been working are unaffected.<\/li>\n<li>Improvement [Protection]: While rewriting the above, six characters turned out to have been counted as consonants: the Turkish <code>\u0131<\/code> and <code>\u0130<\/code>, the Nordic <code>\u00f8<\/code>, and long vowels such as <code>\u0101<\/code> and <code>\u016b<\/code>. Names written with them looked slightly less pronounceable to the detection than they are \u2014 a small bias against Turkish, Baltic and Scandinavian names, in the one direction that costs a real enquiry rather than a spam. They now count as the vowels they are.<\/li>\n<li>Fix [Forminator, Ninja Forms]: When a submission was refused, the explanation was attached to the form's first field so it would appear next to it \u2014 but \"first\" was taken literally, and a form that begins with a hidden field (a tracking value, a pre-filled ID) had the message attached to something nobody can see. The visitor pressed Send, no email arrived, and nothing at all appeared on screen. Hidden fields are now skipped. This is the same silent failure fixed for Avada in 2.15.0, arrived at by a different route; it was found by checking whether that bug could exist elsewhere, and these two are where it could.<\/li>\n<li>Fix [Elementor]: The same check on a form built entirely from hidden fields left nowhere to put the message, and it was dropped. It is now shown above the form instead.<\/li>\n<\/ul>\n\n<h4>2.15.1<\/h4>\n\n<ul>\n<li>Fix [Translations]: <strong>French sites were not seeing the plugin's own translations at all.<\/strong> When WordPress.org publishes a community translation for a plugin, WordPress uses it <em>instead of<\/em> the one the plugin ships \u2014 not in addition to it. Anything the community translation happens not to cover then falls back to English, even where the plugin has a complete translation for that language sitting right there. French has had a community translation since 7 August, so French sites had quietly been showing English wherever it had a gap. Both are now used together: the community translation still comes first, and the plugin's own fills whatever is left. Nothing changes for languages without a community translation. This affects Persian in the same way, and would have hit any other language the moment one appeared.<\/li>\n<li>Fix [Translations]: The list of integrations under Forms was in English no matter what language your site is in \u2014 \"WordPress Comments\", \"WooCommerce Checkout\", \"Password Reset (WordPress &amp; WooCommerce)\" and the other twenty-four. The names had never been marked as translatable, so no translation of them existed in any language, and there was nothing a translator could have done about it. They are translated now in all twenty-five languages the plugin ships. Product names stay as they are: bbPress is still bbPress, only the part in brackets is translated.<\/li>\n<li>Improvement [Admin]: The settings screen for the SilentShield API was still called \"Beta\" in the menu, which read as a warning about the feature rather than a label. It is now \"API \/ SilentShield\", the same name the newer admin interface has used for a while. Only the name changed \u2014 the page, its address and your settings are untouched.<\/li>\n<li>Fix [Translations]: The plugin's own menu was in English too \u2014 Dashboard, Analytics, Audit Log, Beta, Extended and Forms. Help and Upgrade were translated, which is what made it look like a partial translation rather than a missing one.<\/li>\n<li>Fix [Translations]: On the default captcha template, the line under the puzzle (\"Please enter the characters shown in the CAPTCHA\u2026\") and the reload button's label were always English \u2014 for your visitors, on every site, in every language. They had been written in a way that made them invisible to the translation files, so no language ever had them. This is the only one of these fixes your visitors will notice rather than you.<\/li>\n<li>Fix [Translations]: Eight messages on the dashboard, the ones confirming that logs, timers, captchas or IP bans have been cleared, were spelled with a text domain the plugin does not use. They could not be translated in any language and never had been. Fixed and translated.<\/li>\n<li>Fix [Translations]: Around ninety further texts had never reached the translation files at all: the audit log, the setup notice, the AI-crawler settings and their data-protection notes, the weekly report, the feedback question shown on deactivation, and the descriptions under most of the protection settings. If you have ever wondered why a settings page was half in your language and half in English, this is why. All of them are translated now.<\/li>\n<li>Fix [Translations]: One admin notice was in German for everyone, in every language, including on German sites where it only looked correct by accident \u2014 the one that appears when the SilentShield API cannot be reached and the local protection modules take over. It is now written in English and translated like everything else.<\/li>\n<li>Fix [Translations]: \"%d Overrides\" and \"%d forms found\" on the Forms screen could not be translated because of a gap in the tooling that reads the source code: it never looked for texts that change with a number. Both are translated now, in each language's own plural forms \u2014 three of them in Polish and Czech, four in Slovenian and Maltese.<\/li>\n<\/ul>\n\n<h4>2.15.0<\/h4>\n\n<ul>\n<li>New [Integrations]: Jetpack Forms is now supported \u2014 both the contact form block and the older [contact-form] shortcode, which are the same form underneath. Jetpack is installed on several million sites, and where one of them has a contact page, this is usually the form on it. <strong>You have to switch this on<\/strong>, as with every integration: it appears under Forms as \"Jetpack Forms\".<\/li>\n<li>New [Integrations]: bbPress is now supported, for new topics and for replies. Forums that allow guests to post are among the most reliably spammed things on a WordPress site, because every post is public, permanent and carries links \u2014 and unlike a contact form, nobody has to read the spam for it to do damage.<\/li>\n<li>New [Integrations]: BuddyPress member registration is now supported. An open community signup collects fake profiles rather than emails: they stay on your site, they are indexed, and clearing them out later means going through your member list by hand.<\/li>\n<li>New [Integrations]: GiveWP donation forms are now supported. Donation forms are not spammed the way a contact form is \u2014 they are used for card testing, where somebody runs stolen card numbers through a small donation to find out which ones still work. You do not notice it in an inbox; you notice it in chargebacks and in a payment processor asking questions. This is worth switching on even on a site nobody would bother sending spam to.<\/li>\n<li>Fix [Protection]: A refused submission could tell the visitor that the captcha was not correct without saying which check had refused it \u2014 the message stopped at the colon and nothing followed it. The protection itself worked correctly throughout; only its name was missing, and only on some forms, which is why it went unnoticed for so long. It was most likely to appear exactly where it costs the most: on a donation or payment form, where somebody who simply mistyped is left with a refusal and nothing to correct. Every rejection now names the check that made it.<\/li>\n<li>Fix [Protection]: On a form that has no captcha field, every submission after the first was turned away as a duplicate. The duplicate-submission check hands the form a one-time token and discards it the moment it is used, so the browser has to be given a fresh one after each submission \u2014 and it only ever was as a side effect of the captcha being redrawn. Where there was no captcha to redraw, nothing replaced the token, and the form kept sending the used one. On forms that submit without reloading the page, which is most of them now, the effect was immediate: the first enquiry arrived, the second was refused, and the mail log recorded it as a duplicate submission although the visitor had written something entirely different. Refreshing the page cleared it, so it looked intermittent. The token is now renewed independently of whether a captcha is present.<\/li>\n<li>Fix [Protection]: The same token is also renewed on pages served from a full-page cache, and after a browser back\/forward restore. A cached page hands every visitor the same token, so the first person to submit used it up and everyone after them was refused \u2014 on a cached site with this check enabled, that meant one successful submission per cache refresh. Both cases now fetch a fresh token when the page opens. This also restores the intended behaviour of the minimum-time check on cached pages, where the countdown previously began when the cache was written rather than when the visitor arrived.<\/li>\n<li>Fix [Avada]: A submission Avada refused could fail completely silently \u2014 the visitor pressed Send, nothing appeared, and no email was sent. The refusal message is attached to one of the form's fields for Avada to display next to it, and the field chosen was worked out by discarding everything recognisable as hidden. On a site running a second anti-spam plugin, the field that survived was that plugin's honeypot, which is positioned off-screen by design, so the message was placed somewhere no one could see it. The form's own field list is now used to make that choice, which cannot pick a field the form does not visibly contain; where no visible field exists, the message is shown above the form instead of being lost.<\/li>\n<li><p>Improvement [Logging]: \"Duplicate submission\" in the mail log stood for three unrelated things \u2014 a genuinely reused token, a token this site never issued, and a form sent back faster than the configured minimum. The commonest of the three was the stale token described above, which is not a duplicate at all, so the log confirmed a diagnosis that was wrong. Each is now recorded under its own reason, with a line saying what actually happened and what to look at. Nothing changes about which submissions are blocked.<\/p><\/li>\n<li><p>Note [GiveWP]: This covers the classic donation form, not the newer one built in GiveWP's visual form builder, which has been the default for new forms since GiveWP 3.0. Both still ship, and which one you have depends on when the form was made. <strong>If your form was built in the visual builder, it is not protected by this<\/strong> \u2014 please check rather than assume, because we would rather tell you plainly than let you believe a form is covered when it is not. The newer form assembles what it sends in the browser and only includes fields it knows about, so the timing checks that catch automated donations cannot travel with it. We are working on it.<\/p><\/li>\n<li>Note [bbPress]: Whether a rejected post shows a reason depends on your theme. bbPress hands error messages to the theme to display, and not every theme does \u2014 the one we tested against shows nothing, for bbPress's own errors just as much as for the captcha's. If a post is refused and nothing appears to happen, that is what you are seeing; the post is not created either way.<\/li>\n<li>Note [Jetpack]: A submission that fails the captcha is turned away with a message the sender can read, rather than being quietly filed as spam. Jetpack offers both, and the quiet option is the wrong one here: the person who mistyped a captcha is usually a customer, and filing their enquiry away while showing them a success message means they believe they have written to you and you never find out that they did.<\/li>\n<\/ul>\n\n<h4>2.14.1<\/h4>\n\n<ul>\n<li>Fix [Protection]: On English-language sites, a blocked submission named its reason with an internal identifier rather than words \u2014 \"Captcha not correct: captcha-protection\", or \"rule-protection: blacklist\" where one of your own filter rules had matched. The person reading that has usually just mistyped a captcha, and to them it looks like the website is broken rather than like an explanation. Every other language the plugin ships already had proper wording; English was the one that did not. The nine messages now read as plain labels: \"Captcha check\", \"IP check\", \"Timing check\", \"Duplicate submission\", \"Filter rule: ...\" and so on. Nothing changes about which submissions are blocked \u2014 only about what the visitor is told. It became more noticeable in 2.14.0, because the message for a rate-limited address is now shown for the whole duration of the block instead of only on the submission that triggered it.<\/li>\n<\/ul>\n\n<h4>2.14.0<\/h4>\n\n<ul>\n<li>New [WooCommerce]: The block checkout is now protected. This is the checkout WooCommerce gives every new shop since version 8.3, and until now it received no protection at all \u2014 not a weakened version, none. Captcha, honeypot, timing checks and blacklists were all switched on and doing their work everywhere else on the site, while an order placed at the checkout itself went through untouched. Nothing indicated this: the plugin listed WooCommerce as protected, because it was \u2014 the older, classic checkout was. The two are separate pieces of software that happen to sell the same basket, and the block checkout offers none of the places the classic one does for a plugin to step in. <strong>You have to switch this on.<\/strong> It appears as its own entry, \"WooCommerce Block Checkout\", under Forms, next to the existing \"WooCommerce Checkout\" \u2014 turning that one on does not cover it, and never did. If you are unsure which checkout your shop uses: open your checkout page in the editor, and if it shows a single \"Checkout\" block rather than a shortcode, it is the block one.<\/li>\n<li>Improvement [WooCommerce]: If your checkout block sits on a page other than the one WooCommerce has been told is your checkout \u2014 a landing page, a one-page shop, a custom funnel \u2014 the plugin previously loaded nothing there at all, so no protection could run even where it was configured. It now recognises the checkout block wherever it is placed.<\/li>\n<li>Fix [Protection]: When the rate limit blocked an address, only the submission that triggered the block said so. Every attempt for the rest of the block \u2014 an hour by default \u2014 was turned away with whatever generic wording your form plugin uses when it is given no reason, so a site owner testing their own form a few times in a row locked themselves out and then had a form that refused everything and explained nothing. One person spent hours switching protections off one at a time to find out which one it was. The block now names itself for its whole duration, exactly as the first rejection always did.<\/li>\n<li>Fix [Logging]: The anonymous measurements the new content check records were being written to the same place as the log of blocked submissions. Those two are governed by separate switches with opposite defaults \u2014 measuring is on, the block log is off until you ask for it \u2014 so on a normal installation that table filled up with measurements and contained not a single actual block. Anyone opening it while looking for the reason a submission was turned away found only rows belonging to submissions that had been let <em>through<\/em>, and at least one person reasonably concluded the content check had rejected their enquiry when it had done the opposite. Measurements now have their own place. Existing rows are moved across on update; nothing is lost, and the figures shown on the Analytics screen were correct throughout and do not change.<\/li>\n<li>Improvement [Protection]: The new content check judged a field holding a single long word by that word alone, which is a poor basis for a decision when the field is a name, a town, or a German sentence whose only long word is something like \"Rechnungsanschrift\". A lone word now has to look far more clearly machine-generated before it counts against the field; where a second long word is present, nothing changes. Real spam is unaffected \u2014 it fills whole fields with generated text, and every one of those was rechecked against this. The explanation written alongside each measurement also says plainly what happened to the submission and what it counted, instead of \"1 of 1 words\", which meant \"one of the one words long enough to judge\" and was read, understandably, as a word count.<\/li>\n<\/ul>\n\n<h4>2.13.0<\/h4>\n\n<ul>\n<li>Fix [Avada]: Notification emails from Avada forms arrived with the plugin's own hidden fields listed underneath the enquiry \u2014 rows like \"F12 Timer\" followed by a long string of characters. Nothing was broken and no data was at risk, but to the person reading the email it looked like a malfunctioning website, which is a poor thanks for protection that was otherwise doing its job. Avada is the only form plugin that emails back everything a form sent rather than a message you wrote yourself, which is why it happened there and nowhere else. Those fields are now removed before Avada builds the email, and they no longer appear in the stored submission or in Avada's own entries list either. Two of them had also been kept in the plugin's mail log all along, where nobody happened to look; that is fixed by the same change.<\/li>\n<li>New [Protection]: A new check reads what was actually typed into your forms and recognises the kind of spam that fills every field with random characters \u2014 a name like \"Cowqv Exnjznedy\", a town like \"JPnuTSVqMlNmdwoFObq\". This catches something the other checks cannot: they all work by giving the visitor's browser something to return, which a spam program driving a real browser simply hands back correctly. Judging the text instead does not care how good the program is at pretending to be a person, because writing nonsense is the whole point of what it is doing. It starts in observation mode and blocks nothing until you switch it on under Protection, so it cannot turn a real enquiry away while you are still deciding. It never looks at more than one field in isolation: a single unusual name or product code is normal, and only a submission where several fields are nonsense counts. Non-Latin alphabets are skipped entirely rather than guessed at.<\/li>\n<li>New [Integrations]: Formidable Forms is now supported. It was the one major form plugin that every comparable captcha plugin protected and this one did not.<\/li>\n<li>New [Integrations]: Ninja Forms and Forminator are now supported.<\/li>\n<li>New [Integrations]: Kadence Blocks is now supported, for its Advanced Form block. Kadence's older classic form block cannot be protected \u2014 it offers no way for any plugin to stop a submission \u2014 and Kadence have said they are retiring it.<\/li>\n<li>New [Integrations]: MC4WP (Mailchimp for WordPress) newsletter signup forms are now supported. Junk signups do more damage than junk email: they fill your mailing list with addresses that bounce, and that in turn harms the delivery of every newsletter you send afterwards.<\/li>\n<li>New [Integrations]: The \"lost password\" form is now protected, both WordPress's own and WooCommerce's. Left open, that form can be used to send password emails to any address a spammer cares to type in \u2014 the people receiving them have never heard of your site, and the resulting complaints damage the reputation of your domain, which then costs you every other email you try to send. Nothing about this shows up as spam on your own site, which is why it usually goes unnoticed.<\/li>\n<li>New [Integrations]: The WooCommerce \"account details\" form is now protected. Note that it is only ever shown to logged-in customers, and the plugin skips logged-in visitors by default, so this only takes effect if you have turned that off.<\/li>\n<li>Improvement [Support]: The support link inside the plugin now leads to the SilentShield support board for this plugin instead of a general page.<\/li>\n<\/ul>\n\n<h4>2.12.1<\/h4>\n\n<ul>\n<li>New [Elementor]: Elementor's new v4 forms \u2014 the \"atomic\" forms, built on the new element system \u2014 are now protected. They were not before, and not because the protection failed on them: these forms assemble what they send entirely in the browser and only include the fields Elementor itself placed, so everything this plugin adds was dropped on the way out and the form arrived looking like an ordinary, unprotected submission. Its fields now travel with the request. Nothing of ours appears in your notification email or in the submissions table, and the classic Elementor form widget is unaffected.<\/li>\n<li>Fix [Captcha]: On sites with page caching the reload button stopped working, and did so silently. The button sent a security token that WordPress stamps into the page itself and only accepts for about a day; a cached page keeps serving that token long after it has expired, and WordPress then turned every click away before the plugin ever saw it. The button no longer sends that token. It does not need one \u2014 the address the request comes from is checked instead, which a cache cannot invalidate. This affects the same on every form plugin, not only Contact Form 7.<\/li>\n<li>Fix [Captcha]: If your site sends visitors' browsers the instruction not to disclose which page they came from \u2014 a common privacy setting, and one some privacy extensions apply on their own \u2014 the reload button, the audio button and the timing refresh were refused outright. They were relying on exactly the information that setting withholds. They now use signals the browser sends regardless, so the setting no longer costs you a working captcha.<\/li>\n<li>Fix [Captcha]: The limit on how often a new captcha could be requested was counted per address as your server reports it. Behind a CDN or load balancer that is one and the same address for everybody, so all your visitors together shared a single allowance of thirty requests a minute \u2014 busy enough sites simply ran out, and the reload button then stopped working for everyone at once. The limit now counts each visitor separately, using the proxy setting you may already have configured.<\/li>\n<li>Fix [Captcha]: A reload that failed used to leave no trace whatsoever: the old captcha stayed on screen, nothing was said, and nothing was written to the browser console unless you knew about an undocumented debug switch. There was no way to tell a refused request from a broken connection, and nothing useful a visitor could report. A failed reload now says so next to the captcha and records the reason in the browser console.<\/li>\n<li>Fix [Admin]: The SilentShield navigation column could disappear entirely, leaving no way to reach any of its screens \u2014 the sidebar was still on the page, but hidden, and the button meant to bring it back did nothing. The plugin's own styling was competing on equal footing with a rule WordPress itself ships, and which of the two won came down to the order the stylesheets happened to load in. A theme, another plugin, or anything that combines stylesheets could tip it. The sidebar no longer depends on winning that race.<\/li>\n<\/ul>\n\n<h4>2.12.0<\/h4>\n\n<ul>\n<li>Fix [Admin]: On sites whose permalinks are set to \"Plain\", several screens inside the plugin were simply empty \u2014 the Audit Log, the Mail Log and the Analytics figures showed nothing at all, no matter how much had actually been recorded. The records were never lost; the plugin was asking WordPress for them with a malformed address and getting nothing back. All of those screens fill in again after this update. Sites using any other permalink setting were never affected.<\/li>\n<li>New [Setup]: A newly installed plugin protects nothing until you switch on the form plugins you use, and until now nothing said so \u2014 it sat in your plugin list marked \"active\" while every form on the site was still wide open. There is now a notice in the WordPress admin, and a panel on the SilentShield dashboard, naming the form plugins found on your site and linking straight to the screen where you turn them on. Nothing is enabled for you: switching on something like the WordPress login form uninvited is how people end up locked out of their own site. Both disappear as soon as anything is protected.<\/li>\n<li>New [Logging]: When the SilentShield API is in use, its answer to each check is now written to the Audit Log \u2014 verdict, confidence and the server's actual reply \u2014 so a decision can be examined afterwards instead of being taken on trust. Failed calls are always recorded, including what came back; recording the successful ones as well is a new switch under Advanced \u2192 Logging &amp; Tracking, off by default because it writes one entry per submission. Submissions turned away for carrying no behaviour token are logged now too: that is the most common reason a form is blocked, and it previously left no trace at all.<\/li>\n<\/ul>\n\n<h4>2.11.0<\/h4>\n\n<ul>\n<li>New [Protection]: The hidden fields the plugin adds to your forms \u2014 the honeypot and the two JavaScript timing fields \u2014 no longer carry the same names on every site. They are now named per page load, derived from a signed token, so a spam script can no longer be built once against the fixed names and pointed at every site running this plugin.<\/li>\n<li>Fix [JavaScript protection]: The page age a submission claimed was taken from a hidden field that anyone could set to any value, which meant a form could be fetched once and re-submitted for as long as the spammer liked. That age now comes from a token signed with your site's own secret and is rejected once it is older than 24 hours. Submissions that carry no token at all \u2014 form HTML held in a page cache, or rendered before this update \u2014 keep being accepted as before, so nothing breaks when you update.<\/li>\n<li>Fix [JavaScript protection]: A submission whose end time was <em>before<\/em> its start time counted as valid, because the difference was rounded to whole milliseconds and only compared against zero. Such submissions are now rejected, as are those where both timestamps were written in the same instant.<\/li>\n<li>Fix [Honeypot]: A bot that wrote \"0\" into every field it found passed the trap, because a zero  &hellip;<\/li>\n<\/ul>","raw_excerpt":"SilentShield \u2013 the invisible shield against spam. Spam is the weed of the internet. It clogs your forms, steals your time, and corrupts your data.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/sah.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/147547","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sah.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/sah.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/sah.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=147547"}],"author":[{"embeddable":true,"href":"https:\/\/sah.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/forge12"}],"wp:attachment":[{"href":"https:\/\/sah.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=147547"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/sah.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=147547"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/sah.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=147547"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/sah.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=147547"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/sah.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=147547"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/sah.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=147547"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}