Maspik – Multi-Layer Spam Protection icon

Maspik – Multi-Layer Spam Protection

Filters unwanted form submissions using spam detection methods that do not require CAPTCHA verification. Active on more than 30,000 sites with a 4.7/5 rating and a Platinum PF Score of 85.1, indicating strong plugin maturity and user adoption.

Generated on 8 Jul 2026. Score and stats mentioned may differ from current live data.

  • #609 Global Rank
  • 30K+ active installs
  • 4.7/5 87 ratings
  • Since 2021 6 years active

PF Score (About PF Scores)

PF Score is not a quality guarantee. It is a ranking based on available public signals.

Platinum85.5
Platinum
Gold
Silver
Bronze
Low

Score Breakdown

74.6
Popularity 40% 30K+ active installs
87.6
Reputation 35% 4.7★ from 87 ratings
99.8
Freshness 25% Updated 2 days ago

No active penalty — 9 historical CVEs, resolved — details

Download Trends

Loading download data…

Vulnerabilities

9 Total
9 Patched
0 Active
100% Resolved rate
CWE-79 · Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The Maspik – Spam blacklist plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.9.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

7.2 High Affected All – 2.9.1 Patched in ✓ 2.9.2 Published 12 Aug 2026 CVE CVE-2026-28003
CWE-862 · Missing Authorization

The Maspik plugin for WordPress is vulnerable to Missing Authorization in version 2.5.6 and prior. This is due to missing capability checks on the Maspik_spamlog_download_csv function. This makes it possible for authenticated attackers, with subscriber-level access and above, to export and download the spam log database containing blocked submission attempts, which may include misclassified but legitimate submissions with sensitive data.

4.3 Medium Affected All – 2.5.6 Patched in ✓ 2.5.7 Published 9 Sep 2025 CVE CVE-2025-9979
CWE-352 · Cross-Site Request Forgery (CSRF)

The Maspik – Ultimate Spam Protection plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.6. This is due to missing or incorrect nonce validation on the clear_log function. This makes it possible for unauthenticated attackers to clear all spam logs via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

4.3 Medium Affected All – 2.5.6 Patched in ✓ 2.5.7 Published 9 Sep 2025 CVE CVE-2025-9888
CWE-352 · Cross-Site Request Forgery (CSRF)

The Maspik – Advanced Spam Protection plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.7. This is due to missing or incorrect nonce validation on one of its functions. This makes it possible for unauthenticated attackers to change plugin settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

4.3 Medium Affected All – 2.2.7 Patched in ✓ 2.2.8 Published 2 Dec 2024 CVE CVE-2024-53806
CWE-79 · Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The Maspik – Spam Blacklist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

4.4 Medium Affected All – 2.1.2 Patched in ✓ 2.1.3 Published 2 Oct 2024 CVE CVE-2024-9182

Vulnerability data provided by Wordfence Intelligence (opens in a new tab). CVE data: Copyright 1999–2026 The MITRE Corporation. CVE Terms of Use (opens in a new tab).

About Maspik – Multi-Layer Spam Protection

Multi-layer spam protection for forms, comments and WooCommerce. No CAPTCHA, no puzzles — accurate blocking that works out of the box.

Maspik is a complete spam protection platform for WordPress.

Instead of relying on a single detection method, Maspik combines multiple independent protection layers that work together to stop spam before it reaches your inbox.

Protect contact forms, registration forms, comments, WooCommerce, and custom forms using lightweight local validation together with optional cloud intelligence.

Install. Activate. You’re protected.

No CAPTCHA. No puzzles. No interruption for real visitors.

Why Maspik?

Most anti-spam plugins rely on one detection technique. Some only use CAPTCHAs. Some only check external APIs. Some only filter keywords.

Maspik combines many protection layers into one unified spam detection engine.

Every submission can be analysed using local validation, behavioural analysis, reputation services, and optional cloud intelligence.

The result is stronger protection with fewer false positives and a better experience for legitimate visitors.

Protection Layers

Maspik lets you combine multiple independent protection methods:

  • Forbidden keywords
  • Email patterns
  • URL validation
  • Phone format validation
  • Character limits
  • Link limits
  • Emoji filtering
  • Honeypot protection
  • Verification Key
  • Direct POST protection
  • IP blocklists
  • IP reputation
  • Proxy and VPN detection
  • Country and continent restrictions (Pro)
  • Language rules (Pro)
  • Maspik Matrix cloud protection with AI analysis

Enable only the protection layers you need. Everything is configurable.

Built for Performance

Most protection happens locally inside WordPress without contacting external services.

Only optional features such as Matrix or IP reputation require cloud requests. Only enabled protection layers are executed.

No unnecessary JavaScript. No front-end slowdown. Optimized for high-traffic websites.

Privacy First

Most spam detection happens locally. Cloud-based protection is optional, and only the required data is transmitted when it is enabled.

No visitor tracking. GDPR friendly.

Works Immediately

Maspik is designed to work immediately after activation. No complicated configuration, no API keys required, no CAPTCHA setup.

Advanced users can fine-tune every protection layer individually.

Supported Forms

Maspik protects WordPress core forms together with many popular form builders:

  • Elementor Forms
  • Elementor Atomic Forms
  • Contact Form 7
  • Fluent Forms
  • Formidable Forms
  • Forminator
  • Ninja Forms
  • JetFormBuilder
  • Everest Forms
  • Breakdance Forms
  • Bricks Builder
  • Divi Contact Form
  • Hello Plus
  • MetForm
  • Bit Form
  • BuddyPress Registration
  • WordPress Comments
  • WordPress Registration
  • Custom PHP forms (simple developer API)

Pro also supports:

  • WPForms
  • Gravity Forms
  • WooCommerce Registration
  • WooCommerce Checkout

Maspik Matrix

Maspik Matrix is an optional cloud protection layer built into Maspik. It complements the local protection engine by analysing submissions using additional cloud intelligence.

Matrix may include:

  • IP reputation
  • Pattern analysis
  • Heuristic detection
  • Structural analysis
  • AI scoring
  • Threat intelligence

Local rules always continue working independently.

Every installation includes free Matrix usage (100 checks per month). Pro includes unlimited usage.

Submission Log

Understand exactly why spam was blocked. The log shows:

  • Block reason
  • Triggered protection layer
  • Submitted values
  • Full detection trace of every layer that ran
  • IP address and country
  • Date and time
  • Page URL

Mark entries as “Not Spam” to continuously improve your configuration, or turn a blocked value into a rule with one click.

Optionally log passed submissions too, to see exactly why something was not caught.

Statistics

Monitor your protection over time:

  • Total blocked submissions
  • Detection trends
  • Protection layer activity
  • Matrix usage
  • Spam history

API Integrations

Optional integrations include:

  • AbuseIPDB
  • ProxyCheck

Enable only the services you want.

Designed For

  • Business websites
  • WooCommerce stores
  • Agencies
  • Membership websites
  • High-traffic websites
  • Enterprise WordPress

Why Site Owners Choose Maspik

  • No CAPTCHA
  • Better user experience
  • Works immediately
  • Lightweight
  • Multiple protection layers
  • Detailed spam logs
  • Powerful statistics
  • Extensive customization
  • Local-first architecture
  • Optional cloud intelligence
  • Import and export your configuration

Pro Features

Upgrade to Maspik Pro and unlock:

  • Unlimited Matrix protection
  • Country and continent restrictions
  • Language rules
  • Premium integrations (WPForms, Gravity Forms, WooCommerce)
  • Central Dashboard to manage rules across multiple websites
  • Premium support

Learn more: https://wpmaspik.com/

Spam Block Guarantee

Spam is constantly evolving. If unwanted submissions are still getting through, we’ll help you configure Maspik until they’re blocked.

Join the community, share a sample, and we’ll help you improve your protection.

Custom Forms

Built your own form in PHP? List the fields you want analysed and Maspik tells you whether to accept the submission:

$fields = [ [ 'type' => 'text', 'field_name' => 'name', 'value' => $_POST['name'] ?? '' ], [ 'type' => 'email', 'field_name' => 'email', 'value' => $_POST['email'] ?? '' ], [ 'type' => 'textarea', 'field_name' => 'message', 'value' => $_POST['message'] ?? '' ] ];

if ( function_exists( 'maspik_is_spam' ) && maspik_is_spam( $fields, 'Contact form' ) ) { wp_die( 'Spam detected' ); }

Listing the fields explicitly means Maspik analyses exactly the values you care about — never nonces, redirects, tokens, checkboxes or other technical inputs — which keeps detection predictable and avoids false positives.

The honeypot and verification key are read from the request automatically, so there is nothing else to wire up.

Need the reason? maspik_check_spam() returns the message to show the visitor, the offending field, and the layer that blocked it.

The original version 2 filter (maspik_validate_custom_form_fields) continues to work unchanged, so existing integrations keep running after the upgrade.

Full example: https://wpmaspik.com/documentation/custom-php-form/

Documentation

  • Getting Started: https://wpmaspik.com/documentation/
  • Developer Documentation: https://wpmaspik.com/documentation/developers/
  • Support: https://wpmaspik.com/
  • Community: https://www.facebook.com/groups/maspik

Maspik is developed with a strong focus on performance, security, privacy and long-term WordPress compatibility.

Screenshots

Dashboard — protection status, statistics and recent activity at a glance.

Dashboard — protection status, statistics and recent activity at a glance.

Protection — enable and configure each detection layer.

Protection — enable and configure each detection layer.

Logs — review blocked submissions with the full detection trace.

Logs — review blocked submissions with the full detection trace.

Analytics — detection trends over time.

Analytics — detection trends over time.

Playground — test your configuration against sample submissions.

Playground — test your configuration against sample submissions.

Frequently Asked Questions

Do I need to configure anything?

No. Maspik works immediately after activation with sensible defaults. Everything is configurable if you want to fine-tune it.

Will it work with my form plugin?

Maspik supports the most popular form builders out of the box (see the list above) as well as WordPress comments and registration. Active integrations are detected automatically and listed on the Dashboard.

Do I need an API key?

No. Core protection runs locally with no keys. Optional services such as AbuseIPDB or ProxyCheck use your own key if you choose to enable them.

Was a real visitor blocked by mistake?

Open the Logs screen, find the submission, and choose Mark as Not Spam. The sender is added to your allow list and won’t be blocked again. You can also remove the specific rule that caused the block directly from the log entry.

Does it slow down my site?

No. Most checks run locally in PHP, only enabled layers execute, and there is no front-end JavaScript beyond the small guard script used by the honeypot and verification key.

Does it work with page caching?

Yes. Protection runs on submission, not on page render, so cached pages are unaffected.

Will my settings carry over when upgrading from version 2?

Yes. Settings, logs, your license and your Dashboard connection all carry over automatically on update — no reconfiguration needed.

Ratings & Reviews

Recent Reviews

Loading reviews…

View all reviews on WordPress.org (opens in a new tab)

Changelog

3.0.2

  • Fixed: an issue when 2 patterns exist in the Language protection layer.

3.0.1

  • Export the spam log to CSV from the Logs screen, with every submitted field.
  • Fixed: dropdowns, dates, numbers and checkboxes are now recorded in the log — in Gravity Forms and every other form plugin.
  • Fixed: Honeypot Trap and Advance key check switched on in the MASPIK Dashboard are now applied to the site.

3.0.0

  • Complete rewrite: modern modular architecture (PSR-4, dependency injection) with identical spam-detection behavior, covered by unit and integration tests.
  • New admin experience: Dashboard, Protection, Logs, Analytics, Playground, Advanced and Pro screens.
  • Detection Trace: every logged submission records which layers ran, passed, were skipped, timed out or blocked it.
  • Submission logging: choose to log nothing, blocked submissions only, or all submissions for debugging, with retention by row count and by age.
  • One-click rule actions from the log — whitelist a sender, or remove the exact rule that caused a block.
  • Direct POST protection: submissions that bypass the site interface are detected and reported to Matrix.
  • New integrations: Elementor Atomic Forms, Divi, JetFormBuilder, Formidable, MetForm, Breakdance, Bit Form, BuddyPress, WooCommerce Checkout and WooCommerce Registration.
  • WooCommerce checkout protection on both classic and block checkout, with per-gateway control, zero-total orders and a custom blocked-checkout message.
  • Improved IP resolution with a proper proxy trust model, including Cloudflare support.
  • Per-layer custom error messages.
  • Custom PHP forms: new maspik_is_spam() / maspik_check_spam() helpers, so connecting your own form takes one line. Guard fields are handled automatically. The version 2 filter (maspik_validate_custom_form_fields) still works unchanged.
  • Translations for Spanish, French, German, Arabic and Hebrew.
  • Requires PHP 7.4+.

Alternatives to Maspik – Multi-Layer Spam Protection

Other WordPress plugins serving a similar purpose, ranked by relevance and PF Score.

Platinum97.7
Akismet Anti-spam: Spam Protection icon

Akismet Anti-spam: Spam Protection

Filters spam comments and contact form submissions across WordPress and WooCommerce sites.

★ 4.7/5·5.0M+ installs·Updated 17 Aug 2026
Gold84.2
Gravity Forms Zero Spam icon

Gravity Forms Zero Spam

Protects Gravity Forms from spam submissions using honeypot and anti-spam detection methods.

★ 4.3/5·100K+ installs·Updated 14 Aug 2026
Gold75.8
Spam Destroyer icon

Spam Destroyer

Automated spam filtering for WordPress comments and BuddyPress community discussions.

★ 4.6/5·5K+ installs·Updated 29 Apr 2026
Platinum94.3
Antispam Bee icon

Antispam Bee

Filters spam from WordPress comments and trackbacks with privacy-focused protection built in.

★ 4.8/5·700K+ installs·Updated 29 May 2026
Platinum87.1
CF7 Apps – Honeypot, Database, Redirection, Webhook, and Addons for Contact Form 7 icon

CF7 Apps

Adds hCaptcha, honeypot, and spam protection to Contact Form 7 with lightweight security features.

★ 3.8/5·300K+ installs·Updated 6 Aug 2026
Platinum87.1
hCaptcha for WP icon

hCaptcha for WP

CAPTCHA alternative that integrates with Contact Form 7, WooCommerce, Elementor, and 60+ other plugins.

★ 4.6/5·70K+ installs·Updated 6 Aug 2026
Platinum86.1
Blackhole for Bad Bots icon

Blackhole for Bad Bots

Traps and blocks malicious bots from accessing your WordPress site using honeypot detection methods.

★ 4.7/5·30K+ installs·Updated 9 Aug 2026
Gold84.0
Stop Spammers Classic icon

Stop Spammers Classic

Filters and blocks spam submissions to protect WordPress sites from unwanted content.

★ 4.4/5·30K+ installs·Updated 18 Jul 2026
Gold79.9
OOPSpam Anti-Spam: Spam Protection for WordPress Forms & Comments (No CAPTCHA) icon

OOPSpam Anti-Spam

Blocks form and comment spam without CAPTCHA or JavaScript, claiming 99.9% accuracy across protected submissions.

★ 4.9/5·6K+ installs·Updated 24 Jul 2026
Gold79.3
Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms icon

Invisible Anti-Spam & CAPTCHA

Invisible spam protection for every form, login and checkout. No puzzles, no checkboxes, no lost visitors — a CAPTCHA your…

★ 4.9/5·4K+ installs·Updated 11 Aug 2026
Gold75.9
Kama SpamBlock icon

Kama SpamBlock

Light and invisible protection against basic automated comment spam. Pings and trackbacks check for real backlinks.

★ 5/5·4K+ installs·Updated 25 Jul 2026