Honeypot Guard – Silent Anti-Spam icon

Honeypot Guard – Silent Anti-Spam

Honeypot Guard – Silent Anti-Spam is a WordPress plugin with the following stats:

  • #7,081 Global Rank
  • 200+ active installs
  • 5/5 1 ratings
  • Since 2026 1 years active

PF Score (About PF Scores)

PF Score is not a quality guarantee. It is a ranking based on available public signals.

Silver61.4
Platinum
Gold
Silver
Bronze
Low

Score Breakdown

38.4
Popularity 40% 200+ active installs
61.9
Reputation 35% 5★ from 1 ratings
97.5
Freshness 25% Updated 29 days ago

No vulnerability history

Download Trends

Loading download data…

Vulnerabilities

No known vulnerabilities

This plugin has no records in the Wordfence Intelligence vulnerability database.

About Honeypot Guard – Silent Anti-Spam

Anti-spam protection for forms, signups, and comments using advanced honeypot techniques. No CAPTCHAs, no user friction.

Honeypot Guard is a powerful, privacy-focused anti-spam solution that protects your WordPress forms without annoying your visitors with CAPTCHAs. Using invisible detection techniques, it blocks spam bots while maintaining a seamless user experience.

Why Choose Honeypot Guard?

Unlike CAPTCHA-based solutions that frustrate users and hurt conversions (studies show CAPTCHAs reduce form submissions by 10-40%), Honeypot Guard provides superior spam protection with zero user friction.

How It Works

Honeypot Guard uses multiple layers of intelligent detection to catch spam automatically:

  • Invisible Honeypot Fields – Hidden fields that real users never see, but bots fill out automatically
  • Dynamic Field Rotation – Constantly changing field names make it harder for sophisticated bots to adapt
  • Timestamp Validation – Detects instant submissions (bots can’t read like humans)
  • Intelligent Gibberish Detection – Catches keyboard mashing and random text patterns
  • Advanced Heuristic Analysis – Pattern-based detection of common spam characteristics
  • Character Script Filtering – Optionally block submissions containing specific character scripts (Cyrillic, Chinese, etc.)
  • Dotted Email Detection – Catches spammers using excessive dots to generate infinite email addresses (e.g. [email protected])
  • Cookie Verification – Proves JavaScript execution in a real browser environment

Key Features

  • Zero User Friction – Completely invisible protection, no annoying puzzles
  • Privacy-Focused – All processing on your server, no third-party tracking by default
  • Granular Blacklisting – Block by email, domain, IP address, or keywords
  • Rate Limiting – Prevent spam floods with configurable submission limits
  • Detailed Spam Logs – View blocked submissions with one-click IP blocking
  • Multi-Language Admin – Available in 9 languages (English, German, Spanish, Italian, Lithuanian, Swedish, Polish, Estonian, Spanish-Mexico)
  • GDPR Compliant – No data sent to external services (unless you enable optional AI detection)
  • Works Automatically – Integrates seamlessly with popular form plugins

Supported Form Plugins

  • Contact Form 7
  • WPForms
  • Gravity Forms
  • Ninja Forms
  • Formidable Forms
  • WordPress Registration Forms
  • WordPress Comments
  • WooCommerce Checkout & Registration
  • bbPress Forums
  • Any HTML form with minimal configuration

Advanced Protection Options

  • Cloudflare Turnstile (Optional) – Invisible CAPTCHA that catches headless browsers, Tor/VPN bots, and bot farms. Free up to 1M validations/month. Fails open — never blocks real users if Cloudflare is down.
  • AI-Powered Gibberish Detection (Optional) – Use OpenAI or Anthropic APIs for advanced content analysis
  • Meta Pixel Protection – Block form submission tracking until verification
  • Custom Honeypot Field Names – Define your own field names for added security
  • Whitelist Trusted Users – Bypass checks for logged-in users or specific IPs

Privacy & Performance

Honeypot Guard is designed with privacy and performance in mind:

  • Lightweight – Adds virtually zero latency to your site
  • No External Calls – Basic protection requires no API calls
  • Cache Compatible – Works with WP Super Cache, W3 Total Cache, WP Rocket, LiteSpeed, and more
  • No Cookies Required – Core functionality works without cookies (optional cookie verification available)

Professional Support

Need help? Visit mantasdigital.com/honeypot-guard for documentation and support.

Privacy Policy

Honeypot Guard collects and stores:

  • IP addresses of form submissions (for spam detection and blocking)
  • Form submission data flagged as spam (for review and pattern detection)
  • Timestamps of submissions (for rate limiting)

This data is stored in your WordPress database and is never sent to external services unless you enable optional AI-powered detection.

You can configure automatic deletion of spam logs in Settings > Honeypot Guard.

External Services

This plugin can optionally connect to external AI services for advanced gibberish detection. These services are disabled by default and must be explicitly enabled by the administrator.

OpenAI API (Optional)

When AI gibberish detection is enabled and configured with an OpenAI API key:

  • What it does: Analyzes suspicious form field content to detect nonsensical or spam text
  • Data sent: Only the specific text field being analyzed (not the entire form submission)
  • When sent: Only when a submission is flagged as potentially suspicious and AI detection is enabled
  • Service provider: OpenAI, L.L.C.
  • Terms of use: https://openai.com/policies/terms-of-use
  • Privacy policy: https://openai.com/policies/privacy-policy

Anthropic API (Optional)

When AI gibberish detection is enabled and configured with an Anthropic API key:

  • What it does: Analyzes suspicious form field content to detect nonsensical or spam text
  • Data sent: Only the specific text field being analyzed (not the entire form submission)
  • When sent: Only when a submission is flagged as potentially suspicious and AI detection is enabled
  • Service provider: Anthropic, PBC
  • Terms of use: https://www.anthropic.com/legal/consumer-terms
  • Privacy policy: https://www.anthropic.com/legal/privacy

Cloudflare Turnstile (Optional)

When Turnstile is enabled and configured with site/secret keys:

  • What it does: Verifies that form submissions come from real browsers, not headless bots
  • Data sent: A challenge token and the visitor’s IP address
  • When sent: On every form submission when Turnstile is enabled
  • Service provider: Cloudflare, Inc.
  • Terms of use: https://www.cloudflare.com/website-terms/
  • Privacy policy: https://www.cloudflare.com/privacypolicy/
  • Fail-open: If Cloudflare is unreachable, no penalty is applied — real users are never blocked

Important: These services are entirely optional. Honeypot Guard provides effective spam protection without any external services using its built-in detection methods.

Additional Info

Frequently Asked Questions

Does this work with Contact Form 7?

Yes! Honeypot Guard automatically integrates with Contact Form 7, WPForms, Gravity Forms, Ninja Forms, and most other popular form plugins without any configuration.

Will this slow down my site?

No. Honeypot Guard is lightweight and runs entirely on your server. Basic protection requires no external API calls, adding virtually zero latency.

Does it work with caching plugins?

Yes. Honeypot Guard is compatible with WP Super Cache, W3 Total Cache, WP Rocket, LiteSpeed Cache, and other popular caching solutions.

Can I whitelist certain IPs or users?

Yes. Go to Settings > Honeypot Guard and enable whitelist options for logged-in users or specific IP addresses.

What languages are supported?

The admin interface is available in: English, German, Spanish, Spanish (Mexico), Italian, Lithuanian, Swedish, Polish, and Estonian.

Is it GDPR compliant?

Yes. Honeypot Guard does not send any data to external services by default. All processing happens on your server. IP addresses are logged only for spam protection and can be configured for automatic deletion.

Can I use this with Cloudflare?

Yes. Honeypot Guard automatically detects the real visitor IP when behind Cloudflare or other reverse proxies.

Does it work with WooCommerce?

Yes. Honeypot Guard protects WooCommerce registration and checkout forms automatically when enabled.

Ratings & Reviews

Recent Reviews

Loading reviews…

View all reviews on WordPress.org (opens in a new tab)

Changelog

2.4.4

  • CRITICAL FIX: Turnstile submit gate no longer blocks form submission — removed stopImmediatePropagation() that killed CF7/WPForms/Gravity Forms handlers
  • Fixed fail-open bypass using requestSubmit() instead of unreliable btn.click() for consistent re-submission across all form builders
  • Turnstile gate now fails open immediately when Turnstile API is blocked (ad blocker, CSP, network error) instead of waiting 3 seconds

2.4.3

  • Fixed remaining unguarded jQuery calls in listenPopups() — Elementor popup/show and PUM pumAfterOpen listeners now also check typeof jQuery before use

2.4.2

  • Fixed listenPopups() crash on sites with Seraphinite Accelerator — unguarded jQuery calls threw ReferenceError when protection script ran before jQuery loaded (seraph-accel-crit causes early execution)

2.4.1

  • Added cookie consent compatibility for Moove GDPR Cookie Compliance (data-gdpr=”necessary”) and Borlabs Cookie (data-borlabs-cookie-type=”essential”)
  • Turnstile now exempt from consent blocking on all 6 major cookie plugins: CACSP, Complianz, CookieYes, CookieBot, Moove GDPR, and Borlabs Cookie

2.4.0

  • Fixed Turnstile blocked by Seraphinite Accelerator lazy-loading — inline script now marked seraph-accel-crit to prevent deferred execution behind cookie consent modals
  • Added cookie consent plugin compatibility — Turnstile registered as strictly necessary/functional with CACSP, Complianz, CookieYes, and CookieBot (security feature, not tracking — GDPR Recital 49)
  • Added CSP header support — challenges.cloudflare.com automatically appended to existing Content-Security-Policy script-src, connect-src, and frame-src directives when Turnstile is enabled

2.3.9

  • Fixed mu-plugin dropper not firing for multisite-only migrations (migration state was checked after mutation instead of before)
  • Simplified multisite migration block to correctly set $migrated flag before modifying active_sitewide_plugins

2.3.8

  • Fixed directory slug migration for WordPress Multisite — network-activated plugins now correctly migrated
  • Fixed potential fatal error when both old and new plugin paths existed in active_plugins simultaneously

2.3.7

  • CRITICAL FIX: Plugin silently deactivated after update due to directory slug mismatch — added automatic migration that repairs active_plugins path
  • Added self-deleting mu-plugin dropper to heal already-broken installs on next page load
  • Fixed dist ZIP folder name to match WP.org slug (honeypot-guard-silent-anti-spam)

2.3.6

  • Fixed Turnstile widget not rendering inside popup/modal forms — widget now attaches to document.body instead of inside the form, preventing display:none from blocking the iframe

2.3.5

  • Security: CF-Connecting-IP header now verified against Cloudflare’s published IP ranges before trusting — prevents IP spoofing on non-Cloudflare sites
  • Added “Cloudflare IP Detection” setting (auto/on/off) in Security section for manual override
  • Auto-detect mode fetches live Cloudflare IP ranges (cached weekly) with hardcoded fallback

2.3.4

  • Security: Fixed REST API validate endpoint — no longer performs stateful mutations (rate limiting, auto-blacklisting) from unauthenticated REST calls
  • Security: Hardened IP detection — removed trust of spoofable X-Forwarded-For/X-Real-IP headers, now uses REMOTE_ADDR (or Cloudflare CF-Connecting-IP when behind Cloudflare)
  • Security: Removed public form nonce fallback from REST permission callback

2.3.3

  • Fixed Turnstile widget visibility — container now uses opacity:0.01 instead of visibility:hidden so Cloudflare’s iframe can render and generate tokens

2.3.2

  • Fixed Turnstile race condition — forms submitted before Turnstile API loads now wait for the token with a 3-second fail-open timeout
  • Added form queue (pendingTsForms) for forms protected before Turnstile is ready
  • Submit interceptor retries up to 6 times (3s) then submits without token to never block real users
  • Works with all form builders: CF7, WPForms, Gravity Forms, Ninja Forms, Divi, Elementor, etc.

2.3.1

  • Bumped WordPress compatibility to 7.0

2.3.0

  • NEW: Dotted Email Detection — catches spammers using excessive dots in email addresses (e.g. [email protected]) to generate infinite unique addresses. Configurable threshold and score penalty. Enabled by default.
  • NEW: Cloudflare Turnstile Integration — optional invisible CAPTCHA that catches headless browsers, Tor/VPN bots, and bot farms that bypass honeypot fields. Free tier (1M validations/month). Fail-open design — never blocks real users if Cloudflare is unreachable. Server-side token verification (secret key never exposed to browsers).
  • Both features available in WordPress and Shopify versions

2.2.3

  • Fixed spacing above activation modal title

2.2.2

  • Fixed activation modal positioning — now displays as full-screen centered overlay
  • Blocking modal with dark transparent background on all plugin admin pages
  • Standalone API endpoint for reliable key activation
  • Smart review prompts with usage-based timing
  • Review request email on Day 6 with platform-specific links

2.2.0

  • Added API key activation system — plugin requires a free API key to enable spam protection
  • API keys generated at mantasdigital.com/honeypot-guard/ and sent via email
  • Admin notice prompts activation with link to get a free key
  • New API Key Activation card at top of settings page
  • Domain-bound keys for basic abuse prevention
  • All 9 admin languages updated with activation UI translations
  • Shopify app: activation banner, settings card, proxy gating

2.1.0

  • Rebranded from Open Honeypot to Honeypot Guard – Silent Anti-Spam
  • Improved input sanitization for enhanced security
  • Consolidated inline scripts into enqueued JavaScript file
  • Moved inline styles to CSS file for better performance
  • Fixed output buffering to ensure proper buffer closure
  • Added additional translated strings for better localization
  • Updated plugin URLs and documentation

2.0.2

  • Fixed all WordPress Plugin Check errors for WordPress.org compliance
  • Added proper output escaping throughout the plugin
  • Replaced date() with gmdate() for timezone consistency
  • Replaced parse_url() with wp_parse_url() for WordPress compatibility
  • Added prefixed helper functions (open_honeypot_t, open_honeypot_e, open_honeypot_url)
  • Improved SQL query security with proper escaping
  • Fixed plugin header for WordPress.org submission

2.0.1

  • Added cookie verification option for JavaScript execution proof
  • Added blocked entries management for viewing spam patterns
  • Improved gibberish detection with multiple algorithms
  • Added South Asian script blocking option
  • Multi-language sidebar menu items
  • Updated translations for all 9 languages

2.0.0

  • Complete rewrite with modern architecture
  • Added AI-powered gibberish detection (OpenAI/Anthropic)
  • Added granular blacklisting (email, domain, IP, keywords)
  • Added rate limiting
  • Added multi-language support (9 languages)
  • Added spam log dashboard with one-click IP blocking
  • Added Contact Form 7 rate limiting fix
  • Improved heuristic analysis
  • Added WPML compatibility

1.0.0

  • Initial release
  • Basic honeypot protection
  • Timestamp validation
  • Simple blacklisting

Alternatives to Honeypot Guard – Silent Anti-Spam

Other WordPress plugins serving a similar purpose, ranked by relevance and PF Score.

Platinum94.3
Antispam Bee icon

Antispam Bee

Filters spam from WordPress comments and trackbacks with privacy-focused protection built in.

★ 4.8/5·700K+ installs·Updated 29 May 2026
Platinum87.1
CF7 Apps – Honeypot, Database, Redirection, Webhook, and Addons for Contact Form 7 icon

CF7 Apps

Adds hCaptcha, honeypot, and spam protection to Contact Form 7 with lightweight security features.

★ 3.8/5·300K+ installs·Updated 6 Aug 2026
Platinum86.1
Blackhole for Bad Bots icon

Blackhole for Bad Bots

Traps and blocks malicious bots from accessing your WordPress site using honeypot detection methods.

★ 4.7/5·30K+ installs·Updated 9 Aug 2026
Platinum98.7
Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) icon

Really Simple Security

Hardens WordPress security with two-factor authentication, login protection, and vulnerability detection across 3 million active sites.

★ 4.9/5·3.0M+ installs·Updated 27 Jul 2026
Platinum98.3
Limit Login Attempts Security – Login Security, 2FA, Firewall, Brute Force Prevention icon

Limit Login Attempts Security

Defends WordPress logins with brute force protection, two-factor authentication, and IP blocking.

★ 4.8/5·1.0M+ installs·Updated 12 Aug 2026
Platinum98.0
Loginizer icon

Loginizer

Protects WordPress login pages from brute force attacks through automated threat detection and blocking.

★ 4.8/5·1.0M+ installs·Updated 3 Aug 2026
Platinum97.7
Akismet Anti-spam: Spam Protection icon

Akismet Anti-spam: Spam Protection

Filters spam comments and contact form submissions across WordPress and WooCommerce sites.

★ 4.7/5·5.0M+ installs·Updated 17 Aug 2026
Platinum97.6
Wordfence Security – Firewall, Malware Scan, and Login Security icon

Wordfence Security

Firewall, malware scanner, and two-factor authentication for WordPress site security.

★ 4.7/5·5.0M+ installs·Updated 10 Aug 2026
Platinum96.9
ManageWP Worker icon

ManageWP Worker

Centralized dashboard for managing, backing up, and securing multiple WordPress sites simultaneously.

★ 4.6/5·1.0M+ installs·Updated 18 Aug 2026