{"id":241299,"date":"2025-12-08T05:36:58","date_gmt":"2025-12-08T05:36:58","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/digitalezen-cf7-antispam-shield\/"},"modified":"2026-08-26T07:17:32","modified_gmt":"2026-08-26T07:17:32","slug":"digitalezen-antispam-shield-for-cf7","status":"publish","type":"plugin","link":"https:\/\/pe.wordpress.org\/plugins\/digitalezen-antispam-shield-for-cf7\/","author":17757124,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.1.0","stable_tag":"1.1.0","tested":"7.1","requires":"6.7","requires_php":"7.4","requires_plugins":null,"header_name":"DigitaleZen AntiSpam Shield for CF7","header_author":"DigitaleZen","header_description":"Advanced protection against spam for Contact Form 7. Blacklist, logging, flood control and a sleek dashboard.","assets_banners_color":"336572","last_updated":"2026-08-26 07:17:32","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/wordpress.org\/plugins\/digitalezen-antispam-shield-for-cf7\/","header_author_uri":"https:\/\/digitalezen.it","rating":0,"author_block_rating":0,"active_installs":0,"downloads":348,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"riccardorosignoli","date":"2025-12-08 05:37:02"},"1.1.0":{"tag":"1.1.0","author":"riccardorosignoli","date":"2026-08-26 07:17:32"}},"upgrade_notice":{"1.1.0":"<p>Security, privacy, compatibility, and data-migration update for WordPress 7.1 and Contact Form 7 6.1.7. Back up the site and database before updating.<\/p>"},"ratings":[],"assets_icons":{"icon-256x256.png":{"filename":"icon-256x256.png","revision":3413878,"resolution":"256x256","location":"assets","locale":"","width":512,"height":512}},"assets_banners":{"banner-772x250.png":{"filename":"banner-772x250.png","revision":3413878,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.0","1.1.0"],"block_files":[],"assets_screenshots":[],"screenshots":[]},"plugin_section":[],"plugin_tags":[109,1784,1152,598,599],"plugin_category":[54],"plugin_contributors":[251858],"plugin_business_model":[],"class_list":["post-241299","plugin","type-plugin","status-publish","hentry","plugin_tags-antispam","plugin_tags-blacklist","plugin_tags-contact-form-7","plugin_tags-honeypot","plugin_tags-spam","plugin_category-security-and-spam-protection","plugin_contributors-riccardorosignoli","plugin_committers-riccardorosignoli"],"banners":{"banner":"https:\/\/ps.w.org\/digitalezen-antispam-shield-for-cf7\/assets\/banner-772x250.png?rev=3413878","banner_2x":false,"banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/digitalezen-antispam-shield-for-cf7\/assets\/icon-256x256.png?rev=3413878","icon_2x":"https:\/\/ps.w.org\/digitalezen-antispam-shield-for-cf7\/assets\/icon-256x256.png?rev=3413878","generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p>DigitaleZen AntiSpam Shield for CF7 protects Contact Form 7 submissions without adding a CAPTCHA or requiring form-tag configuration.<\/p>\n\n<p>Its checks run through Contact Form 7's supported spam API and include:<\/p>\n\n<ul>\n<li>An automatic, visually hidden honeypot.<\/li>\n<li>A site-signed form token with a minimum submission time.<\/li>\n<li>Per-IP and per-email rate limiting.<\/li>\n<li>A local adaptive blacklist that learns site-HMAC email\/IP identities only from high-confidence spam signals.<\/li>\n<li>Matching against migrated or locally supplied domain, username, and keyword rules.<\/li>\n<li>Contact Form 7 spam-log integration for every local decision.<\/li>\n<\/ul>\n\n<p>Blocked-event data is stored in private WordPress database tables. The default privacy mode stores masked email and IP values together with site-specific HMAC identifiers. Events are removed automatically after 30 days by default; administrators can select a retention period from 1 to 365 days.<\/p>\n\n<p>The local reputation threshold is deliberately conservative. Learned entries expire after 90 days without new evidence, and administrators can reset all learned reputation after a suspected false positive. The signed JSON blacklist is rebuilt locally with an atomic replacement and a verified database fallback. It contains no plaintext email or IP address.<\/p>\n\n<p>The dashboard provides local event totals, a text-accessible chart summary, protected CSV export, local-blacklist status, privacy controls, and optional weekly email reports. Weekly reports are disabled by default.<\/p>\n\n<p>When version 1.1.0 upgrades an existing 1.0.0 installation, it first stores a checksum-verified private backup of known legacy files, imports compatible log and blacklist data, and only then removes those files from the public uploads directory. The original private migration backups remain available for administrator-controlled deletion.<\/p>\n\n<h3>Privacy<\/h3>\n\n<p>Blocked events are stored locally in WordPress database tables and are subject to the configured retention period. The plugin registers exporters and erasers with the WordPress personal-data tools and adds suggested privacy-policy text under <strong>Settings &gt; Privacy<\/strong>.<\/p>\n\n<p>The reputation table and signed local JSON use site-specific HMAC values for email and IP identities. Those values cannot be reused as a shared cross-site blacklist. The JSON is placed in a randomized plugin directory with Apache\/IIS deny rules and a blocking index file; the verified database copy remains the runtime fallback.<\/p>\n\n<p>CSV exports are available only to administrators, require a WordPress nonce, and neutralize spreadsheet formula prefixes.<\/p>\n\n<h3>External services<\/h3>\n\n<p>This plugin does not use an external blacklist, CAPTCHA, analytics endpoint, CDN asset, or other external service. All detection, learning, storage, JSON generation, and scheduled cleanup run on the site that installed the plugin.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Install and activate Contact Form 7 version 6.1.7 or newer.<\/li>\n<li>Install and activate DigitaleZen AntiSpam Shield for CF7.<\/li>\n<li>Open <strong>CF7 AntiSpam<\/strong> in the WordPress administration menu.<\/li>\n<li>Review retention, privacy, and optional weekly-report settings.<\/li>\n<\/ol>\n\n<p>No Contact Form 7 form tags or shortcodes need to be added.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20it%20require%20a%20captcha%3F\"><h3>Does it require a CAPTCHA?<\/h3><\/dt>\n<dd><p>No. The plugin uses an automatic honeypot, signed timing token, rate limiting, and local adaptive blacklist matching.<\/p><\/dd>\n<dt id=\"do%20i%20need%20to%20edit%20my%20contact%20form%207%20forms%3F\"><h3>Do I need to edit my Contact Form 7 forms?<\/h3><\/dt>\n<dd><p>No. The token and honeypot fields are inserted automatically through Contact Form 7 filters.<\/p><\/dd>\n<dt id=\"what%20visitor%20data%20is%20stored%3F\"><h3>What visitor data is stored?<\/h3><\/dt>\n<dd><p>Only submissions classified as spam are logged. By default, the plugin stores the event time, form ID, detection reason, masked email\/IP values, and site-HMAC identifiers. Administrators can choose full identity storage, change retention, export retained events, or delete them.<\/p><\/dd>\n<dt id=\"does%20deactivation%20delete%20data%3F\"><h3>Does deactivation delete data?<\/h3><\/dt>\n<dd><p>No. Deactivation only removes scheduled tasks. Data is deleted during plugin removal only when the administrator has explicitly enabled <strong>Delete all plugin data when the plugin is deleted<\/strong>.<\/p><\/dd>\n<dt id=\"are%20weekly%20reports%20enabled%20automatically%3F\"><h3>Are weekly reports enabled automatically?<\/h3><\/dt>\n<dd><p>No. Weekly CSV reports are opt-in and use the email address selected by an administrator.<\/p><\/dd>\n<dt id=\"does%20the%20blacklist%20use%20an%20external%20service%3F\"><h3>Does the blacklist use an external service?<\/h3><\/dt>\n<dd><p>No. The plugin creates and updates its signed JSON blacklist on the WordPress site itself. It makes no reputation or blacklist request to DigitaleZen, Google, or another provider.<\/p><\/dd>\n<dt id=\"how%20does%20local%20learning%20avoid%20immediate%20false%20positives%3F\"><h3>How does local learning avoid immediate false positives?<\/h3><\/dt>\n<dd><p>Only high-confidence honeypot and repeated rate-limit signals add local reputation evidence. An identity is not promoted to the active blacklist until it reaches the learning threshold. Token errors alone never teach the blacklist, learned entries expire, and an administrator can reset learned reputation.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>Tested with WordPress 7.1, PHP 8.4, and Contact Form 7 6.1.7.<\/li>\n<li>Replaced public uploads-based logs and counters with private database tables.<\/li>\n<li>Added checksum-verified migration of version 1.0.0 data before public legacy files are removed.<\/li>\n<li>Added masked identity storage by default, configurable retention, privacy exporters\/erasers, and uninstall controls.<\/li>\n<li>Switched spam classification to Contact Form 7's supported <code>wpcf7_spam<\/code> API and spam log.<\/li>\n<li>Added an automatic honeypot and site-signed timing token without requiring form tags.<\/li>\n<li>Made rate limiting atomic and scoped it to actual submissions.<\/li>\n<li>Replaced the external blacklist feed with a site-local adaptive reputation engine and signed JSON cache.<\/li>\n<li>Added conservative evidence thresholds, automatic reputation expiry, administrator reset, atomic JSON replacement, and a verified database fallback.<\/li>\n<li>Made weekly reports opt-in and stopped deleting retained events after an email attempt.<\/li>\n<li>Added nonce- and capability-protected dashboard actions and formula-safe CSV exports.<\/li>\n<li>Added reproducible PHPCS, PHP compatibility, PHPUnit, and WordPress integration tests.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial public release.<\/li>\n<\/ul>","raw_excerpt":"Privacy-conscious spam protection for Contact Form 7 using a honeypot, signed timing token, rate limiting, and a local adaptive blacklist.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/pe.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/241299","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pe.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/pe.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/pe.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=241299"}],"author":[{"embeddable":true,"href":"https:\/\/pe.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/riccardorosignoli"}],"wp:attachment":[{"href":"https:\/\/pe.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=241299"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/pe.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=241299"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/pe.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=241299"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/pe.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=241299"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/pe.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=241299"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/pe.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=241299"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}