

Settings at a glance: protection status strip, topic tabs and short explanations with built-in help for every option
Spam protection your visitors never see. No image grids, no “I’m not a robot” checkbox, no puzzles, nothing to click. Your visitors just hit Send — while their browser silently solves a tiny cryptographic challenge (proof-of-work) in a few milliseconds. Real humans never notice. Mass-spam bots either fail the challenge or have to burn so much computing power per message that spamming your site stops being worth it.
Every form, out of the box. WordPress logins, registrations and comments, WooCommerce checkout and reviews, and virtually every form plugin — Contact Form 7, Elementor Pro Forms, WPForms, Gravity Forms, Ninja Forms, Fluent Forms, Formidable and dozens more (full list below). One plugin protects all of them, and the most popular builders are detected and configured automatically on activation.
Most anti-spam tools protect only the form plugins they ship an integration for. If your builder is not on their list — or you use a hand-coded form, a theme’s built-in form, or three different builders on one site — you are on your own.
This plugin works differently: it recognizes submissions by their signature — the characteristic fields and actions of the request itself — instead of hooking into specific form plugins. That is why it covers any form:
And because no integration code is involved, nothing breaks when your form builder updates.
In practice that solves two everyday problems:
Every CAPTCHA interaction costs you real visitors: an extra click here, an unreadable image there, “select all traffic lights” on a phone screen — and the contact request or sale is gone. This plugin flips the deal: instead of making humans prove themselves, it makes the device pay. The visitor’s browser proves it is a real, JavaScript-running client by doing a moment of invisible computation. Zero friction for people, real costs for bots.
Everything runs on your own web server — there is no external service in the loop. That is not just a privacy nicety, it is an operational one:
And they all share one structural limit: they protect the forms they ship an integration for. This plugin protects the forms you actually have (see “Truly universal” above).
Pre-configured out of the box — as soon as the plugin is active, these are recognized automatically, no setup:
WordPress: Login, Password Reset, Comments
WooCommerce: Cart, Checkout, Login, Password Reset, Product Reviews
Form and page builders: Contact Form 7, WPForms, Elementor Pro Forms, Ninja Forms, Fluent Forms, Forminator, Gravity Forms, Formidable Forms, Everest Forms, WS Form, SureForms, MetForm, JetFormBuilder, Otter Blocks, Spectra, Kadence Blocks, Essential Blocks, Divi Forms, MW WP Form, Jetpack Forms, Mailchimp for WordPress, MailPoet, WP User Frontend, wpDiscuz, bbPress (topics & replies), Thrive Architect, Thrive Leads, Thrive Apprentice, Thrive Quiz Builder, Thrive Comments, UserFeedback, Popup Maker (subscription form), YITH WooCommerce Wishlist, Newsletter (subscription forms), CoBlocks, Popup Builder
Added in under a minute, without code — switch on direct analysis mode, submit the form once, click save: registration forms (WordPress and WooCommerce), Ultimate Member, BuddyPress, BuddyForms, MemberPress, Paid Memberships Pro, WP-Members, Easy Digital Downloads, CheckoutWC & Flux Checkout, Quform, NEX-Forms, Bit Form, Form Maker, Funnelforms, Mailjet, SiteOrigin Page Builder, Calculated Fields Form, weForms, Responsive Contact Form Builder, Smart Forms, Kali Forms, Happyforms, ApplyOnline, FormCraft, CRM Perks Forms, Tripetto, Easy Form Builder, SimpleForm — and any hand-coded or custom form.
One honest limit: a form that is hosted elsewhere and only embedded on your page (Typeform, Jotform, Zoho Forms, HubSpot, OptinMonster and the like) sends its data straight to that service. The submission never reaches WordPress, so no WordPress plugin — this one included — can check it.