Onsite Spam Guard
by jeromewincek 1 (0 reviews)

Onsite Spam Guard

Config-driven spam protection for comments, WooCommerce reviews, Jetpack forms, and WP Job Manager submissions — no external services or CAPTCHAs.

Onsite Spam Guard ranks #63,321 among WordPress.org plugins with 1+ active installations, is #2,183 of 2,897 in the Discussion & Community category, a 1/5 rating from 0 reviews, and was last updated Sep 15, 2026. Data from WordPress.org, refreshed twice daily — see methodology.

Compatible with WP 7.1
v1.5.0 Current Version v1.5.0
Updated 1 week ago Last Update on 15 Sep, 2026
Refreshed 7 hours ago Last Refreshed on
#2,183 of 2,897 in Discussion & Community Downloads -45.1% this week Actively maintained
View on WordPress.org
Rank
#63,321
No change
Active Installs
1+
No change
KW Avg Position
100
24 better
Downloads
350
+8 today
Support Resolved
0%
No change
Rating
20%
Review 1 out of 5
1 (0 reviews)

Next Milestone 10

Total Progress 10%
0+ 10+
62,375
Ranks to Climb
-
Growth Needed
8,000,000
Active Installs
Pro

Unlock Exact Install Count

See the precise estimated active installs for this plugin, calculated from real-time ranking data.

  • Exact install estimates within tiers
  • Track install growth over time
  • Milestone progress predictions
Upgrade to Pro
Need 9 more installs to reach 10+

Rank Changes

57,864 60,514 63,164 65,814 68,464 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026 23-09-2026
44,083 50,628 57,173 63,717 70,262 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026 23-09-2026
Current #63,321
Change
Best #

Upgrade to Pro

Unlock 30-day and 90-day rank history charts with a Pro subscription.

Upgrade Now

Active Installs Growth

Active Installs 0,000,000+
Growth +0.0%
Peak 0,000,000

Downloads Growth

0 10 20 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026 23-09-2026
0 10 20 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026 20-09-2026 21-09-2026 22-09-2026 23-09-2026
Downloads
Growth
Peak

Upgrade to Pro

Unlock 30-day, 90-day, and yearly download history charts with a Pro subscription.

Upgrade Now

Reviews & Ratings

1.0
0 reviews
Overall 20%
5
0 (0%)
4
0 (0%)
3
0 (0%)
2
0 (0%)
1
0 (0%)

Frequently Asked Questions

Common questions about Onsite Spam Guard

No. Every check runs on your own server. Nothing about a submission is sent anywhere outside your site.
No. All protection is invisible. The honeypot field is hidden, and the timing and behavioral checks happen in the background.
When a submission is blocked (and logging is enabled), the plugin records the guard that blocked it, the form context, the reason, a short excerpt of the content, the visitor IP address, and the browser user-agent. Entries older than the retention window (default 30 days, configurable; set to 0 to keep them indefinitely) are pruned automatically. The plugin also registers suggested privacy-policy text you can add to your site's policy. I'm behind Cloudflare or a load balancer and the wrong IP is logged. By default the plugin uses the direct connection IP, because forwarded headers can be spoofed to bypass the allowlist. If your site sits behind a trusted reverse proxy, enable Trust proxy headers for IP detection under Spam Guard → Settings → Allowlist.
By default a blocked comment or review is placed in the spam queue (Comments → Spam) rather than being rejected outright, so you can restore a false positive with one click — nothing is lost. Open Spam Guard → Spam Logs to see which guard blocked it and why, then loosen that guard on the settings page — for example, raise the link limit, lower the behavioral threshold, or add the sender to the allowlist. If you would rather reject blocked comments with an error message, enable that option under Spam Guard → Settings → General.
Yes. Enable Rate limit on the Guards tab, then set the maximum number of submissions and the window they are counted over — 20 per hour and 5 per minute are both expressible. It counts per sender — the logged-in user where there is one, otherwise the connection IP — and each form type is counted separately. It is off by default, because on sites where many visitors share an address (an office, a school, or mobile carrier NAT) an IP-based limit can catch people who are not doing anything wrong. Set the maximum to 0 to disable it without turning the guard off.
Yes. Every Contact Form 7 form on the site is protected the moment the plugin is active, and a Contact Form 7 forms switch appears under Protection targets on the General tab. There is nothing to add to your forms. You do not place a tag in each form, and there is no per-form setup — forms you build later are covered the same way, with no step to forget. What runs is the full set of guards rather than a single trick: a hidden field bots fill in, a check that the form was not submitted faster than a person could type, a signature proving the submission came from your site, duplicate detection, an optional rate limit, and your own keyword and link rules. A bot written to step around any one of those still has to get past the rest. A blocked submission is marked as spam, so the visitor sees the message you configured for spam on that form, and the reason is recorded in Contact Form 7's own spam log next to the plugin name. Because Contact Form 7 lets you name fields whatever you like, nothing here matches on field names. It reads the types you built the form from: the message and text fields are screened for content — including the subject line, which spam often targets — and the email field is used as the sender's address. A field holding nothing but a web address is not counted as a link, whether you built it with a URL field or a plain text one, so asking visitors for their website cannot trip the link limit just by being filled in correctly. Links written among your visitor's words still count, which is what spam actually looks like.
Yes. When WP Job Manager is active the frontend job submission form is protected automatically — including the "save as draft" path — and a WP Job Manager job submissions switch appears under Protection targets on the General tab. WP Job Manager's own answer to submission spam is Google reCAPTCHA; this gives you the same protection without the third-party service or the puzzle your posters have to solve. Job listings run longer than comments and legitimately carry more links, so the form gets its own section on the Per-form tab. Two thresholds are worth setting there, and the first is worth doing before you take your first listing: raise the link limit — the default of 3 suits a comment, while an ordinary job description linking to an about page, a benefits page, a team page and an application page already has four. Then raise the minimum submit time well above the site-wide default — nobody writes a job description in three seconds, so a longer minimum costs genuine posters nothing and stops scripted submissions. The company website, video and Twitter fields are never counted as content links, so filling them in normally cannot trip the limit.
No — it complements it. Onsite Spam Guard's guards run before WordPress's own comment checks, and those built-ins still run underneath: the duplicate-comment check, the comment flood throttle, the Disallowed Comment Keys blocklist, and the "hold a comment with this many links" setting (all under Settings → Discussion). Its Keyword, Link limit, and Duplicate guards overlap those, so you can rely on either or both. What it adds on top is the honeypot, timing, signature, and behavioral checks core has no equivalent for, one settings screen with logging, and protection for WooCommerce reviews and Jetpack contact forms — not just comments. You can also go the other way and put WordPress's list to work everywhere: enable Also apply WordPress's Disallowed Comment Keys on the Guards tab and the plugin runs every protected submission through core's own blocklist — so the list you already maintain under Settings → Discussion starts covering reviews, Jetpack forms, and any form added through the plugin's API, not only comments.
Yes. The timing and authenticity checks use a token whose signature does not expire (unlike a WordPress nonce, which would go stale on a cached page and block legitimate visitors), so full-page caching does not produce false positives.
By default, yes — deleting the plugin (not just deactivating it) drops its database table, removes all of its options, clears its scheduled task, and purges its transients, on every site of a multisite network. If you would rather keep your settings and logs (for example, before reinstalling), turn off Delete all plugin data when this plugin is deleted under Spam Guard → Settings → Logging first.

Sign In / Register

You need to sign in or register to use this feature.