{"id":352233,"date":"2026-08-14T11:27:48","date_gmt":"2026-08-14T11:27:48","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/lancedesk-form-guard\/"},"modified":"2026-08-26T14:38:14","modified_gmt":"2026-08-26T14:38:14","slug":"lancedesk-form-guard","status":"publish","type":"plugin","link":"https:\/\/bs.wordpress.org\/plugins\/lancedesk-form-guard\/","author":20992349,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"0.1.10","stable_tag":"0.1.10","tested":"7.1","requires":"6.4","requires_php":"8.0","requires_plugins":null,"header_name":"LanceDesk Form Guard","header_author":"Lance Desk","header_description":"Protects contact form submissions with local heuristics and optional AI classification before notification emails are sent.","assets_banners_color":"8fa5bc","last_updated":"2026-08-26 14:38:14","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/github.com\/lancedesk\/lancedesk-form-guard","header_author_uri":"https:\/\/lancedesk.com","rating":0,"author_block_rating":0,"active_installs":0,"downloads":325,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"0.1.1":{"tag":"0.1.1","author":"lancedesk","date":"2026-08-14 12:09:07"},"0.1.10":{"tag":"0.1.10","author":"lancedesk","date":"2026-08-26 14:38:14"},"0.1.2":{"tag":"0.1.2","author":"lancedesk","date":"2026-08-21 17:53:47"},"0.1.3":{"tag":"0.1.3","author":"lancedesk","date":"2026-08-23 13:54:39"},"0.1.4":{"tag":"0.1.4","author":"lancedesk","date":"2026-08-24 16:35:12"},"0.1.5":{"tag":"0.1.5","author":"lancedesk","date":"2026-08-24 16:54:15"},"0.1.6":{"tag":"0.1.6","author":"lancedesk","date":"2026-08-24 17:19:40"},"0.1.8":{"tag":"0.1.8","author":"lancedesk","date":"2026-08-25 20:55:49"}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3647245,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3647245,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3647245,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3647245,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["0.1.1","0.1.10","0.1.2","0.1.3","0.1.4","0.1.5","0.1.6","0.1.8"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3647304,"resolution":"1","location":"assets","locale":"","width":1280,"height":608},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3647304,"resolution":"2","location":"assets","locale":"","width":1280,"height":608},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3647304,"resolution":"3","location":"assets","locale":"","width":1280,"height":612},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3647304,"resolution":"4","location":"assets","locale":"","width":1280,"height":604},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3647304,"resolution":"5","location":"assets","locale":"","width":1280,"height":608},"screenshot-6.png":{"filename":"screenshot-6.png","revision":3647304,"resolution":"6","location":"assets","locale":"","width":1280,"height":609},"screenshot-7.png":{"filename":"screenshot-7.png","revision":3647304,"resolution":"7","location":"assets","locale":"","width":1280,"height":605}},"screenshots":{"1":"First-run setup checklist to get Form Guard protecting forms quickly.","2":"Integrations screen showing WordPress Core and supported form plugins.","3":"Forms list with per-form protection toggles.","4":"Protection rules: default action and Layer 1 heuristic controls.","5":"AI providers with encrypted API keys and connection testing.","6":"Security logs with verdict, layer, confidence, and reason.","7":"Log detail drawer with integration, layer, provider, confidence, reason, and captured fields."}},"plugin_section":[],"plugin_tags":[2353,109,601,600,599],"plugin_category":[42,54],"plugin_contributors":[231774],"plugin_business_model":[],"class_list":["post-352233","plugin","type-plugin","status-publish","hentry","plugin_tags-ai","plugin_tags-antispam","plugin_tags-forms","plugin_tags-security","plugin_tags-spam","plugin_category-contact-forms","plugin_category-security-and-spam-protection","plugin_contributors-lancedesk","plugin_committers-lancedesk"],"banners":{"banner":"https:\/\/ps.w.org\/lancedesk-form-guard\/assets\/banner-772x250.png?rev=3647245","banner_2x":"https:\/\/ps.w.org\/lancedesk-form-guard\/assets\/banner-1544x500.png?rev=3647245","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/lancedesk-form-guard\/assets\/icon-128x128.png?rev=3647245","icon_2x":"https:\/\/ps.w.org\/lancedesk-form-guard\/assets\/icon-256x256.png?rev=3647245","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/lancedesk-form-guard\/assets\/screenshot-1.png?rev=3647304","caption":"First-run setup checklist to get Form Guard protecting forms quickly."},{"src":"https:\/\/ps.w.org\/lancedesk-form-guard\/assets\/screenshot-2.png?rev=3647304","caption":"Integrations screen showing WordPress Core and supported form plugins."},{"src":"https:\/\/ps.w.org\/lancedesk-form-guard\/assets\/screenshot-3.png?rev=3647304","caption":"Forms list with per-form protection toggles."},{"src":"https:\/\/ps.w.org\/lancedesk-form-guard\/assets\/screenshot-4.png?rev=3647304","caption":"Protection rules: default action and Layer 1 heuristic controls."},{"src":"https:\/\/ps.w.org\/lancedesk-form-guard\/assets\/screenshot-5.png?rev=3647304","caption":"AI providers with encrypted API keys and connection testing."},{"src":"https:\/\/ps.w.org\/lancedesk-form-guard\/assets\/screenshot-6.png?rev=3647304","caption":"Security logs with verdict, layer, confidence, and reason."},{"src":"https:\/\/ps.w.org\/lancedesk-form-guard\/assets\/screenshot-7.png?rev=3647304","caption":"Log detail drawer with integration, layer, provider, confidence, reason, and captured fields."}],"raw_content":"<!--section=description-->\n<p>LanceDesk Form Guard protects contact forms and WordPress post comments from spam using a two-layer defense system:<\/p>\n\n<ul>\n<li><strong>Layer 1 \u2014 Heuristics:<\/strong> Fast deterministic checks for BBCode injection, link stuffing, suspicious image\/shortener hosts, commercial\/SEO cold outreach (including polite sales pitches), honeypot fields, and too-fast submissions.<\/li>\n<li><strong>Layer 2 \u2014 AI Analysis:<\/strong> Optional semantic spam classification via Groq, OpenAI, or Anthropic (off by default; requires privacy acknowledgment and your API keys).<\/li>\n<\/ul>\n\n<p><strong>Supported integrations<\/strong><\/p>\n\n<ul>\n<li>WPForms, Contact Form 7, Gravity Forms, Quform, and Ninja Forms (per-form toggles)<\/li>\n<li><strong>WordPress Core<\/strong> \u2014 native post comment forms (site-wide toggle under Settings)<\/li>\n<\/ul>\n\n<p>Blocked submissions are logged with hashed IP and email values. Legitimate submissions flow normally.<\/p>\n\n<h3>External services<\/h3>\n\n<p>This plugin optionally connects to third-party AI APIs to classify form submissions for spam. No submission text is sent until AI analysis is enabled, the privacy acknowledgment is checked in Settings, and at least one provider is enabled with an API key.<\/p>\n\n<p><strong>Groq<\/strong> \u2014 https:\/\/groq.com\/\n* Used for: Optional Layer 2 spam classification of form submissions.\n* Data sent: Truncated form submission text (not stored passwords or payment data collected by this plugin).\n* When: AI analysis is enabled, privacy is acknowledged, heuristics pass or the submission is ambiguous, and Groq is selected\/enabled with a valid API key.\n* Terms of Service: https:\/\/groq.com\/terms-of-use\/\n* Privacy Policy: https:\/\/groq.com\/privacy-policy\/<\/p>\n\n<p><strong>OpenAI<\/strong> \u2014 https:\/\/openai.com\/\n* Used for: Optional Layer 2 spam classification of form submissions.\n* Data sent: Truncated form submission text.\n* When: AI analysis is enabled, privacy is acknowledged, and OpenAI is reached in the provider fallback order with a valid API key.\n* Terms of Service: https:\/\/openai.com\/policies\/terms-of-use\/\n* Privacy Policy: https:\/\/openai.com\/policies\/privacy-policy\/<\/p>\n\n<p><strong>Anthropic<\/strong> \u2014 https:\/\/www.anthropic.com\/\n* Used for: Optional Layer 2 spam classification of form submissions.\n* Data sent: Truncated form submission text.\n* When: AI analysis is enabled, privacy is acknowledged, and Anthropic is reached in the provider fallback order with a valid API key.\n* Terms of Service: https:\/\/www.anthropic.com\/legal\/consumer-terms\n* Privacy Policy: https:\/\/www.anthropic.com\/legal\/privacy<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>lancedesk-form-guard<\/code> folder to <code>\/wp-content\/plugins\/<\/code><\/li>\n<li>Activate the plugin through the <strong>Plugins<\/strong> screen in WordPress<\/li>\n<li>Open <strong>Form Guard<\/strong> in the admin menu and complete the setup checklist<\/li>\n<li>Enable protection on individual forms (or turn on <strong>Protect WordPress comment forms<\/strong> in Settings)<\/li>\n<li>Optionally configure an AI provider under <strong>Protection<\/strong> and <strong>AI Providers<\/strong><\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"which%20form%20plugins%20are%20supported%3F\"><h3>Which form plugins are supported?<\/h3><\/dt>\n<dd><p>WPForms, Contact Form 7, Gravity Forms, Quform, and Ninja Forms when installed and active. Native WordPress post comment forms are supported without any third-party plugin \u2014 enable <strong>Protect WordPress comment forms<\/strong> under <strong>Form Guard \u2192 Settings<\/strong>.<\/p><\/dd>\n<dt id=\"are%20wordpress%20comments%20protected%3F\"><h3>Are WordPress comments protected?<\/h3><\/dt>\n<dd><p>Yes. When the master switch is on and <strong>Protect WordPress comment forms<\/strong> is enabled, comments run through the same Layer 1 heuristics (and optional Layer 2 AI) as contact forms. <strong>Blocked comments are not saved to WordPress<\/strong> \u2014 they exist only in Form Guard logs. The visitor is redirected back to the post (silent discard) or shown a generic error (soft fail), depending on your Protection default action.<\/p><\/dd>\n<dt id=\"what%20happens%20if%20the%20ai%20provider%20is%20unavailable%3F\"><h3>What happens if the AI provider is unavailable?<\/h3><\/dt>\n<dd><p>You can configure fail-open (allow submission when heuristics pass) or fail-closed behavior in Protection Rules.<\/p><\/dd>\n<dt id=\"is%20submission%20data%20sent%20to%20third%20parties%3F\"><h3>Is submission data sent to third parties?<\/h3><\/dt>\n<dd><p>When Layer 2 AI analysis is enabled <strong>and<\/strong> you have acknowledged the privacy notice <strong>and<\/strong> configured a provider with an API key, truncated form field text may be sent to that provider for spam classification. Heuristics-only protection stays on your site. See <strong>External services<\/strong> below.<\/p><\/dd>\n<dt id=\"does%20this%20plugin%20use%20the%20wordpress%20ai%20client%3F\"><h3>Does this plugin use the WordPress AI Client?<\/h3><\/dt>\n<dd><p>Not in this release. Form Guard uses site-owner API keys with a multi-provider fallback (Groq, OpenAI, Anthropic) so spam classification works on WordPress 6.4+ without requiring core AI Client setup. We may evaluate WordPress AI Client integration in a future release.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>0.1.10<\/h4>\n\n<ul>\n<li>Layer 1 commercial outreach expanded into full vendor\/agency solicitation detection: contact-card CTAs, sales mailboxes + URLs, ecommerce\/dev service pitches, and brand\/domain glue \u2014 blocks submissions even when Quform honeypot is empty.<\/li>\n<\/ul>\n\n<h4>0.1.9<\/h4>\n\n<ul>\n<li>Quform: treat Quform\u2019s built-in honeypot as spam when filled (block + log before Quform validation).<\/li>\n<li>Layer 1: Random \/ Gibberish Content rule for bot keyboard fills and dotted obfuscated emails.<\/li>\n<li>Quform logs: strip CSRF\/uid\/ajax\/loaded meta keys from Captured Fields.<\/li>\n<\/ul>\n\n<h4>0.1.8<\/h4>\n\n<ul>\n<li>Settings and Protection: Save buttons stay disabled until a setting actually changes.<\/li>\n<\/ul>\n\n<h4>0.1.7<\/h4>\n\n<ul>\n<li>Quform: show the real form name in Security Logs (e.g. \u201cContact Us\u201d) instead of the numeric id.<\/li>\n<li>Quform: merge form values with flattened POST so message bodies are always scored (fixes soft SEO pitches being Allowed while still saving Quform entries).<\/li>\n<li>Quform: block responses short-circuit correctly so silent discard does not create entries.<\/li>\n<\/ul>\n\n<h4>0.1.6<\/h4>\n\n<ul>\n<li>Safer default: plugin data (settings, keys, logs) is kept on uninstall unless \u201cDelete all plugin data on uninstall\u201d is turned on.<\/li>\n<\/ul>\n\n<h4>0.1.5<\/h4>\n\n<ul>\n<li>Admin UX: hide Logs search and Forms filter\/search when there are fewer than 20 items.<\/li>\n<li>Integrations intro text uses full content width.<\/li>\n<li>Providers: Save Key stays disabled until an API key is entered.<\/li>\n<\/ul>\n\n<h4>0.1.4<\/h4>\n\n<ul>\n<li>Layer 1 catches soft content-collaboration and link-opportunity outreach (e.g. \u201ccame across your website\u201d, \u201clink opportunities\u201d, \u201cboth audiences\u201d).<\/li>\n<li>Layer 1 corpus hardening: soft SEO proposals, backlink swaps, Xrumer\/GSA hosts, token scams, Russian tehosmotr\/darknet\/gambling SEO spam, product dump pitches.<\/li>\n<li>Settings toggles for delete-on-uninstall and AI privacy acknowledgment match the master switch style.<\/li>\n<\/ul>\n\n<h4>0.1.3<\/h4>\n\n<ul>\n<li><strong>WordPress Core comment protection<\/strong> \u2014 honeypot\/timestamp on comment forms; toggle under Settings \u2192 WordPress Core; Integrations card.<\/li>\n<li><strong>Blocked comments never reach wp_comments<\/strong> \u2014 discarded before save (fixes auto-approve for logged-in moderators); log-only record in Form Guard.<\/li>\n<li><strong>Layer 1 tightening<\/strong> \u2014 commercial outreach threshold lowered; catches polite SEO\/sales pitches (e.g. \u201cquick call\u201d, \u201cgrow your business online\u201d) without AI.<\/li>\n<li><strong>Security logs UX<\/strong> \u2014 per-user read\/unread state, unread badge on Logs nav, improved table layout and layer labels.<\/li>\n<li><strong>Plugin Check<\/strong> \u2014 i18n translators, Tested up to 7.1, PHPCS suppressions for false positives.<\/li>\n<\/ul>\n\n<h4>0.1.2<\/h4>\n\n<ul>\n<li>Stronger Layer 1 heuristics when AI is off: max 2 links, suspicious image\/shortener hosts, commercial\/SEO outreach patterns, and handle dumps.<\/li>\n<\/ul>\n\n<h4>0.1.1<\/h4>\n\n<ul>\n<li>Log detail drawer shows integration, layer, provider, action, confidence, reason, and captured fields.<\/li>\n<li>AI outbound calls require privacy acknowledgment; AI analysis defaults off.<\/li>\n<li>Improved external services documentation in the readme.<\/li>\n<\/ul>\n\n<h4>0.1.0<\/h4>\n\n<ul>\n<li>Initial release.<\/li>\n<\/ul>","raw_excerpt":"Block contact form and comment spam with local heuristics and optional AI before emails send or comments publish.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/bs.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/352233","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/bs.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/bs.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/bs.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=352233"}],"author":[{"embeddable":true,"href":"https:\/\/bs.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/lancedesk"}],"wp:attachment":[{"href":"https:\/\/bs.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=352233"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/bs.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=352233"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/bs.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=352233"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/bs.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=352233"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/bs.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=352233"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/bs.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=352233"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}