{"id":260843,"date":"2025-11-16T20:01:27","date_gmt":"2025-11-16T20:01:27","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/basic-honeypot-for-contact-form-7\/"},"modified":"2026-07-20T18:24:08","modified_gmt":"2026-07-20T18:24:08","slug":"apiosys-honeypot-cf7","status":"publish","type":"plugin","link":"https:\/\/he.wordpress.org\/plugins\/apiosys-honeypot-cf7\/","author":15701295,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.3","stable_tag":"1.0.3","tested":"7.0.2","requires":"6.5","requires_php":"7.2","requires_plugins":null,"header_name":"Apio systems - Honeypot for Contact Form 7","header_author":"Joris Le Blansch","header_description":"Basic Honeypot plugin for Contact Form 7 to drastically reduce spam on form submissions without user interaction. Includes honeypot field, time-based validation, and content analysis. Store results in Flamingo.","assets_banners_color":"7c8d8d","last_updated":"2026-07-20 18:24:08","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/apio.systems","header_author_uri":"https:\/\/www.apio.systems","rating":0,"author_block_rating":0,"active_installs":90,"downloads":792,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","changelog"],"tags":{"0.9.3":{"tag":"0.9.3","author":"apiosys","date":"2025-11-28 08:05:10"},"0.9.4":{"tag":"0.9.4","author":"apiosys","date":"2026-04-23 08:23:04"},"1.0.2":{"tag":"1.0.2","author":"apiosys","date":"2026-07-20 17:38:41"},"1.0.3":{"tag":"1.0.3","author":"apiosys","date":"2026-07-20 18:24:08"}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.jpg":{"filename":"icon-128x128.jpg","revision":3487501,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-128x128.png":{"filename":"icon-128x128.png","revision":3487501,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.jpg":{"filename":"icon-256x256.jpg","revision":3487501,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3487501,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.jpg":{"filename":"banner-1544x500.jpg","revision":3487506,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.jpg":{"filename":"banner-772x250.jpg","revision":3487506,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["0.9.3","0.9.4","1.0.2","1.0.3"],"block_files":[],"assets_screenshots":{"screenshot-4.png":{"filename":"screenshot-4.png","revision":3615830,"resolution":"4","location":"plugin","width":500,"height":498},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3615830,"resolution":"2","location":"plugin","width":500,"height":498},"screenshot-1.png":{"filename":"screenshot-1.png","revision":3615830,"resolution":"1","location":"plugin","width":500,"height":498},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3615830,"resolution":"3","location":"plugin","width":500,"height":498}},"screenshots":{"1":"Spam caught when Honeypot field was filled.","2":"Spam caught when the form was submitted too quickly.","3":"Spam caught when too many URLs are present in the message fields.","4":"Spam caught when certain keywords are detected."}},"plugin_section":[],"plugin_tags":[109,601,598],"plugin_category":[42,54],"plugin_contributors":[250763],"plugin_business_model":[],"class_list":["post-260843","plugin","type-plugin","status-publish","hentry","plugin_tags-antispam","plugin_tags-forms","plugin_tags-honeypot","plugin_category-contact-forms","plugin_category-security-and-spam-protection","plugin_contributors-apiosys","plugin_committers-apiosys"],"banners":{"banner":"https:\/\/ps.w.org\/apiosys-honeypot-cf7\/assets\/banner-772x250.jpg?rev=3487506","banner_2x":"https:\/\/ps.w.org\/apiosys-honeypot-cf7\/assets\/banner-1544x500.jpg?rev=3487506","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/apiosys-honeypot-cf7\/assets\/icon-128x128.png?rev=3487501","icon_2x":"https:\/\/ps.w.org\/apiosys-honeypot-cf7\/assets\/icon-256x256.png?rev=3487501","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/apiosys-honeypot-cf7\/trunk\/screenshot-1.png?rev=3615830","caption":"Spam caught when Honeypot field was filled."},{"src":"https:\/\/ps.w.org\/apiosys-honeypot-cf7\/trunk\/screenshot-2.png?rev=3615830","caption":"Spam caught when the form was submitted too quickly."},{"src":"https:\/\/ps.w.org\/apiosys-honeypot-cf7\/trunk\/screenshot-3.png?rev=3615830","caption":"Spam caught when too many URLs are present in the message fields."},{"src":"https:\/\/ps.w.org\/apiosys-honeypot-cf7\/trunk\/screenshot-4.png?rev=3615830","caption":"Spam caught when certain keywords are detected."}],"raw_content":"<!--section=description-->\n<p>I like to use Contact Form 7 on most of my WordPress sites. It's a powerful form manager that suits all my needs. I don't like to use external calls to protect the forms from spam submissions though (like reCaptcha or hCaptcha) and don't want to present a manual captcha to a user (math or other puzzle). Since I couldn't find a really basic honeypot script that works on most entries, I created one here. Hopefully it's useful to someone else also.<\/p>\n\n<h3>Setup<\/h3>\n\n<ul>\n<li>Install the plugin using the regular plugin setup routine or upload the entire apiosys-honeypot-cf7 folder to the \/wp-content\/plugins\/ directory.<\/li>\n<li>Activate the plugin through the \"Plugins\" menu in WordPress, you MUST have Contact Form 7 AND Flamingo installed and enabled.<\/li>\n<li>Add the following shortcodes to your Contact Form 7 forms:<\/li>\n<\/ul>\n\n<p>[honeypot] - Adds the hidden honeypot field\n[timestamp] - Adds time-based validation<\/p>\n\n<ul>\n<li>Complete the rest of the options which you can find in Admin &gt; Contact &gt; Honeypot. A generally good working set of values is enabled by default there.<\/li>\n<\/ul>\n\n<h3>What tests are used?<\/h3>\n\n<ul>\n<li>A Honeypot Field<\/li>\n<li>A Checkbox Trap<\/li>\n<li>Time-Based Validation<\/li>\n<li>Email domain Check<\/li>\n<li>Content Analysis (across all form fields, not just the message)<\/li>\n<li>Weak-Signal Scoring (combines many small clues to catch \"human-looking\" spam)<\/li>\n<\/ul>\n\n<h3>Does it really work?<\/h3>\n\n<p>It has been tested on several high-traffic WP sites. I see a return of ~ 1 \u2030 (i.e. 1 in a thousand) of spam going through. That usually corresponds to humans paid to fill forms or sophisticated bots. Please feel free to contribute to make it even better. You can contribute directly <a href=\"https:\/\/github.com\/apio-sys\/apiosys-honeypot-cf7\">here<\/a>.<\/p>\n\n<!--section=installation-->\n<ul>\n<li>Install the plugin using the regular plugin setup routine or upload the entire apiosys-honeypot-cf7 folder to the \/wp-content\/plugins\/ directory.<\/li>\n<li>Activate the plugin through the \"Plugins\" menu in WordPress, you MUST have Contact Form 7 AND Flamingo installed and enabled.<\/li>\n<li>Add the following shortcodes to your Contact Form 7 forms:<\/li>\n<\/ul>\n\n<p>[honeypot] - Adds the hidden honeypot field\n[timestamp] - Adds time-based validation<\/p>\n\n<ul>\n<li>Complete the rest of the options which you can find in Admin &gt; Contact &gt; Honeypot. A generally good working set of values is enabled by default there.<\/li>\n<\/ul>\n\n<!--section=changelog-->\n<h4>1.0.3 - 2026-07-20<\/h4>\n\n<ul>\n<li>FIX: Removed a redundant <code>@version<\/code> docblock tag from the main plugin file that had drifted out of sync with the <code>Version:<\/code> header. The mismatch could stop some WordPress installs from recognizing the update; the <code>Version:<\/code> header is now the single source of truth.<\/li>\n<li>FIX: Sanitize the company-name POST value before comparison so no non-sanitized input is read (resolves a Plugin Check \/ WPCS ValidatedSanitizedInput warning). No behavior change.<\/li>\n<\/ul>\n\n<h4>1.0.2 - 2026-07-20<\/h4>\n\n<ul>\n<li>FEAT: New \"Company Name + Free Email\" scoring signal - adds a point when a company\/organization name is filled in but a free\/personal email (gmail, hotmail...) is used. Catches human-looking spam that claims a corporate identity while writing from a throwaway mailbox. Off by default; recommended for business (B2B) forms.<\/li>\n<li>FEAT: New opt-in \"Work Email Requirement\" - a friendly Contact Form 7 validation message that asks the visitor for a work address when they provide a company name but a free\/personal email, instead of silently accepting the submission. Message is customizable.<\/li>\n<li>FEAT: Company\/organization field names are now configurable (used by both features above).<\/li>\n<\/ul>\n\n<h4>1.0.1 - 2026-07-14<\/h4>\n\n<ul>\n<li>CHANGE: Widened the \"short message\" scoring signal from under 6 words to under 15 words (still a single weak point). Catches content-free one-liners (\"I agree\", \"write about your prices\") from JS-executing bots that leave the honeypot empty, while staying well clear of genuine inquiries, which run to dozens of words.<\/li>\n<\/ul>\n\n<h4>1.0.0 - 2026-07-12<\/h4>\n\n<ul>\n<li>FEAT: Weak-signal spam scoring - combines many small clues (links, free\/disposable email, gmail alias tricks, random digits in email, very short messages, \"Name &amp; Name\" company patterns, missing JavaScript) with a configurable threshold to catch human-looking spam that passes every individual check.<\/li>\n<li>FEAT: Content analysis now scans additional fields (name, company, job title, subject...), not only the message.<\/li>\n<li>FEAT: Keyword matching normalizes hyphens, punctuation and accents, so \"no-obligation\" matches \"no obligation\".<\/li>\n<li>FEAT: Detects whitespace \/ blank-line flooding used to hide spam.<\/li>\n<li>FEAT: URL detection now also counts www. and bare-domain links; optional \"disallow any link in message\" toggle.<\/li>\n<li>CHANGE: Merged the separate \"spam keywords\" and \"spam phrases\" lists into a single list (existing settings are migrated automatically).<\/li>\n<li>First mature release after months of testing on live data.<\/li>\n<\/ul>\n\n<h4>0.9.4 - 2025-12-04<\/h4>\n\n<ul>\n<li>FEAT: Added checkbox trap.<\/li>\n<li>FEAT: Improved field hiding.<\/li>\n<li>FEAT: Email domain TLD check.<\/li>\n<li>FEAT: Updated default spam keywords list.<\/li>\n<li>FEAT: Separate list with spam phrases.<\/li>\n<li>FEAT: Obfuscated timestamp.<\/li>\n<\/ul>\n\n<h4>0.9.3 - 2025-11-16<\/h4>\n\n<ul>\n<li>FIX: CSS resource version.<\/li>\n<\/ul>\n\n<h4>0.9.2 - 2025-11-14<\/h4>\n\n<ul>\n<li>First production release.<\/li>\n<\/ul>","raw_excerpt":"Basic Honeypot plugin for Contact Form 7 to drastically reduce spam on form submissions without user interaction.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/he.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/260843","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/he.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/he.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/he.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=260843"}],"author":[{"embeddable":true,"href":"https:\/\/he.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/apiosys"}],"wp:attachment":[{"href":"https:\/\/he.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=260843"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/he.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=260843"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/he.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=260843"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/he.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=260843"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/he.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=260843"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/he.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=260843"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}