BLACK FRIDAY
Save 59% on PageForge Annual $191/year $485/year
Claim 59% Off →
SpamAnvil – AI Anti-Spam & Comment Spam Protection icon
Actively maintained Tested with WP 7.1

SpamAnvil – AI Anti-Spam & Comment Spam Protection

Free AI anti-spam & Akismet alternative. Uses ChatGPT, Claude, Gemini & other LLMs to block comment spam that traditional filters miss.

Active installs30+10+ tier
Downloads · 30d927▲ +25.4% vs prev. 30d
Rating5/51 reviews
Health score74/100Good
All-time downloads2.8KSince Feb 2026
Support resolved—No recent threads
RequiresWP 5.8PHP 7.4+
Downloads · 7d353▲ +47.7% week over week
Our verdict

Solid choice

SpamAnvil is a solid plugin choice in 2026, with a few things worth checking first. It runs on 30+ sites, is rated 5/5 and was last updated 2 days ago, and scores 74/100 on our health check.

  • Actively developed — last update 2 days ago
  • Tested with the latest WordPress (7.1)
  • Momentum — downloads up 25.4% vs the previous 30 days
  • Small user base (30+ active installs)
  • Very few reviews so far

How does it stack up?

Side-by-side on installs, updates, ratings & support

Daily downloads

244974Jul 1Aug 14Sep 28
Yesterday80
Daily average (1y)12
Peak day99Jul 15, 2026
Last 12 months2.8K

Download spikes usually follow a new release — each site that auto-updates counts as a download.

Rankings

Where SpamAnvil stands today

WordPress.org search rankings

Live position in the plugin search, top 100
KeywordPositionCompeting pluginsCategory
AI >100 6,484 Best AI plugins →
antispam #47 216 Best antispam plugins →
comment spam #49 1,576 Best comment spam plugins →
moderation >100 743 Best moderation plugins →
spam protection #55 1,510 Best spam protection plugins →

Version adoption

Share of active sites per release.

  • 1.1850.0%
  • 1.2050.0%

Rating breakdown

★★★★★★★★★★ 5 from 1 reviews

  • 5★100.0%
  • 4★0.00%
  • 3★0.00%
  • 2★0.00%
  • 1★0.00%

About SpamAnvil

From the official readme · v1.20.1

Description

SpamAnvil is a free, open-source WordPress anti-spam plugin — and a genuine Akismet alternative — that uses artificial intelligence to block comment spam. Unlike Akismet (which requires a paid plan for commercial sites) or simple keyword-based filters, SpamAnvil leverages large language models (LLMs) to actually understand your comments and detect even the most sophisticated spam. It layers a honeypot, a time trap and per-IP rate limiting in front of the AI, so obvious bots are blocked for free.

Traditional spam filters rely on static word lists and link counting. Spammers have evolved. SpamAnvil fights back with AI that understands context, intent, and language patterns – catching spam that looks legitimate and approving real comments that others would flag.

Why SpamAnvil?

  • Set up in about a minute – Activation opens a wizard that asks for one API key and verifies it before saving. Nothing is stored unless the test passes.
  • 100% Free – No premium tier, no subscription, no hidden costs. Bring your own API key (free options available).
  • Smarter Than Rules – AI understands context. A comment about “buying a new home” won’t be flagged just because it contains “buy”.
  • Defense in Depth – Honeypot, time trap, per-IP rate limit and heuristics block obvious bots for free, so the AI is only spent on the subtle cases.
  • Open Mode – Because the filtering is invisible and automatic, you can drop the usual barriers (name/email, login, moderation) and get more real comments – even anonymous ones – without opening the door to spam.
  • Works With Free AI Models – Use OpenRouter’s free models for $0 cost, or connect premium models for maximum accuracy.
  • Privacy-First – Your data stays between you and your chosen AI provider. IP addresses are stored as salted, keyed hashes (HMAC-SHA-256), not recoverable without your site’s secret. GDPR/LGPD compliant by design.
  • No Cloud Lock-in – Choose from 6+ AI providers. Switch anytime. Your anti-spam, your rules.

Supported AI Providers

  • OpenAI (GPT-4o-mini, GPT-4o, etc.)
  • Anthropic Claude (Claude Sonnet, Haiku, etc.)
  • Google Gemini (Gemini 2.0 Flash, Pro, etc.)
  • OpenRouter (100+ models, including FREE ones)
  • Featherless.ai (Open-source models)
  • Any OpenAI-compatible API (LM Studio, Ollama via proxy, vLLM, etc.)

A Swiss-Army-Knife of Defenses

SpamAnvil layers several spam defenses so cheap, invisible filters catch obvious bots for free and the AI only handles the subtle cases. Every layer is optional and runs before any paid API call:

  • Honeypot – A hidden field bots fill but humans never see. Instant, free block.
  • Time trap – Comments submitted faster than a human could type are flagged. Tamper-proof (signed) and fails open, so it never blocks a real visitor.
  • Per-IP rate limit – Throttles comment floods from a single IP before they even reach the database.
  • Heuristics engine – Regex/statistical pre-analysis (URLs, spam words, gambling/SEO author names, language mismatch, prompt-injection patterns) that auto-spams the obvious cases with no API call.
  • AI verdict – An LLM scores the rest 0-100 in context.

Key Features

  • AI-Powered Spam Detection – Each comment is analyzed by an LLM that scores it 0-100 for spam probability. Works with reasoning models (their thinking is parsed correctly).
  • Layered Bot Defense – Honeypot, time trap and per-IP rate limiting block obvious bots for free, before any AI call.
  • Model Picker – Browse and search each provider’s live model list right from the settings page (OpenAI, OpenRouter, Featherless). OpenRouter shows a “free” badge and context size.
  • “Open Mode” – One toggle removes WordPress comment friction (no required name/email, no login, no moderation hold) so leaving a real, even anonymous, comment is effortless. Comments appear instantly and spam is removed in the background.
  • Verdict Cache – Identical repeated spam reuses a recent AI verdict instead of calling the API again, cutting cost during floods.
  • Intelligent Heuristics Engine – Pre-analyzes comments to catch obvious spam without API calls.
  • Async Background Processing – Comments are queued and processed via WP-Cron so your site stays fast.
  • Smart IP Blocking – Automatically blocks repeat offenders with escalating ban durations (24h, 48h, 96h… capped at 30 days).
  • Automatic Retry with Backoff – Failed API calls retry with exponential delays; a real “Test Connection” verifies actual classification, not just the HTTP status.
  • Encrypted API Key Storage – Authenticated AES-256-GCM encryption, or wp-config.php constants for maximum security.
  • Statistics Dashboard & Logs – Track spam caught by each layer, API usage and errors, with the AI’s reasoning for every comment. An admin warning surfaces silent failures (no provider, or a backlog of failed items).
  • Customizable AI Prompts, Fallback Providers, Prompt-Injection Defense, Configurable Threshold, Moderator Bypass.

How It Works

  1. A visitor submits a comment.
  2. Rate limit – too many comments from this IP too fast? Throttled with an HTTP 429 (before anything is stored).
  3. IP block – is the IP already banned for repeat spam? Blocked.
  4. Form traps – was the hidden honeypot filled, or the comment submitted implausibly fast? Marked as spam instantly, no API call.
  5. Heuristics – a quick regex/statistical pre-analysis; obvious spam is auto-marked with no API call.
  6. Otherwise the comment is queued for AI analysis (or processed immediately in sync mode). Identical repeated content reuses a cached verdict.
  7. The AI analyzes the comment in context (post title, author info, heuristic data) and returns a spam score.
  8. Comments above your threshold are marked spam; clean comments are auto-approved. Repeat-offender IPs are escalated.

With Open Mode on, comments publish instantly and any spam is removed in the background instead of being held for moderation.

Use Cases

  • Blogs receiving hundreds of spam comments per day
  • WooCommerce stores where comment spam affects SEO and credibility
  • Membership sites that need to protect community discussions
  • Multilingual sites – AI understands comments in any language, unlike keyword-based filters
  • High-traffic sites – Async processing handles any volume without slowing down your site
  • Sites tired of Akismet – Free alternative with no cloud dependency and full data control

Security

SpamAnvil follows WordPress security best practices throughout:

  • Authenticated AES-256-GCM encrypted API key storage
  • wp-config.php constant support for API keys (never touch the database)
  • Configurable trusted IP header (default REMOTE_ADDR) so a forged X-Forwarded-For cannot bypass IP blocking or rate limiting
  • Nonce verification on all forms and AJAX requests
  • Capability checks on all admin actions
  • Prepared SQL statements on every database query
  • Output escaping on all rendered content
  • Prompt injection defense: boundary tags around the comment body AND commenter metadata, system prompt hardening, heuristic injection detection (body and author fields), strict JSON validation, deterministic settings

Languages

  • English (default)
  • Translation-ready (.pot file included)

Third-Party Services

SpamAnvil sends comment data (content, author name, email, and URL) to external AI services for spam analysis. The specific service used depends on your configuration. No data is sent until you configure and enable a provider.

When using the “Generic OpenAI-Compatible” option, data is sent to the URL you configure. You are responsible for ensuring compliance with the privacy policies of your chosen service.

Installation

Automatic Installation

  1. Go to Plugins > Add New in your WordPress admin
  2. Search for SpamAnvil
  3. Click Install Now and then Activate
  4. Activation opens the setup wizard – paste an API key and click Test and finish
  5. Done. Comments are analyzed from that moment on.

Manual Installation

  1. Download the plugin zip file
  2. Go to Plugins > Add New > Upload Plugin
  3. Upload the zip file and click Install Now
  4. Activate the plugin and follow the setup wizard

Getting a Free API Key

The setup wizard walks you through this, but in full:

  1. Create an account at OpenRouter.ai and generate an API key
  2. Paste it into the wizard, or into the OpenRouter card under Settings > SpamAnvil > Providers
  3. The default model setting is OpenRouter’s free router chain (openrouter/free, openrouter/auto), so free models are tried first

OpenRouter rate-limits free usage, which is plenty for a normal blog; a busy site can add credit to raise the limits.

Optional: Define API keys in wp-config.php

For maximum security, define API keys as constants in your wp-config.php:

define('SPAMANVIL_OPENAI_API_KEY', 'sk-...');
define('SPAMANVIL_OPENROUTER_API_KEY', 'sk-or-...');
define('SPAMANVIL_ANTHROPIC_API_KEY', 'sk-ant-...');
define('SPAMANVIL_GEMINI_API_KEY', '...');
define('SPAMANVIL_FEATHERLESS_API_KEY', '...');

When keys are defined in wp-config.php, they are never stored in the database at all.

Frequently asked questions

Is SpamAnvil really free?

Yes, 100% free and open source. There is no premium version. You only need an API key from an AI provider, and free options are available (e.g., OpenRouter with free Llama models).

How is SpamAnvil different from Akismet?

Akismet uses a centralized cloud service owned by Automattic. It requires a paid subscription for commercial sites, and all your comments are sent to Akismet’s servers. SpamAnvil lets you choose your own AI provider, works with free models, keeps you in control of your data, and uses true AI understanding instead of statistical pattern matching.

How is SpamAnvil different from Antispam Bee?

Antispam Bee uses traditional techniques like honeypot fields, country blocking, and regex rules. These work for basic spam but miss sophisticated attacks. SpamAnvil adds AI analysis that actually reads and understands comments in context, catching spam that looks legitimate to keyword-based systems.

Which AI provider should I use?

For free usage: OpenRouter with the free Llama 3.1 8B model works surprisingly well for spam detection. For best accuracy: OpenAI GPT-4o-mini offers the best quality-to-price ratio. For privacy: Google Gemini or a self-hosted model via the Generic OpenAI-compatible option. For maximum reliability: Configure a primary + fallback provider so spam checking never stops.

Does this slow down my website?

No. In the default async mode, comments are held as “pending” and processed in the background via WP-Cron every 5 minutes. Your visitors experience zero added latency. There’s also a sync mode available if you prefer instant results.

What happens if the AI service is down?

SpamAnvil has built-in resilience: failed requests are retried up to 3 times with exponential backoff (1 min, 5 min, 15 min). You can also configure a fallback provider that kicks in automatically when the primary fails.

Is my data safe?

Comment content is sent to your chosen AI provider for analysis – this is the only external data transmission. API keys are encrypted with authenticated AES-256-GCM in the database (or can be defined in wp-config.php to never touch the database). IP addresses are stored as salted, keyed hashes (HMAC-SHA-256, not reversible without your site’s secret) and displayed masked in the admin panel.

Does SpamAnvil work with WooCommerce?

Yes. SpamAnvil hooks into WordPress’s standard comment system, which WooCommerce product reviews also use.

Does it work with multilingual sites?

Yes! AI language models understand comments in virtually any language. This is a major advantage over keyword-based spam filters that only work for English.

Can spammers trick the AI with prompt injection?

SpamAnvil uses 6 layers of prompt injection defense: (1) comment content is wrapped in boundary tags, (2) the system prompt explicitly instructs the AI to ignore instructions within comments, (3) heuristic patterns detect common injection phrases and raise the spam score, (4) responses are validated as strict JSON, (5) LLM temperature is set to 0 for deterministic behavior, (6) content is truncated at 5,000 characters.

What is Open Mode?

Open Mode is an optional toggle (Settings → General) that makes leaving a real comment effortless. It removes WordPress’s usual friction – no required name/email (anonymous comments allowed), no login, no first-comment moderation hold – and publishes comments instantly, letting SpamAnvil quietly remove any spam in the background. It’s safe to enable because the invisible defense layers (honeypot, time trap, rate limit, heuristics, AI) still filter spam automatically. It’s applied via filters, so turning it off restores your original settings. Tip: pair it with Sync mode if you want zero delay…

Will the honeypot or time trap block real visitors?

No. The honeypot is a hidden field only bots fill, and the time trap uses a signed timestamp and “fails open” – if anything is missing or looks off, it never flags the comment. Both are invisible to real visitors and, when in doubt, mark a comment as spam (recoverable from the Spam folder) rather than hard-blocking it.

Can I browse a provider’s models?

Yes. On the Providers tab, click “Browse models” next to the model field for OpenAI, OpenRouter or Featherless to search that provider’s live model list and pick one. OpenRouter models show a “free” badge and context size.

Can I use a local/self-hosted AI model?

Yes! If you run a local model with an OpenAI-compatible API (e.g., LM Studio, Ollama with a proxy, vLLM, Text Generation WebUI), you can connect it using the “Generic OpenAI-Compatible” provider option with your local URL.

Who developed SpamAnvil?

SpamAnvil was created by Dr. Alexandre Amato, a vascular surgeon and software developer based in Brazil. When he’s not in the operating room, he builds open-source tools and medical education resources such as Enciclopédia Médica.

What WordPress versions are supported?

SpamAnvil requires WordPress 5.8+ and PHP 7.4+.

How can I support SpamAnvil?

SpamAnvil is 100% free and always will be. No premium tier, no “pro” upsells. If it’s saving you time and money, you can sponsor the project on GitHub. What’s the next WordPress problem I’ll solve and make free? I’m tired of expensive solutions for simple problems.

Changelog

Fixes a 1.20.0 regression: when the first AI model in your list was slow, the fallback model was never tried. Recommended if you list more than one model.

1.20.1

  • Fix: with a slow first model, the fallback model was never tried (introduced in 1.20.0). The time limit gave the first model in the list all the time the run had left. When that model hung, it used up the whole budget, no time remained for the next model, and the next run started again from the first — so a healthy fallback could go unused indefinitely while the comment waited. Each call now leaves at least 8 seconds for every model still behind it in the list, so a hanging first model is cut off in time for the fallback to answer in the same run.
  • Fix: the automatic search for a replacement free model (used when a configured model has disappeared) listed the provider’s models with a fixed 30-second timeout, outside the run’s time limit. It now gets only the time that is left, minus what the classification call after it needs.

1.20.0

  • Fix: the background job could run far past its time limit. It allows itself 50 seconds per run, but only checked the clock after finishing a whole comment — and a single comment can go through several models, each allowed 60 seconds to answer. On a slow day one run could take minutes, pile up against the next one, or be killed by the host halfway through. Every model call is now limited to the time the run has left, and a call is not started at all when fewer than 8 seconds remain: the comment goes back to the queue untouched and is picked up on the next run. If some models were asked and none answered in time, it counts as a normal failed attempt with the usual backoff, so a model that always hangs cannot keep a comment cycling forever.
  • Fix: behind a proxy or CDN, repeat offenders were counted by the proxy’s address. The block check at submission uses the visitor IP from the header you chose on the IP tab (1.10.0), but the repeat-offender count taken after a verdict — usually in the background job — read the address WordPress stored, which behind a proxy is the proxy’s. SpamAnvil now remembers the visitor IP it resolved when the comment arrived and uses that same identity at every step. Sites not behind a proxy are unaffected and store nothing extra.
  • Fix: log and statistics retention drifted by the site’s time zone. Entries are written in the site’s local time, but the cleanup compared them against UTC, so on a site at UTC−3 logs were removed 3 hours early (up to 14 hours in other zones). The cutoffs, and the date ranges of the Statistics tab, now use the site’s time zone.
  • Fix: the verdict cache did not notice a change of endpoint for the “Generic OpenAI-compatible” provider. Pointing it at another server with the same model name and key kept serving the old server’s verdicts. The endpoint is now part of the provider fingerprint.
  • New: a warning under the Generic provider’s API URL when it uses plain http:// to a server on the internet: the API key and every comment, with the commenter’s name and email, would travel unencrypted. Local and private-network addresses (a model on the same machine or LAN) are not flagged.
  • Fix: the text SpamAnvil suggests for your privacy policy said IP addresses are stored “only” as hashes. A partly masked form is also kept for the IP tab, and since this release the visitor IP resolved behind a proxy is kept with the comment. The text now says both.
  • Clarification of 1.19.1: a moderator’s decision is checked against the database right before a verdict is applied, so a change made while the AI was answering is respected. The check and the write are still two steps, so a moderation landing in the few milliseconds between them can be overwritten; the 1.19.1 notice said “always”, which overstated it.
  • Development: the test suite now also runs against WordPress 5.8 on PHP 7.4 — the oldest versions the plugin declares support for — not only the latest WordPress.

1.19.1

  • Fix: 1.19.0’s second check before applying a verdict did not work on most sites. It re-read the comment’s status through WordPress’ in-request cache, which the background job had filled when it loaded the comment — so a moderator acting in another browser tab while the model was answering was invisible to it, and the verdict overwrote their decision anyway. The status (and the moderation mark below) is now read straight from the database. The 1.19.0 test changed the comment inside the same request, where the cache is cleared, so it passed without proving anything; the new test writes the database the way a separate request does, and fails against the 1.19.0 code.
  • Fix: sending a comment back to “pending” did not count as a moderator’s decision. A comment the AI marked as spam, returned to pending by a moderator, could be picked up again by the automatic scan of pending comments and get the same verdict from the cache; a comment a moderator unapproved could be approved automatically. Now every status change a person (or another plugin) makes — approve, pending, spam, trash — is recorded on the comment, evicts its cached verdict and closes its queue entry, and the automatic paths leave that comment alone. The manual “Scan pending” button is how you ask for a fresh analysis. SpamAnvil’s own verdicts, honeypot, time trap and heuristic blocks are not recorded as moderation.
  • Fix: the verdict cache ignored which provider and model answered, so switching to another model kept serving the old model’s verdicts. The provider configuration is now part of the cache key.
  • New: the “Privacy Notice” option now does what it says. The checkbox (on by default) was saved but nothing ever displayed it. When SpamAnvil is on and a provider is configured, commenters now see one line above the submit button saying their comment, name, email and website are sent to an external AI service to filter spam. Moderators, whose comments are never analyzed, do not see it. SpamAnvil also suggests matching text for your privacy policy under Settings → Privacy. Turn the option off on the General tab if your privacy policy already covers it.
  • Fix: uninstalling with “Delete data” on left behind the cached verdicts and per-comment bookkeeping; they are now removed. The daily email digest is now unscheduled on uninstall, and re-scheduled if its cron event goes missing.

1.19.0

  • Fix: the 1.16.0 prompt fix never reached sites that simply clicked “Update”. WordPress does not run a plugin’s activation code on update, so SpamAnvil re-runs its migrations when it notices a new version — but it only compared the database schema version, and 1.16.0 changed the default prompt without changing the schema. Sites that updated from 1.15.x or earlier without deactivating and reactivating stayed on the old prompt, the one that marked comments in another language, and short polite ones, as spam. Migrations now run whenever the plugin version changes, so this update applies the 1.16.0 prompt at last. As before, only unmodified default prompts are replaced; customized prompts are left alone. The 1.16.0 upgrade notice said this happened automatically; for those sites it did not.
  • Fix: “Reset to Default” on the Prompt tab restored the pre-1.16.0 prompt, from a copy kept in the JavaScript that was never updated. The button now uses the plugin’s current defaults.
  • Fix: turning SpamAnvil off did not stop the analysis. The switch on the General tab stopped new comments from being queued, but the background job kept processing what was already queued and kept picking up pending comments, spending API calls. Now the switch stops everything: the background job, the manual “Process queue” and “Scan pending” buttons, and Open Mode’s changes to WordPress’ comment settings. Queued comments wait and are processed once SpamAnvil is on again.
  • Fix: a comment that a moderator had already handled could be overruled by the queue. The queue checked only that the comment still existed, so a comment sent to the trash while it waited could come back approved when its turn came. Now moderating a comment — approving it, marking it spam or trashing it, whether done by a person or another plugin — closes its queue entry without an API call. SpamAnvil also checks again right before applying a verdict, because a model can take a minute to answer: if someone decided in the meantime, the AI’s verdict is written to the log and the comment is left as that person set it. In Open Mode and Sync mode, where comments are published before analysis, an approved comment is still analyzed as before.
  • Fix: the verdict cache could reuse a verdict for a different situation. It matched only the comment text and the author’s website, so the same words on another post, from another author, or after a prompt change got the old verdict for up to 7 days. The cache now matches only when everything the model would see is identical: text, post, author name, email and website, and the prompts. When a moderator overturns a verdict that came from the cache, that entry is deleted so the same text is not judged the same way again.
  • Change: OpenRouter now uses free models only by default. Since 1.13.1 the default was “openrouter/free, openrouter/auto”: when the free models could not answer — about 4 calls in 10 — the paid openrouter/auto stepped in. An account without credit was never charged, but one with credit paid for part of the analysis without being told, while the setup wizard said the free option “costs nothing”. The default is now openrouter/free alone; when no free model answers, the comment waits in the queue and is retried later. Existing sites move to the new default only if they were still on a chain SpamAnvil wrote itself (the old default, or the one the 1.17.0 wizard stored); a chain you edited is left alone. To let a paid model step in again, add openrouter/auto at the end of the model list on the Providers tab.

1.18.1

  • Fix: on sites with WP_DEBUG enabled, WordPress logged “Translation loading for the spamanvil domain was triggered too early” whenever the plugin had to (re)schedule its cron events. Scheduling runs on plugins_loaded and reaches the cron_schedules filter, where the interval’s label is translated — before WordPress is ready for translations. Schema check and cron scheduling now run on init instead. Verified against WordPress 7.1-RC4: the notice is gone and the events still schedule.
  • Fix: 1.15.0 added a second set_transient( 'spamanvil_activation_redirect' ) inside the activator, which also runs on a database-version change — so a future schema bump would have redirected people to the settings screen out of nowhere. Removed; the activation hook has always set it.
  • Correction to the 1.15.0 release notes. They stated that the post-activation redirect “never actually happened” because nothing set the flag it reads. That was wrong: spamanvil.php has set that transient since 1.1.1, and the redirect did fire. What 1.15.0 genuinely changed was its destination — unconfigured installs now land on the setup wizard instead of the settings page.
  • Compatibility: WordPress 7.1 verified end to end on RC4 rather than by code review — activation, all admin screens, the comment form’s honeypot and signed time trap, an anonymous comment reaching the queue, a bot caught by the honeypot, per-IP rate limiting, and cron scheduling. No PHP notices, warnings or deprecations from the plugin.

1.18.0

  • New: a screen to get back the comments that were flagged by mistake. The prompt rules removed in 1.16.0 had been auto-marking real readers as spam — a comment written in another language scored 75+, generic praise 70+. Fixing the rules does not bring those comments back, and WordPress deletes spam older than 30 days on its own, so they are recoverable only for a while. Settings → SpamAnvil → Logs now links to a review screen listing the spam-flagged comments that carry no link and no author website and whose score sits just above your threshold — the shape a wrongly flagged reader has, and the shape real spam almost never has. Each row shows the AI’s own reason for flagging it, and ticking a comment restores and publishes it. A dismissible notice points there while there is something to review. Verdicts from the honeypot, time trap, rate limit and heuristics are never listed: those are deterministic, and were never the prompt’s doing.

Full changelog on WordPress.org →

Screenshots

First-run setup - One API key, tested before it is saved. The free option costs nothing
First-run setup - One API key, tested before it is saved. The free option costs nothing
Statistics dashboard - All-time spam blocked, 30-day counters and daily activity
Statistics dashboard - All-time spam blocked, 30-day counters and daily activity
Evaluation logs - Full audit trail: score, heuristics, provider, model, the AI's reason and response time
Evaluation logs - Full audit trail: score, heuristics, provider, model, the AI's reason…
General settings - Enable/disable, processing mode, spam threshold, queue status
General settings - Enable/disable, processing mode, spam threshold, queue status
Providers tab - Chain several AI providers with per-provider models and Test Connection
Providers tab - Chain several AI providers with per-provider models and Test Connection
Prompt tab - Editable system and user prompts, with the prompt-injection defense built in
Prompt tab - Editable system and user prompts, with the prompt-injection defense built in
IP Management - Visitor IP source, rate limiting and blocked IPs with escalation levels
IP Management - Visitor IP source, rate limiting and blocked IPs with escalation levels
Smart email notifications - No more one email per spam attempt: get notified only after the verdict, or a single daily digest
Smart email notifications - No more one email per spam attempt: get notified only after…

For developers

Is this your plugin? Show off the numbers.

Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.

Active installs badge Rating badge Health score badge

Best SpamAnvil alternatives

All AI plugins →
Alternatives
Rank Plugin Active installs Rating Updated Health
1 Elementor Website Builder – more than just a page builder Elementor Website Builder – more than just a page builder The Elementor Website Builder has it all: drag and drop page builder, Atomic Editor, pixel… by Elementor 10M+ ★★★★★★★★★★ 4.5 (7.3K) 5 days ago 93
2 All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) All in One SEO AIOSEO is the WordPress SEO plugin. Boost SEO rankings with AI SEO tools, schema, meta… by Syed Balkhi 2M+ ★★★★★★★★★★ 4.7 (5.2K) 6 days ago 98
3 AI Agent by SiteGround AI Agent by SiteGround Manage your WordPress site with AI - create content, install plugins, and perform site… by SiteGround 1M+ ★★★★★★★★★★ 1.6 (97) 4 weeks ago 66
4 Premium Addons for Elementor – AI-Ready Elementor Addons, Widgets & Templates Premium Addons for Elementor 90+ Elementor widgets & addons, 600+ templates, Mega Menu, WooCommerce, Display Conditions… by Leap13 600K+ ★★★★★★★★★★ 4.9 (1.7K) 1 day ago 96
5 Angie – Agentic AI Angie – Agentic AI Build anything your site needs. Manage it through an agentic AI conversation inside… by Elementor 100K+ ★★★★★★★★★★ 3.1 (18) 1 week ago 73
6 AI Engine – The Chatbot, AI Framework & MCP for WordPress AI Engine – The Chatbot, AI Framework & MCP for WordPress AI meets WordPress. Your site can now chat, write poetry, solve problems, and maybe make… by Jordy Meow 90K+ ★★★★★★★★★★ 4.9 (867) 4 days ago 96
7 AI Provider for Anthropic AI Provider for Anthropic Anthropic (Claude) provider for the PHP AI Client SDK. by WordPress.org 60K+ ★★★★★★★★★★ No reviews 1 month ago 59
8 AI AI AI features, experiments and capabilities for WordPress. by WordPress.org 50K+ ★★★★★★★★★★ 4.6 (9) 1 month ago 82
9 AI Provider for OpenAI AI Provider for OpenAI AI Provider for OpenAI for the PHP AI Client SDK. by WordPress.org 50K+ ★★★★★★★★★★ No reviews 1 week ago 63
10 AI Provider for Google AI Provider for Google Google AI (Gemini) provider for the PHP AI Client SDK. by WordPress.org 40K+ ★★★★★★★★★★ No reviews 1 week ago 78

FAQ

SpamAnvil: quick answers

Straight answers, pulled from live WordPress.org data.

Live data from WordPress.org · checked Sep 29, 2026

Is SpamAnvil free?

Yes. SpamAnvil is free to download and use from the official WordPress.org plugin directory.

Is SpamAnvil safe to use in 2026?

SpamAnvil is a solid plugin choice in 2026, with a few things worth checking first. It runs on 30+ sites, is rated 5/5 and was last updated 2 days ago, and scores 74/100 on our health check.

How many websites use SpamAnvil?

SpamAnvil is active on 30+ WordPress websites and has been downloaded 2,798 times since it launched in February 2026. It was downloaded 927 times in the last 30 days.

Does SpamAnvil work with WordPress 7.1?

Yes. The developer has tested SpamAnvil up to WordPress 7.1.2, the latest release. It requires WordPress 5.8 or newer.

What PHP version does SpamAnvil need?

SpamAnvil requires PHP 7.4 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.

When was SpamAnvil last updated?

The latest version, 1.20.1, was released on September 27, 2026 (2 days ago).

Who makes SpamAnvil?

SpamAnvil is developed and maintained by Alexandre Amato.

What are the best alternatives to SpamAnvil?

The most popular alternatives to SpamAnvil are Elementor Website Builder (10M+ installs), All in One SEO (2M+ installs) and AI Agent by SiteGround (1M+ installs).

Powered by PageForge

Want thousands of pages that rank like these? Build them in an afternoon.

This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.

  • CSV, Google Sheets & API data sources
  • AI content, schema & internal links per page
  • Works with Elementor, Gutenberg, Yoast & Rank Math
  • Free on WordPress.org — no credit card
Sarah is here to help!
Hi there! 👋 Need help finding what you're looking for?
Sarah
Sarah
Online & Ready to Help
Hi there! 👋 Need help finding what you're looking for?

We'll use this to continue our conversation

Just now ✓ Verified

Join 500+ SEO Pros Scaling Their Strategy

Get exclusive programmatic SEO tactics, AI content workflows, and the latest PageForge updates delivered straight to your inbox. Stay ahead of the algorithm.

We care about your data in our privacy policy.