BLACK FRIDAY
Save 59% on PageForge Annual $191/year $485/year
Claim 59% Off →
Spamify – Elastic Spam Shield icon
Actively maintained Tested with WP 7.1

Spamify – Elastic Spam Shield

Self-contained email validation and spam protection for WordPress forms. Syntax + optional mailbox checks, honeypot, rate limiting and CAPTCHA.

Active installs<10New
Downloads · 30d225▼ -17.3% vs prev. 30d
Rating—0 reviews
Health score64/100Good
All-time downloads303Since Sep 2026
Support resolved—No recent threads
RequiresWP 5.8PHP 7.4+
Downloads · 7d33▲ +26.9% week over week
Our verdict

Solid choice

Spamify – Elastic Spam Shield is a solid plugin choice in 2026, with a few things worth checking first. Was last updated 3 weeks ago, and scores 64/100 on our health check.

  • Actively developed — last update 3 weeks ago
  • Tested with the latest WordPress (7.1)
  • Small user base (<10 active installs)
  • Very few reviews so far

How does it stack up?

Side-by-side on installs, updates, ratings & support

Daily downloads

91827Aug 30Sep 17Oct 6
Yesterday6
Daily average (1y)8
Peak day37Sep 1, 2026
Last 12 months308

Download spikes usually follow a new release — each site that auto-updates counts as a download.

Rankings

Where Spamify stands today

WordPress.org search rankings

Live position in the plugin search, top 100
KeywordPositionCompeting pluginsCategory
anti-spam >100 735 Best anti-spam plugins →
contact form >100 8,471 Best contact form plugins →
email validation >100 4,392 Best email validation plugins →
protection >100 5,657 Best protection plugins →
spam >100 3,626 Best spam plugins →

About Spamify – Elastic Spam Shield

From the official readme · v1.1.0

Description

Spamify is a lightweight, self-contained email spam and validation plugin for WordPress forms. It scores every submitted email address and blocks or flags the ones that look fake, invalid, or abusive — without sending your visitors’ data to any tracking service.

It never sends your data to the plugin author or to any analytics or tracking service, and it does not require an account or a licence key. One optional feature — live mailbox verification — reaches out to the recipient’s own mail server, and it is on by default — you can turn it off under Settings → Advanced Filters (see External Services below).

Detection layers:

  • Syntax – Validates the email format and catches gibberish, keyboard-mash, and obviously fake addresses. Runs locally, always on.
  • SMTP mailbox verification (on by default) – Connects to the recipient domain’s mail server and asks whether the mailbox exists. No message is ever sent.
  • Behavior & bot signals – Scores mouse, scroll, keyboard and focus activity, a headless-browser (automation) check, keystroke rhythm, and a JavaScript challenge — all collected locally from the page the visitor already loaded, with no network calls or third-party service involved.

Bot protection & security (all local, all free):

  • Honeypot & timing – Hidden decoy fields plus a minimum form-fill time catch automated submissions.
  • Rate limiting – Throttle how many submissions a single IP can make within a rolling window.
  • CAPTCHA (optional) – Invisible Cloudflare Turnstile or Google reCAPTCHA v3, using your own free provider keys.
  • Allowlist – Always let trusted domains, exact email addresses, or IP / CIDR ranges through.
  • Hide login (optional) – Move wp-login.php to an address of your choice and serve a 404 (or a redirect) at the old one and at /wp-admin/ (WordPress normally bounces logged-out visitors from /wp-admin/ to the login screen, which would give the secret address away), so brute-force bots have nothing to hammer. Every login, logout, lost-password and registration link — including the ones inside WordPress emails — is rewritten for you. Multisite compatible: each site in a network keeps its own address, subdirectory installs get the slug under their own folder, and a single SPAMIFY_HIDE_LOGIN_SLUG constant in wp-config.php can enforce one address network-wide.

Privacy & administration:

  • GDPR tools – Automatic daily log purge by retention window, plus optional IP anonymisation.
  • Site Health – Built-in WordPress Site Health checks for logging, DNS, and mailbox verification.
  • Setup wizard – A guided first-run wizard to get protected in about a minute.
  • Dashboard & logs – See what was blocked, flagged, and allowed, with per-day charts, plus a WP Dashboard widget showing today’s and this week’s figures at a glance.
  • Review Queue – Every currently-flagged submission — comments, registrations, profile changes, and every connected form — in one screen, instead of scattered across the native Comments/Users screens.
  • Timeline – Look up one email address or IP and see its full chronological history across every zone, with the evidence behind every hit.
  • Digest reports – A daily, weekly, or monthly summary email, optionally with a CSV report (totals, source breakdown, top offending domains) attached.

Supported forms:

  • WordPress core (registration, comments, profile update, lost password, multisite signup)
  • Contact Form 7
  • WPForms
  • Jetpack Forms
  • Elementor Forms

Upgrade to Pro

Spamify is free forever on WordPress.org — everything described above runs standalone, with no account, licence key, or nag screens required.

Spamify Pro adds the rest of the detection engine and site-wide protection tools for busier or higher-traffic sites:

  • Disposable domain blocking – 100,000+ throwaway and temporary-inbox providers, refreshed automatically.
  • IP threat intel & DNSBL – matches the sender’s IP against aggregated abuse feeds and DNS blocklists.
  • VPN / proxy / Tor detection – flags anonymised traffic from VPNs, open proxies, Tor exit nodes and datacenter ranges.
  • Content analysis – link stuffing, spam keywords, homoglyph and Unicode obfuscation.
  • Behavioural reputation – per-sender history layered on top of honeypot and timing.
  • Custom rules – your own if-this-then-that logic on any field or signal.
  • Network firewall – VPN/Tor/ASN blocking with escalating temporary bans.
  • Geo report & country blocking – a world map of where blocked spam comes from, powered by a free offline database.
  • Uptime monitor & deliverability tools – scheduled URL checks, bulk email-list verification, and an SPF/DKIM/DMARC checker.
  • More integrations – WooCommerce, Gravity Forms, Ninja Forms, Fluent Forms, newsletter opt-ins, and a universal connector for any form.

Plans start at $49/year for up to 3 sites, with Agency and Lifetime options for larger portfolios. Buy Spamify Pro →

External Services

Two features can connect to an external service. SMTP mailbox verification is on by default (you can turn it off under Settings → Advanced Filters); CAPTCHA verification stays off until you enable it and add your own provider keys. Neither sends any data to the plugin author.

1. SMTP mailbox verification (on by default)

When you turn on SMTP Verification (Settings → Advanced Filters), the plugin opens a direct connection to the mail server (MX host) of the recipient email address’s own domain and performs an SMTP handshake to check whether the mailbox exists. What is sent: the email address being validated, sent only to that address’s own mail provider, and only at the moment a form containing that address is submitted or checked. No email message is ever sent, and no data is sent to the plugin author or to any third-party service. Because each address is verified against its own provider’s server, there is no single service, account, terms of service, or privacy policy involved. Turn this feature off under Settings → Advanced Filters if you prefer that submitted addresses are never contacted.

Outbound-port connectivity probe. Many hosts block outbound port 25, which makes mailbox verification impossible. To detect this, the plugin makes a one-off TCP connection to a well-known public mail server — by default Google’s inbound MX, gmail-smtp-in.l.google.com on port 25 — and closes it immediately without sending any data. Only a yes/no “is port 25 open” result is kept (cached for up to a week). This probe runs when SMTP verification is enabled, and when you open the Advanced settings tab or the Tools → Site Health screen (so the status can be shown). No personal data is transmitted. You can change or disable the probe host with the spamify_port25_probe_host filter.

2. CAPTCHA verification (optional, disabled by default)

If you enable CAPTCHA (Settings → Bot Protection) and enter your own provider keys, the visitor’s CAPTCHA token is sent to your chosen provider’s verification endpoint so the provider can confirm the visitor is human:

  • Cloudflare Turnstile – token sent to https://challenges.cloudflare.com/turnstile/v0/siteverify. Terms: https://www.cloudflare.com/website-terms/ — Privacy: https://www.cloudflare.com/privacypolicy/
  • Google reCAPTCHA v3 – token sent to https://www.google.com/recaptcha/api/siteverify. Terms: https://policies.google.com/terms — Privacy: https://policies.google.com/privacy

Only the CAPTCHA token and the visitor IP are sent, only on form submission, and only if you have configured a provider. This feature is off until you supply keys.

Installation

  1. Upload the spamify folder to the /wp-content/plugins/ directory, or install it through the Plugins screen in WordPress.
  2. Activate the plugin through the Plugins menu in WordPress.
  3. Open Spamify in the admin menu and follow the setup wizard to configure protection.

Frequently asked questions

Does this plugin send any data to your servers?

No. Spamify never contacts the plugin author’s servers, and it sends no data to any analytics or tracking service. It runs on your own site. The only outbound connections are those described in External Services — SMTP mailbox verification and its port-25 connectivity probe (verification is on by default; you can turn it off under Settings → Advanced Filters), and CAPTCHA verification (off until you add your own keys).

Is SMTP verification required?

No. It is on by default, but you can turn it off under Settings → Advanced Filters. The plugin still validates syntax and protects your forms with the honeypot, timing, rate-limiting, allowlist, and CAPTCHA features without it.

Which PHP version is required?

PHP 7.4 or higher.

Why are some submissions marked “unverifiable”?

Many hosts block outbound port 25, and many mail servers greylist or use catch-all addresses, so a mailbox cannot always be confirmed. By default these are flagged for review rather than blocked; you can change this in Settings.

Is there a Pro version?

Yes. Spamify Pro adds the rest of the detection engine (disposable-domain blocking, IP threat intel, VPN/Tor detection, content analysis, custom rules), a network firewall, a geo report, deliverability tools, and integrations for WooCommerce, Gravity Forms, Ninja Forms and Fluent Forms. The free version on WordPress.org is fully functional on its own and is not a limited trial. See spamify-pro.github.io or Buy Spamify Pro.

I hid my login page and locked myself out. What now?

Add define( 'SPAMIFY_HIDE_LOGIN_DISABLE', true ); to your wp-config.php. wp-login.php works normally again, and you can change or switch off the setting from Protection → Hide login.

Does hiding the login work on multisite?

Yes. Every site in the network sets its own address on its own Protection screen, and on a subdirectory network the address lives under that site’s folder (example.com/team/secret-login/). To use one address everywhere, add define( 'SPAMIFY_HIDE_LOGIN_SLUG', 'secret-login' ); to wp-config.php. wp-signup.php and wp-activate.php stay reachable so registration and activation keep working. The feature needs pretty permalinks.

Changelog

1.1.0

  • Maintenance: Internal code-quality refresh. Every source file is now under 400 lines, large admin pages and engine layers were split into focused, single-responsibility files, and the admin stylesheet was broken into per-screen partials — no behaviour or settings change.
  • Maintenance: JavaScript is now internationalised through the standard wp.i18n API (with wp_set_script_translations), so every user-facing string in the browser is translatable; all named callbacks, added file-level documentation, and no anonymous functions remain.
  • Maintenance: Re-audited every AJAX endpoint to confirm nonce verification and capability checks are in place.

1.0.1

  • New Feature: Continuous Spam Scan — retro-scanning legacy accounts/comments now survives a page reload or navigating away instead of stopping, and Pause/Resume picks up exactly where it left off rather than starting over.
  • New Feature: Behavior & Bot Signals detection layer — scores headless/automation-browser detection, keystroke rhythm, mouse/keyboard/focus activity, and a JavaScript challenge, all collected locally on every form with no third-party service involved.
  • New Feature: Review Queue — every currently-flagged submission across comments, registrations, profile changes, and every connected form, in one screen instead of scattered across the native Comments/Users screens.
  • New Feature: Visual “why was this blocked” Timeline per IP/email — chronological history of every hit from that address across all zones.
  • New Feature: A “Spamify” dashboard widget on the core WP dashboard (wp-admin/index.php) — today’s and this week’s blocked/flagged counts at a glance, no need to visit the plugin page.
  • New Feature: Digest emails can now be sent daily, weekly, or monthly, optionally with a CSV summary report (totals, source breakdown, top offending domains) attached.
  • Fix: The Activity Log’s “Delete entry” button did not actually delete the log row.
  • Fix: The Spam Scan page’s “no offline Tor/ASN dataset” notice rendered as a garbled, unreadably narrow box instead of a normal banner.

1.0.0

  • Initial release.
  • Feature: Hide login — serve wp-login.php from a custom address and answer the old one, plus /wp-admin/ for logged-out visitors, with the theme’s 404 page, a home-page redirect, or a URL of your choice. All generated login/logout/lost-password/registration links are rewritten automatically.
  • Multisite: per-site login addresses, subdirectory-network aware matching, network-level links resolve against the main site, and an optional SPAMIFY_HIDE_LOGIN_SLUG constant enforces one address across the whole network.
  • Major: syntax validation, optional SMTP mailbox verification (off by default), honeypot & timing, per-IP rate limiting, allowlist, invisible CAPTCHA (bring your own keys), GDPR log tools, Site Health checks, and a setup wizard. Integrations for WordPress core forms, Contact Form 7, WPForms, Jetpack Forms, and Elementor Forms.

Full changelog on WordPress.org →

Screenshots

Spamify – Elastic Spam Shield screenshot
Spamify – Elastic Spam Shield screenshot
Spamify – Elastic Spam Shield screenshot
Spamify – Elastic Spam Shield screenshot
Spamify – Elastic Spam Shield screenshot
Spamify – Elastic Spam Shield screenshot
Spamify – Elastic Spam Shield screenshot
Spamify – Elastic Spam Shield screenshot

For developers

Is this your plugin? Show off the numbers.

Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.

Active installs badge Rating badge Health score badge

Best Spamify – Elastic Spam Shield alternatives

All anti-spam plugins →
Alternatives
Rank Plugin Active installs Rating Updated Health
1 Akismet Anti-spam: Spam Protection Akismet Anti-spam: Spam Protection The best anti-spam protection to block spam comments and spam in a contact form. The most… by Automattic 5M+ ★★★★★★★★★★ 4.7 (1.2K) 2 months ago 94
2 Antispam Bee Antispam Bee Sophisticated antispam plugin for effective daily comment and trackback spam-fighting… by pluginkollektiv 700K+ ★★★★★★★★★★ 4.8 (226) 2 months ago 78
3 WP Armour – Honeypot Anti Spam WP Armour – Honeypot Anti Spam Fastest growing Anti Spam plugin. No API calls, subscriptions, captcha or puzzle. Full GDPR… by Dnesscarkey 400K+ ★★★★★★★★★★ 5 (1.5K) 1 month ago 80
4 CF7 Apps – Honeypot, Database, Redirection, Webhook, and Addons for Contact Form 7 CF7 Apps Add hCaptcha, Honeypot, and Redirection to Contact Form 7 with CF7 Apps, and generate forms… by Saad Iqbal 300K+ ★★★★★★★★★★ 3.8 (135) 1 week ago 89
5 Anti-Spam by CleanTalk – Spam Protection Without CAPTCHA Anti-Spam by CleanTalk – Spam Protection Without CAPTCHA Stop spam in contact forms, comments, registrations, and WooCommerce automatically. CAPTCHA… by CleanTalk Inc 200K+ ★★★★★★★★★★ 4.8 (3.2K) 2 days ago 92
6 CloudSecure WP Security CloudSecure WP Security CloudSecure WP Securityは、管理画面とログインURLをサイバー攻撃から守る、国産・日本語対応のセキュリティ対策プラグインです。… by XServer 100K+ ★★★★★★★★★★ 5 (2) 1 week ago 86
7 Gravity Forms Zero Spam Gravity Forms Zero Spam Block form spam in Gravity Forms with an invisible token check, email rejection rules, and… by GravityKit 100K+ ★★★★★★★★★★ 4.3 (24) 1 month ago 84
8 Email Encoder – Protect Email Addresses and Phone Numbers Email Encoder – Protect Email Addresses and Phone Numbers Protect email addresses and phone numbers on your site and hide them from spambots. Easy to… by Online Optimisation 90K+ ★★★★★★★★★★ 4.9 (93) 2 weeks ago 91
9 Spam Protection | Maspik Spam Protection | Maspik Blocks spam the moment you activate it. No CAPTCHA, no setup, no API key. Multi-Layer. Just… by yonifre 30K+ ★★★★★★★★★★ 4.7 (87) 1 week ago 94
10 Blackhole for Bad Bots Blackhole for Bad Bots Blackhole is a WordPress security plugin that detects and traps bad bots in a virtual black… by Jeff Starr 30K+ ★★★★★★★★★★ 4.7 (148) 2 months ago 90

FAQ

Spamify – Elastic Spam Shield: quick answers

Straight answers, pulled from live WordPress.org data.

Live data from WordPress.org · checked Oct 7, 2026

Is Spamify – Elastic Spam Shield free?

Yes. Spamify – Elastic Spam Shield is free to download and use from the official WordPress.org plugin directory.

Is Spamify – Elastic Spam Shield safe to use in 2026?

Spamify – Elastic Spam Shield is a solid plugin choice in 2026, with a few things worth checking first. Was last updated 3 weeks ago, and scores 64/100 on our health check.

How many websites use Spamify – Elastic Spam Shield?

Spamify – Elastic Spam Shield is active on <10 WordPress websites and has been downloaded 303 times since it launched in September 2026. It was downloaded 225 times in the last 30 days.

Does Spamify – Elastic Spam Shield work with WordPress 7.1?

Yes. The developer has tested Spamify – Elastic Spam Shield up to WordPress 7.1.3, the latest release. It requires WordPress 5.8 or newer.

What PHP version does Spamify – Elastic Spam Shield need?

Spamify – Elastic Spam Shield requires PHP 7.4 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.

When was Spamify – Elastic Spam Shield last updated?

The latest version, 1.1.0, was released on September 15, 2026 (3 weeks ago).

Who makes Spamify – Elastic Spam Shield?

Spamify – Elastic Spam Shield is developed and maintained by Spamify.

What are the best alternatives to Spamify – Elastic Spam Shield?

The most popular alternatives to Spamify – Elastic Spam Shield are Akismet Anti-spam: Spam Pro… (5M+ installs), Antispam Bee (700K+ installs) and WP Armour (400K+ installs).

Powered by PageForge

Want thousands of pages that rank like these? Build them in an afternoon.

This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.

  • CSV, Google Sheets & API data sources
  • AI content, schema & internal links per page
  • Works with Elementor, Gutenberg, Yoast & Rank Math
  • Free on WordPress.org — no credit card
Sarah is here to help!
Hi there! 👋 Need help finding what you're looking for?
Sarah
Sarah
Online & Ready to Help
Hi there! 👋 Need help finding what you're looking for?

We'll use this to continue our conversation

Just now ✓ Verified

Join 500+ SEO Pros Scaling Their Strategy

Get exclusive programmatic SEO tactics, AI content workflows, and the latest PageForge updates delivered straight to your inbox. Stay ahead of the algorithm.

We care about your data in our privacy policy.