تخطى إلى المحتوى
WordPress.org

العربية

  • القوالب
  • الإضافات
  • الأخبار
  • الدعم الفني
  • حول
    • كُتيب المساهمة
  • احصل على ووردبريس
احصل على ووردبريس
WordPress.org

Plugin Directory

Reycob Form Firewall

  • Submit a plugin
  • My favorites
  • Log in
  • Submit a plugin
  • My favorites
  • Log in

Reycob Form Firewall

بواسطة Victor Rodriguez
تنزيل
  • تفاصيل
  • المراجعات
  • التنصيب
  • التطوير
الدعم

الوصف

Reycob Form Firewall adds a lightweight protection layer for public forms without using an external CAPTCHA service.

Main features:

  • Local math CAPTCHA loaded only when the visitor interacts with the checkbox.
  • Browser proof token, honeypot field, and origin validation for protected forms.
  • Rate limits per visitor and per endpoint.
  • Specific protection for WooCommerce product reviews against links, duplicated spam, and repeated abusive submissions.
  • Automatic exclusions for WooCommerce cart, checkout, payments, coupons, shipping, Store API, REST API, webhooks, cron, and server-to-server requests.
  • Admin settings for limits, CAPTCHA, browser proof mode, IP source, and excluded paths.
  • Developer opt-out with data-rffw-skip="1" and opt-in for custom admin-post or admin-ajax actions through the rffw_protected_actions filter.

The plugin is designed for visible public forms. It does not modify global fetch or XMLHttpRequest, does not call third-party APIs, and does not log IP addresses or submitted form contents.

The JavaScript and CSS files distributed with the plugin are the human-readable source files. No minification, bundling, compilation, npm, webpack, or other build step is required.

Privacy

The plugin does not collect analytics, does not send data to external services, and does not store submitted form contents.

Temporary tokens and hashed rate-limit keys may be stored in WordPress transients to validate CAPTCHA challenges, browser proof checks, and request frequency. These temporary values expire automatically.

التنصيب

  1. Upload the plugin folder to /wp-content/plugins/reycob-form-firewall/, or install it through the WordPress Plugins screen.
  2. Activate Reycob Form Firewall.
  3. Go to Settings > Form Firewall.
  4. Review the default limits and clear any page cache/CDN cache after activation.
  5. Test your public contact forms, login, registration, comments, product reviews, cart, checkout, and payment flow.

الأسئلة المتكررّة

Does it use Google reCAPTCHA or another external service?

No. The CAPTCHA is generated and verified locally by WordPress.

Does it protect WooCommerce checkout?

No. Checkout, cart, coupons, payment callbacks, shipping calculations, Store API, and product add-to-cart actions are intentionally excluded so normal store operations keep working.

Does it protect WooCommerce reviews?

Yes. Product reviews use the general form protections plus an additional review-specific spam check.

Can I exclude a form?

Yes. Add data-rffw-skip="1" to the form element. Administrators can also exclude paths from the settings screen.

Can developers protect custom AJAX or admin-post actions?

Yes. Use the rffw_protected_actions filter to return an array of action names that should require the firewall checks.

المراجعات

لا توجد مراجعات لهذه الإضافة.

المساهمون والمطوّرون

“Reycob Form Firewall” هو برنامج مفتوح المصدر. وقد ساهم هؤلاء الأشخاص بالأسفل في هذه الإضافة.

المساهمون
  • Victor Rodriguez

ترجمة ”Reycob Form Firewall“ إلى لغتك.

مُهتم بالتطوير؟

تصفّح الشفرة، تحقق من مستودع SVN، أو الاشتراك في سجل التطوير بواسطة RSS.

سجل التغييرات

1.3.7

  • Render the honeypot as a hidden input so browser autofill and password managers cannot populate it.
  • Reset form rate-limit keys after the autofill compatibility correction.

1.3.6

  • Count only submissions that pass the browser proof and CAPTCHA toward form rate limits.
  • Reset the rate-limit key namespace so false positives from earlier versions do not keep legitimate forms blocked.

1.3.5

  • Use a non-semantic honeypot name and standard autocomplete suppression to prevent browser and password-manager autofill.
  • Ignore the former honeypot field so cached pages using version 1.3.4 no longer trigger false-positive blocks.

1.3.4

  • Prevent browser password managers from filling the hidden honeypot field and causing false-positive blocks.
  • Isolate CAPTCHA hover, focus, and active button states from theme styles.

1.3.3

  • Use WordPress-generated endpoint paths for admin AJAX, admin post, comments, login, REST, XML-RPC, and admin area detection.
  • Move CAPTCHA styles into a human-readable CSS source file and enqueue it normally.

1.3.2

  • Prepared WordPress.org readme, centralized sanitized request reads, and adjusted automated review compatibility.

1.3.1

  • Limited protection scope to public forms, login, registration, comments, and WooCommerce product reviews.
  • Excluded WooCommerce cart, checkout, payments, Store API, webhooks, and license/API requests.
  • Removed global request interception and added on-demand CAPTCHA loading.

ميتا Meta

  • Version 1.3.7
  • Last updated قبل يومين
  • Active installations 20+
  • WordPress version 6.0 أو أعلى
  • Tested up to 7.1.1
  • PHP version 7.4 أو أعلى
  • Language
    English (US)
  • Tags
    captchaformslogin securityspam protectionwoocommerce
  • عرض متقدم

التقييم

لم يتم تقديم أي مراجعات بعد.

Your review

See all reviews

المساهمون

  • Victor Rodriguez

الدعم

لديك شيء لتقوله؟ بحاجة الى مساعدة؟

عرض منتدى الدعم

  • نبذة عن
  • أخبار
  • الاستضافة
  • الخصوصية
  • Showcase
  • قوالب
  • إضافات
  • الأنماط
  • تعلم
  • الدعم الفني
  • المطوّرون
  • WordPress.tv ↗
  • شارك بالمساهمة معنا
  • الفعاليات
  • Donate ↗
  • Swag ↗
  • WordPress.com ↗
  • Matt ↗
  • bbPress
  • BuddyPress
WordPress.org
WordPress.org

العربية

  • Visit our X (formerly Twitter) account
  • قم بزيارة حسابنا على بلوسكاي
  • Visit our Mastodon account
  • قم بزيارة حسابنا على ثريدز
  • قم بزيارة صفحتنا على الفيسبوك
  • Visit our Instagram account
  • Visit our LinkedIn account
  • قم بزيارة حسابنا على تيك توك
  • Visit our YouTube channel
  • قم بزيارة حسابنا على Tumblr
الكود شِعرٌ.
The WordPress® trademark is the intellectual property of the WordPress Foundation.