Title: SpamJam – Anti-Spam Protection for Comments &amp; Forms
Author: Matt Biscay
Published: <strong>27. juuli 2022</strong>
Last modified: 9. aug 2026

---

Search plugins

![](https://ps.w.org/spamjam/assets/banner-772x250.png?rev=2762608)

![](https://ps.w.org/spamjam/assets/icon-256x256.png?rev=2762608)

# SpamJam – Anti-Spam Protection for Comments & Forms

 By [Matt Biscay](https://profiles.wordpress.org/skyminds/)

[Download](https://downloads.wordpress.org/plugin/spamjam.zip)

 * [Details](https://et.wordpress.org/plugins/spamjam/#description)
 * [Reviews](https://et.wordpress.org/plugins/spamjam/#reviews)
 *  [Installation](https://et.wordpress.org/plugins/spamjam/#installation)
 * [Development](https://et.wordpress.org/plugins/spamjam/#developers)

 [Support](https://wordpress.org/support/plugin/spamjam/)

## Description

Spam should not create more work for you—or more friction for your visitors.

SpamJam quietly stops automated comment spam with layered, on-site checks. There
are **no CAPTCHAs to solve**, no puzzles to frustrate readers, and no complicated
setup before protection begins.

Install it, activate it, and get back to running your site.

#### Why Site Owners Choose SpamJam

🚫 **Less Spam to Moderate** – Catch automated submissions before they clutter your
comment queue.
 👤 **No Friction for Real People** – Visitors can comment without
image grids, challenges, or extra verification steps. ⚡ **Protected from Activation**–
Core comment protection is enabled by default, with sensible settings already in
place. 🧠 **Fewer False Positives** – Multiple signals work together; suspicious
edge cases can be held for review instead of being discarded. 🩶 **Lightweight by
Design** – Focused checks run where they are needed, without loading a heavy front-
end framework. 🔒 **Privacy-Conscious Detection** – Core comment analysis runs on
your WordPress site rather than sending comment content to a remote spam-scoring
service.

#### Free Comment Protection

The free version gives blogs, publishers, and WooCommerce stores a strong first 
line of defense:

 * **Per-site salted honeypot** – An invisible, site-specific trap makes generic
   bot scripts easier to identify.
 * **Submission timing check** – Detects forms submitted faster than a person could
   reasonably complete them.
 * **Weighted spam scoring** – Combines form, timing, token, and referrer signals
   instead of relying on one fragile test.
 * **Safer moderation path** – Suspicious submissions below the blocking threshold
   can be held for review.
 * **Secure form validation** – Nonces and time-boxed HMAC tokens help verify legitimate
   comment submissions.
 * **Built-in keyword blocklist** – Stops common comment-spam patterns.
 * **WooCommerce product reviews** – Protects review forms and declares compatibility
   with WooCommerce HPOS.
 * **No-JavaScript fallback** – Visitors with JavaScript disabled are not automatically
   hard-blocked.
 * **Dashboard statistics** – See the protection working from your WordPress admin.

No account or API key is required to start protecting comments.

#### Go Beyond Comments with SpamJam Pro

When spam reaches registrations, contact forms, or a high-traffic site, SpamJam 
Pro adds the control and visibility you need:

 * **Protection for popular form plugins** – Cover Contact Form 7, WPForms, Gravity
   Forms, Elementor Forms, Fluent Forms, Formidable Forms, Ninja Forms, and WooCommerce
   registration.
 * **Actionable spam inbox** – Search and filter events, review false positives,
   restore recoverable comments, allow trusted senders, and use bulk actions.
 * **Source-aware rules** – Allow, moderate, block, or discard submissions using
   conditions tailored to each protected source.
 * **Registration protection** – Add honeypot checks and email confirmation to WordPress
   registrations.
 * **Flood and content controls** – Set rate limits, minimum comment length, maximum
   links, and your own blocked terms.
 * **Targeted blocking** – Block configured IP addresses, email addresses, domains,
   or countries while allowlisting trusted senders.
 * **Reports and analytics** – Understand trends, sources, repeat signals, and false
   positives; receive weekly summaries or export PDF reports.
 * **Professional site tools** – Add an automatically updated extended blocklist,
   multisite synchronization, and white-label controls.

Every Pro feature is included. Choose a license based only on the number of sites
you manage from SpamJam’s Account screen in your WordPress dashboard.

#### Built for the Sites Spam Targets

SpamJam is a practical fit for:

 * Blogs and publications with open comments
 * WooCommerce stores collecting product reviews
 * Membership and community sites accepting registrations
 * Lead-generation sites using popular form plugins
 * Agencies managing protection across multiple WordPress sites

#### How SpamJam Stops Bots

SpamJam looks for the patterns automated submissions leave behind:

 1. A site-specific hidden field catches bots that fill every input.
 2. A signed timestamp identifies implausibly fast submissions.
 3. Secure tokens and referrer checks test whether the request came through the expected
    form flow.
 4. A built-in blocklist catches common spam content.
 5. A weighted scoring engine combines those signals and decides whether to allow, 
    hold, or block the submission.

Real visitors keep the familiar WordPress comment experience. The protection stays
in the background.

#### Privacy & Data Handling

Core comment detection is performed on your site and does not require a remote content-
scoring service. Optional logging is off by default. If you enable it, you control
retention, and recovery data can be disabled for metadata-only logging. SpamJam 
excludes passwords, nonces, security tokens, CAPTCHA values, and CSRF fields from
recoverable form data.

Some optional licensing, update, geographic blocking, and premium blocklist features
connect to external services when used. Review your site’s privacy obligations and
enabled settings as you would with any WordPress plugin.

## Installation

 1. In WordPress, go to **Plugins > Add New**.
 2. Search for **SpamJam**.
 3. Click **Install Now**, then **Activate**.
 4. Your comment forms are protected immediately. Open **SpamJam** in the admin menu
    to review statistics or adjust settings.

You can also upload the plugin ZIP from **Plugins > Add New > Upload Plugin**.

## FAQ

### Does SpamJam work immediately after activation?

Yes. Core comment protection is enabled by default with sensible settings. You can
fine-tune it from the SpamJam admin screen, but you do not need to configure an 
API key or build rules before getting protection.

### Will this slow down my site?

SpamJam is designed to stay focused and load its comment-protection script only 
on pages where comments are open. It has no jQuery dependency, and premium feature
files load conditionally when their features are enabled.

### Will my users see captchas?

No. SpamJam’s core protection uses hidden traps, secure tokens, timing, and request
signals instead of CAPTCHA challenges.

### Does this work with my theme?

SpamJam works with standard WordPress comment forms and includes a fallback selector
for themes that use a custom form ID. A developer filter is available for unusual
comment-form markup.

### Is this compatible with WooCommerce?

Yes. The free version protects WooCommerce product review forms and declares compatibility
with High-Performance Order Storage (HPOS). SpamJam Pro can also protect WooCommerce
account registration.

### What’s the difference between Free and Pro?

Free focuses on automatic comment and product-review protection. SpamJam Pro adds
registration and third-party form coverage, custom rules, an actionable spam inbox,
targeted blocking, deeper analytics, reporting, multisite synchronization, and white
labeling. Every Pro license includes the complete feature set; licenses differ only
by the number of sites covered.

### How does geographic blocking work?

SpamJam Pro can block comments from selected country codes. When enabled, SpamJam
uses an external IP geolocation lookup and caches the result to reduce repeat requests.

### What is rate limiting?

Rate limiting caps how many comment submissions one IP address can make during a
configurable period. It helps contain bursts without changing the experience for
ordinary commenters.

### Can I see what spam was blocked?

SpamJam Pro adds a searchable inbox for blocked events, reasons, sources, and review
status. You can configure retention and choose whether to keep the minimum recovery
data needed to restore a false-positive comment.

### Does this work with other anti-spam plugins?

It may, but running multiple plugins that modify or validate the same comment form
can create duplicate checks or conflicts. Test the combination on a staging site
and avoid overlapping protection where possible.

### Will SpamJam block legitimate comments?

No anti-spam system can promise zero false positives. SpamJam reduces the risk by
combining several signals and holding suspicious edge cases for moderation when 
appropriate. SpamJam Pro adds false-positive review and recovery tools.

### Do you offer support?

Free users can use the WordPress.org support forum. SpamJam Pro customers can contact
priority support.

### Is my data sent to third parties?

Core comment detection runs locally and does not require sending comment content
to a remote scoring API. Optional features may connect to external services, and
optional logs are stored in your WordPress database. See the Privacy & Data Handling
section above and assess the settings you enable for your own privacy requirements.

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“SpamJam – Anti-Spam Protection for Comments & Forms” is open source software. The
following people have contributed to this plugin.

Contributors

 *   [ Matt Biscay ](https://profiles.wordpress.org/skyminds/)

[Translate “SpamJam – Anti-Spam Protection for Comments & Forms” into your language.](https://translate.wordpress.org/projects/wp-plugins/spamjam)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/spamjam/), check out
the [SVN repository](https://plugins.svn.wordpress.org/spamjam/), or subscribe to
the [development log](https://plugins.trac.wordpress.org/log/spamjam/) by [RSS](https://plugins.trac.wordpress.org/log/spamjam/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 3.1.0 – 2026-08-09

 * UI – Introduced the shared Utopique admin layout with consistent headers, tabs,
   cards, headings, descriptions, and license presentation.
 * UI – Improved the Spam Inbox placement, settings save flow, dashboard cards, 
   and responsive settings layout.
 * Security – Expanded author-name heuristics, registered-name impersonation protection,
   comment surface hardening, and recovery controls.
 * Compatibility – Added native controls for website-field removal, pingbacks, trackbacks,
   self-pings, and pingback discovery headers.
 * Quality – Added field descriptions throughout the settings interface and expanded
   release integration coverage.

#### 3.0.0 – 2026-08-02

 * Pricing – Consolidated all paid features into one SpamJam Pro feature set; license
   options now differ only by site allowance
 * UI – Replaced the four-tier comparison with a concise Free-versus-Pro comparison
   and removed paid-tier upsells
 * Major – Universal form protection for Contact Form 7, WPForms, Gravity Forms,
   Elementor Forms, Fluent Forms, Formidable Forms, Ninja Forms, and WooCommerce
   registration
 * Major – Actionable spam inbox with search, source/status filters, bulk operations,
   false-positive tracking, allowlisting, deletion, and safe comment restoration
 * Major – Advanced source-aware rules supporting allow, moderate, block, and discard
   actions
 * Major – Expanded analytics with daily trends, previous-period comparisons, protected-
   source breakdowns, and accuracy signals
 * Major – Weekly HTML reports with delivery diagnostics and secure, dependency-
   free PDF exports
 * Privacy – Optional minimal recovery payload; passwords, nonces, tokens, CAPTCHA
   values, and CSRF fields are never retained
 * Database – Versioned schema adds event source, review status, recovery payload,
   and restored-comment tracking

## Meta

 *  Version **3.1.0**
 *  Last updated **3 nädalat ago**
 *  Active installations **100+**
 *  WordPress version ** 6.2 or higher **
 *  Tested up to **7.1**
 *  PHP version ** 7.4 or higher **
 *  Language
 * [English (US)](https://wordpress.org/plugins/spamjam/)
 * Tags
 * [comment spam](https://et.wordpress.org/plugins/tags/comment-spam/)[honeypot](https://et.wordpress.org/plugins/tags/honeypot/)
   [registration spam](https://et.wordpress.org/plugins/tags/registration-spam/)
   [security](https://et.wordpress.org/plugins/tags/security/)[spam protection](https://et.wordpress.org/plugins/tags/spam-protection/)
 *  [Advanced View](https://et.wordpress.org/plugins/spamjam/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/spamjam/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/spamjam/reviews/)

## Contributors

 *   [ Matt Biscay ](https://profiles.wordpress.org/skyminds/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/spamjam/)

## Donate

Would you like to support the advancement of this plugin?

 [ Donate to this plugin ](https://www.paypal.com/cgi-bin/webscr?cmd=_s-xclick&hosted_button_id=DNSC3NVBWR66L)