Category: WordPress

  • Prevent for User Enumeration on WordPress

    Prevent for User Enumeration on WordPress

    I’m happy to announce option Prevent collecting of authors logins which you can find under settings,

    WordPress console -> Settings -> Security by CleanTalk -> General Settings

    This option disables users IDs enumeration in your WordPress. So, it stands against brute force for authors names. Here is example how the enumeration works in the plain WordPress,

    https://blog.cleantalk.org/?author=1

    By executing such links, an attacker brute forces users list on a site to get valid IDs and use it in further attacks.

    If you turn option Prevent collecting of authors logins on, the plugin disable enumeration by showing a blank page instead of valid page of author. URL for the blank page like this,

    https://blog.cleantalk.org/author/honeypot_login_1753432662.9124

    That’s it! Drop questions in the comment form down below.

  • Chaty Spam protection for WordPress in 5 minutes

    Chaty Spam protection for WordPress in 5 minutes

    Struggling with spam flooding your Chaty Floating Widget on WordPress? You’re not alone — it’s a common headache. The source of spam are only these two widgets and there is a plugin that protects both of them, and does it without using annoying CAPTCHAs.

    0

    The Anti-Spam by CleanTalk grants cloud protection from spam, is absolutely invisible to users and runs in background. Which might be pretty useful – 300,000+ active installations and 3,000+ reviews on WordPress can’t lie. It contains many features such as logging for your control, SpamFirewall, stop words and much more.

    Anti-Spam plugin by CleanTalk

    Step 1: Install the Anti-Spam plugin

    CleanTalk is a powerful plugin that blocks spam silently in the background. It also has direct integration with Chaty Floating Chat and here’s how to set it up:

    1. Firstly, to install the Anti-Spam plugin, go to your WordPress admin panelPluginsAdd New. You can also download it in the WordPress catalog.

      Anti-spam plugin installation
    2. Then enter «СleanTalk» in the search box and click the Install button for «Spam protection, Anti-Spam, FireWall by CleanTalk».

      Anti-spam plugin installation
    3. After installing the plugin, click the «Activate»‎ button.

      Anti-spam plugin installation
    4. After it is done go to the plugin settings and click the «Get Access Key Automatically» button.

      Setting spam protection
    5. Then go to Advanced settings in the right-bottom and find the “Protect external forms” and switch it on. It is needed to protect WhatsApp widget inside Chaty from spam. Then just click the «Save Settings»‎ button.

      Screenshot 2025 07 08 at 12.09.24

    From now Anti-Spam starts protecting all forms on your site including Chaty without any extra setup.


    Step 2: Test Spam Protection of your forms

    Use this simple test to confirm that CleanTalk is active:

    • At first, open your form in an Incognito browser tab
    • Use this test email: st********@*****le.com
    • Submit the form
    1

    If the plugin is working, you’ll see a message that the submission was blocked. That means the Anti-Spam plugin now filters our your Chaty spam!

    Important: You must test in Incognito because admins are not blocked by default.


    Enjoy the result!

    If you have any questions, add a comment and we will be happy to help you.

  • WP CLI support in Security by CleanTalk (WordPress plugin)

    WP CLI support in Security by CleanTalk (WordPress plugin)

    We’ve added to Security by CleanTalk support of WP CLI commands. The list of commands,

    • Service setup, including interactions with cloud to get an API key and synchronization.
    • Various settings of the plugin.
    • Settings for templates.
    • Malware scanner commands.

    Full guide with examples is here https://cleantalk.org/help/security-wp-cli

    It works on plugins starting version 2.156 which has been released on May 19, 2025.

    Have questions? Please drop us a message in the comment form down below.

  • Anti-spam protection for WS Form Lite has been released!

    Anti-spam protection for WS Form Lite has been released!

    We have protected one more contact form for WordPress, this is WP Forms lite,

    Anti-Spam by CleanTalk (plugin) protects all kinds of submissions posted through this form against spambots and spam posted by real visitors (with some rate of false/negatives).

    Anyway, to set up the protection follow steps,

    • Download and install WS Form Lite https://wordpress.org/plugins/ws-form/
    • Download and install Anti-Spam by CleanTalk https://cleantalk.org/help/install-wordpress
    • Go to WordPress console -> Settings -> Anti-Spam by CleanTalk.
    • Click ‘GET ACCESS KEY’ button.
    • Wait until the plugin synced data with the cloud.
    • Copy a form short code of from WordPress console -> WS Form -> Forms.
      • For example: [ws_form id=”1″]
    Screenshot 2025 06 16 at 12.46.47 PM
    Screenshot 2025 06 16 at 12.46.47 PM
    • Post the short code in any post/page on your site.
    Screenshot 2025 06 16 at 12.47.05 PM
    Screenshot 2025 06 16 at 12.47.05 PM
    • Go to the page as a regular website visitor (you must be logged out from WordPress console, for example use Anonymous mode in your browser).
    • Test the form with whatever First, Last name and use email st********@****le.com. This is email marked to test “spam” submission.
    • If everything is fine, you have a message,

    *** Forbidden. Sender blacklisted. Anti-Spam by CleanTalk. ***

    Screenshot 2025 06 16 at 12.30.54 PM
    Screenshot 2025 06 16 at 12.30.54 PM

    That’s all. Enjoy spam free website!

  • 5 Best Free WordPress Forms Plugins Protected by CleanTalk Anti-Spam

    5 Best Free WordPress Forms Plugins Protected by CleanTalk Anti-Spam

    top 5 plugins

    How many free WordPress forms are there in the catalog?

    Free WordPress forms are not always 100% free, actually. WordPress catalog has hundreds of form plugins, though. We’ve collected top contact form plugins that are totally free or have a free version, not limited by time period.

    All of the forms are absolutely compatible with Anti-Spam by CleanTalk spam protection giving you peace of mind without captchas or annoying puzzles.

    Here are the top 5 free WordPress form plugins that combine usability with anti-spam protection.

    1. Contact Form 7

    contact form 7

    With over 5 million active installations, Contact Form 7 is a no-frills, lightweight solution trusted by millions. It employs sophisticatedly modularized architecture and its original Schema-Woven Validation technology.

    Features:

    • Fully free and open-source
    • Supports shortcodes and basic customization
    • Original Schema-Woven Validation technology

    Download Contact Form 7 | Protect Contact Form 7 from spam

    2. WPForms Lite

    wpforms

    WPForms Lite is perfect for beginners. The drag-and-drop builder and ready-made templates make it one of the easiest free form plugins available.

    Features:

    • Drag-and-drop interface
    • Mobile-friendly and fast
    • Lots of pre-built form templates

    Download WPForms | Protect WPForms from spam

    3. Ninja Forms

    ninja free wordpress form
    ninja forms

    Ninja Forms offers powerful customization in its free version, and its user-friendly builder is ideal for both beginners and developers.

    Features:

    • Extendable via 40+ add-ons
    • 24+ free drag-and-drop form fields
    • Free email notifications on submission

    Download Ninja Forms | Protect Ninja Forms from spam

    4. Everest Forms

    everest

    Everest Forms is a lightweight yet powerful form plugin with a clean interface and plenty of flexibility – even in the free version.

    Features:

    • Pre-designed templates
    • Easy drag-and-drop form builder
    • A great number of features in free plan

    Download Everest Forms | Protect Everest Forms from spam

    5. Fluent Forms

    fluent

    Fluent Forms is designed to be fast, lightweight, and easy to use. The free version comes packed with features that are premium in other plugins.

    Features:

    • Fast loading and responsive
    • Multiple templates included
    • Includes payment, quiz and calculator forms

    Download Fluent forms | Protect Fluent forms from spam

    Why use CleanTalk for free WordPress forms

    Free WordPress form plugins need to be protected not least then the others. The right anti-spam solution for your forms not only protects your form from spam emails and messages, but also:

    • Won’t make your visitors struggle with CAPTCHAs or puzzles;
    • Protects all your forms on the site at once;
    • Protects your site from spam bots even before they reach it;
    • Is set up with no coding needed.

    But don’t just take our word for it, check it out for yourself at cleantalk.org!

  • CleanTalk Gravity Forms false/positive research

    CleanTalk Gravity Forms false/positive research

    We are happy to remind all our customers that we implemented a reliable Anti-Spam protection for the Gravity Forms plugin a long time ago:

    To date, the plugin has filtered a huge amount of spam messages on Gravity Forms and made many people a little happier.

    We are constantly monitoring the protection quality of our Anti-Spam plugin, and recently, we found a review on WordPress where our customer reported some issues with Gravity Forms protection:

    https://wordpress.org/support/topic/finally-348

    The problem was that some submissions were mistakenly blocked. The common reason for false/positives is incorrectly detected request parameters. This can happen due to the following:

    – Specific website plugins and their settings

    – Specific website themes

    – JavaScript errors on a website 

    We started our investigation. Our Technical Support team reviewed all support requests related to Gravity Forms over the last few months and found no issues. 

    Our engineers have also reviewed the feedback in the plugin’s requests from our customer. There was nothing to analyze either. But that was not enough to stop our investigation, and we took further action. We ran additional tests in our environment and checked the protection with different plugin settings. The protection worked perfectly, all data was accurately extracted and sent correctly. 

    We can confirm that the default plugin settings are optimal for protecting Gravity Forms, and there is no need to change them unless absolutely necessary.

    Based on our investigation, we haven’t found any common problems with Gravity Forms protection. Possible false/positives are individual; if you are experiencing any issues with the Anti-Spam plugin, we strongly recommend contacting our support team. Please mark requests for us using this guide and contact us at su*****@*******lk.org or use our private Ticket System.

    To find a solution, our support team will do additional tests and analyze the request parameters. 

    Your feedback helps us become better every day!

  • Spam protection is available for HubSpot and Leaky Paywall

    Spam protection is available for HubSpot and Leaky Paywall

    I’m glad to announce our experienced developers added spam protection to Anti-Spam by CleanTalk for Leaky Paywall and HubSpot users!

    The protection works in this way,

    To active protection for both services, simply install Anti-Spam by CleanTalk for WordPress,
    https://cleantalk.org/help/install-wordpress

    Make sure you are using at least 6.50 version of our plugin.

    Have any questions? Drop a message in the comment form down below!

    Have fun in promoting your business online!

  • Brave forms spam protection for WordPress

    Brave forms spam protection for WordPress

    CleanTalk added spam protection for Brave Forms using direct form integration. So in case, you prefer using this type of forms be sure to use the most effective Anti-Spam plugin. Read the guide below and learn 4 steps to protect all your contact forms from spam.

    Once the CleanTalk Anti-Spam plugin is installed it starts to protect all of the existing forms on your WordPress website. It may not only be Brave Forms but also many others.

    Download CleanTalk Anti-Spam plugin | Download Brave Builder 

    How to install CleanTalk Anti-Spam plugin

    To install the Anti-Spam plugin, go to your WordPress admin panelPluginsAdd New.

    Then enter «CleanTalk» in the search box and click the Install button for «Spam protection, Anti-Spam, FireWall by CleanTalk».

    After installing the plugin, click the «Activate»‎ button.

    After it is done go to the plugin settings and click the «Get Access Key Automatically» button. Then just click the «Save Settings»‎ button.

    That’s it! From now you How to completely protect your Contact Forms from spam.

    How to check Brave Forms Spam Protection

    You can test the work of Anti-Spam protection for your Contact Forms by using a test email s @ cleantalk.org (without spaces). First, open the form in an Incognito browser tab. Fill in all the required form fields and send a form. After submitting the form, you will see a block message about the block on the form submission.

    brave
    brave

    If you have any questions, add a comment and we will be happy to help you.

    Create your CleanTalk account – Register now and protect your Contact Forms from spam in 5 minutes

    Update

    The protection works only for website visitors, not for website admins. Be sure to test the form protection using Incognito mode.

    Additional features

    • CleanTalk protects all forms at once: comments, registrations, feedbacks, contacts, reviews.
    • Installation takes about 1-2 minutes.
    • Smart 99% protection against spambots.
    • Always online – 24/7 technical support.
    • Logs, SpamFireWall, personal lists, country filters, stop-words, and many others.

    Discover the complete list of CleanTalk Anti-Spam plugin features here.

  • FiboSearch Spam Protection

    FiboSearch Spam Protection

    CleanTalk added spam protection for FiboSearch Search Forms for WooCommerce in the CleanTalk Anti-Spam plugin using direct form integration. So in case, you prefer using search forms be sure to use the most effective Anti-Spam plugin. Read the guide below and learn 4 steps to protect all your contact forms from spam.

    Once the CleanTalk Anti-Spam plugin is installed it starts to protect all of the existing forms on your WordPress website. It may not only be FiboSearch but also many others.

    Download CleanTalk Anti-Spam plugin | Download FiboSearch 

    How to install CleanTalk Anti-Spam plugin

    To install the Anti-Spam plugin, go to your WordPress admin panelPluginsAdd New.

    Then enter «CleanTalk» in the search box and click the Install button for «Spam protection, Anti-Spam, FireWall by CleanTalk».

    After installing the plugin, click the «Activate»‎ button.

    After it is done go to the plugin settings and click the «Get Access Key Automatically» button. Then just click the «Save Settings»‎ button.

    That’s it! From now you How to completely protect your FiboSearch from spam.

    banner 1544x500

    If you have any questions, add a comment and we will be happy to help you.

    Create your CleanTalk account – Register now and protect your Contact Forms from spam in 5 minutes

    Additional features

    • CleanTalk protects all forms at once: comments, registrations, feedback, contacts and reviews.
    • Installation takes about 1-2 minutes.
    • Smart 99% protection against spambots.
    • Always online – 24/7 technical support.
    • Logs, SpamFireWall, personal lists, country filters, stop-words, and many others.

    Discover the complete list of CleanTalk Anti-Spam plugin features here.

  • Protecting Your WordPress Website: A Backup Guide

    Protecting Your WordPress Website: A Backup Guide

    A robust backup strategy for any WordPress website is compulsory to store important content and keep the business running in case anything goes wrong. This guide reviews the best practices for WordPress backup and reviews some of the top-rated WordPress backup plugins to simplify the process.

    Automated WordPress Backup: The Power of Plugins

    Consider the WordPress backup plugin for a better, more efficient, and more reliable solution. These plugins will automate backing up for you, even on a schedule, and quite often provide extra features, such as:

    • Restore your entire site to a previous point in time with just one click.
    • Store backups safely off-site to safeguard against server failures.
    • Receive notifications for successful or failed backups.
    • The only backup changes since the last backup have been saving storage space.

    Example of WordPress Backup Plugin: WPvivid

    WPvivid is a highly rated plugin that offers a wide range of WordPress backup and restoration options. It’s user-friendly and offers peace of mind knowing your site is safe.

    How to Use WPvivid

    Installation

    1. Login to your WordPress dashboard.
    2. Go to Plugins > Add New.
    3. Search for “WPvivid Backup”
    4. Install the plugin.
    5. Activate the plugin.

    First Backup:

    1. Go to WPvivid > Backup & Restore.
    2. Click Backup Now.
    1. Go to WPvivid > Schedule.
    2. Set up a regular schedule of automated backup.
    3. Click Save Changes.

    Restore Your Site:

    1. Go to WPvivid > Backup.
    2. Choose the backup you want to restore.
    3. Click Restore.

    Extra Tips:

    • Test Your Backups: Regularly restore your site from a backup to make sure it’s working correctly.
    • Keep Multiple Backups: Keep multiple backups to be safe from data loss. Secure Your Backups: If you’re storing backups off-site, use strong passwords and encryption. 
    • Monitor Your Backups: Keep an eye on your backup schedule and storage usage.
    • Regular Backups: Set up regular backups, preferably daily or weekly. 
    • Offsite Storage: Store backups off-site to protect against local disasters. 
    • Test Restores: Periodically test restoring your site from backups to ensure they are working.
    • Secure Backups: Protect backups with strong passwords and encryption.

    With these best practices in place and by using a reliable WordPress backup plugin, you can all but secure your WordPress site and minimize the possible disasters to the barest minimum.

    More WordPress Guides: