Protect private conversations in Better Messages from spam and scam attempts with rate limits, contact filters, bot detection and safety warnings. Every module is optional and configurable.
Spam protection has become more difficult.
Modern bots do not always behave like obvious bots. Some can complete registration forms, work with automated browsers and behave enough like a normal visitor to get through basic anti bot measures. CAPTCHAs can help, but they are not a complete solution either.
There is another problem with private communities: most protection stops at the login or registration stage.
A bot may create an account in a relatively human way, wait until the account is accepted and then let automation take over. Once logged in, it can start sending private messages to other members without passing through the same protections that were used during registration.
This plugin was built specifically for that part of the problem.
It adds protection to the private messaging activity itself. Instead of relying on a single CAPTCHA or trying to identify every possible bot, it looks at behaviour and message patterns inside Better Messages.
That includes things such as:
The goal is not to find one perfect way to identify a bot. It is to make automated abuse harder at the point where it actually happens.
The plugin comes with sensible defaults, but every community is different. Use Log only to see how the rules behave on your own site before deciding what you want to block.
This plugin was built to solve a real problem.
The site it was built for is a friendly community where members can chat privately with each other. Registration was already protected, comment forms were covered and public spam was under control. Yet new accounts kept appearing in private inboxes with the same opening lines, the same stories and the same requests to continue the conversation on another messenger platform.
Blocking one account only meant another would appear. Blocking a keyword was easy to work around and deleting one scam conversation did not stop the same message from being sent to other members. Bots also respected the message delay that can be configured in Better Messages and simply adjusted their behaviour to stay within that limit. Slowing messages down therefore did not stop them. It only made the automated activity look more like normal user behaviour.
Most anti spam plugins are designed for comments, forms and public content. They do not address what happens inside a real-time private chat.
That is why this plugin was built around the actual problems encountered on a live community.
The features were developed from real situations, tested against real examples and refined through use. The defaults are based on observed behaviour rather than theoretical scenarios. Detection rules have also been tested against both common scam patterns and normal messages that should not trigger a filter. The result is a plugin that works with sensible defaults but can also be adjusted to fit your own community.
Please treat this plugin as a free resource for the community.
Three principles guide the plugin:
New accounts are often used to send messages at scale.
You can set:
Replies in existing conversations are not limited. A new member can still have a normal conversation with someone they have already contacted.
Detect e mail addresses, phone numbers and links in private messages.
Each type can independently be set to:
The default detection covers common local and international phone formats, e mail addresses, bare domains and common messenger invite links.
Phone prefixes can be configured for your own country.
The detection rules have been tested against legitimate content too, including dates, file names and version numbers.
Add your own messenger or service patterns to the link filter.
This is useful for services that are specific to your region or community, such as Zalo, LINE or KakaoTalk.
Patterns are matched case insensitively. You only need to enter the pattern itself. You do not need to add https://.
Use an editable keyword list to detect mentions of services such as WhatsApp, Telegram, Snapchat, Instagram, Discord, Kik, Viber, WeChat and Signal. Add one word or phrase per line and choose Block, Log only or Off. You can apply the filter to all accounts or only new accounts and optionally temporarily lock an account after repeated matches within a configurable retention window. Because keyword matching is less precise than the contact filter, Log only is recommended when setting it up.
Detect copy and paste spam across conversations.
The plugin counts identical messages per user within a configurable time window. Both the message threshold and the time window are configurable.
The check works across all conversations, so sending the same message to many different members still counts.
For established members, sharing an e mail address or phone number can trigger a confirmation step. The first message is held back and the member sees a short warning, giving them a moment to consider why the other person may be asking for their private details. If they send the exact same message again within the confirmation window, it is delivered. New accounts are handled by the new account rules instead.
When a very new account shares an e mail address or phone number, the other participant automatically sees a short safety warning in the conversation. It reminds them to be careful when a new member quickly asks to move the conversation elsewhere or requests private contact details. Nothing is blocked and the sender does not see the warning. The aim is to give members a moment to recognise a potentially risky pattern before sharing their own details. The warning threshold and message are configurable.
Receive an e mail when the plugin detects a signal such as contact information, a new account limit or duplicate messages.
Alerts can be enabled separately for each signal type.
A cooldown prevents one active account from generating a large number of identical alerts.
Alerts contain information about who triggered the signal, what was detected and when it happened. They do not contain the message itself.
Some automated browsers try to look like normal browsers. This check looks for a few clear inconsistencies that can reveal automation.
It can detect:
The check only acts on clear signals. Missing client hints are not treated as suspicious, since browsers such as Safari, Firefox and iOS may not send them at all. The Windows version check only applies when the relevant Windows values are present. Other browsers and operating systems are not affected.
Use Log only first to see what the check detects on your site before enabling Block.
Optionally add Cloudflare Turnstile for invisible bot verification.
Members do not see a puzzle or checkbox. The verification runs in the background. Users who actively block Turnstile with a privacy extension get a friendly notification to allow Cloudflare to run in order to send messages.
Turnstile requires Cloudflare keys and is completely optional. The other modules work without Cloudflare.
In older versions of Better Messages, when a message is rejected, the message editor is normally cleared.
This module restores the text so the member can edit it and try again without having to retype everything.
Enable this optional module only while you are still running an older version of Better Messages. It can also still be useful to enable when blocking certain words, as it gives people a chance to change their input.
Add user IDs that should bypass all checks. This is useful for testing and for moderators who should not be affected by new account limits.
The plugin can write its decisions to the PHP error log using [BMSG] entries.
The log shows who triggered a signal, which signal was detected and what action was taken.
Message content is never written to the log.
This makes Log only mode useful for tuning the settings based on what actually happens on your site.
The guard is designed to add as little overhead as possible. Each module only runs when it is relevant, and checks exit early when there is nothing to process. Front end scripts and styles are loaded only when needed, while counters and temporary data use lightweight cached storage.
The result is a guard that protects private messages without adding unnecessary work to the rest of your site.
The plugin has been thoroughly tested in both automated tests and a live community. The detection rules, duplicate detection, admin interface and individual modules are all covered by testing.
There are more than 90 automated assertions, all passing before a release. The plugin has also been tested against real scam attempts and normal user behaviour.
The features were developed from real situations, tested against real examples and refined through use.
This plugin includes an optional Cloudflare Turnstile anti-spam module. It is disabled by default and does nothing until an administrator enables it in the plugin settings.
When enabled, the plugin:
Turnstile is an interactive security service: when active, visitor interaction with the widget is processed by Cloudflare under Cloudflare’s own terms and privacy policy. No message content is sent to Cloudflare; only the widget token is verified.
The widget script and server-side verification are provided by Cloudflare, Inc.:
* Cloudflare Terms of Service: https://www.cloudflare.com/terms/
* Cloudflare Privacy Policy: https://www.cloudflare.com/privacypolicy/
anti-spam-guard-for-better-messages.zip and click Install Now, then Activate.No settings are required. The plugin remains inactive until you enable a module.
This plugin is released under the GPL v2 license to comply with WordPress plugin guidelines.
Developed by Butterfly88