Data443 Anti-Spam extracts every URL from a comment and classifies it against the Data443 classification API. A comment linking to malware, phishing, or another flagged category is held for moderation or sent straight to spam — your choice. The verdict comes from live URL classification, so there are no keyword rules to maintain and no local list of bad words.
What it does
Requirements
The Data443 classification API is a paid service with a free 30-day trial. A card is required to start the trial, but nothing is charged during it: cancel before the 30 days are up and you are charged nothing at all, and after that you can cancel any time. The endpoint comes filled in and subscribing is two clicks — the credentials install themselves, with nothing to copy or paste. Until the site is subscribed nothing is evaluated and WordPress moderates comments exactly as before.
Multisite
Runs per site. Each site has its own endpoint, subscription, settings and results, and one subscription covers one site. There is no network settings screen and nothing for a network administrator to do.
The plugin sends the URLs found in comments and Contact Form 7 submissions to https://websecjd-rest.data443.io/ to have them classified, and uses the same service to set up and manage this site’s subscription. The classification is what decides whether a comment is spam, so the plugin cannot do its job without it. Clearing the API Endpoint setting stops every request below.
What is sent, and when:
https://example.com/, as a probe — when an administrator clicks Check Connection.https://keycloak.data443.io/ — whenever the cached token expires.This service is provided by Data443 Risk Mitigation, Inc.: terms of service / EULA, terms for support and maintenance services, privacy policy.
Subscribing and managing billing open Stripe-hosted pages in the administrator’s browser, and Stripe reports the resulting subscription status back to Data443. The purchaser gives Stripe an email address, card details and whatever billing information Stripe requires; the plugin neither sees nor stores any of it. Nothing reaches Stripe unless an administrator opens one of those pages.
This service is provided by Stripe, Inc.: consumer terms of service, Stripe services agreement, privacy policy.