FormGhost

FormGhost

Details
View on WordPress

The spam never happened. FormGhost is a privacy-first WordPress antispam plugin that makes spam quietly disappear: bots are shown a fake success page and walk away believing they got through, while you never receive a thing. No CAPTCHA is ever shown, no data leaves your server, and no personally identifiable information is kept on disk. Spam goes into the Vault. Real users never see anything.

Every feature is free. There is no Pro version, no license key, no upsell.

Why FormGhost

  • No CAPTCHAs. No “select all the buses.” No “I’m not a robot” checkbox.
  • No cloud dependency — the spam detection itself makes no external HTTP calls. The only optional exceptions (CAPTCHA verification, MX lookup) are off by default and documented under External services.
  • GDPR / DSGVO friendly. IP addresses are hashed with a per-site secret before storage. Form payloads are encrypted (AES-256-GCM) in the vault.
  • Ghost Response: bots see a fake success message and walk away thinking the submission worked. You never get the email.
  • Blocked something legitimate? Open it in the Vault and forward it to the inbox it was headed to with one click.

How it works

Every submission is graded by up to nine independent layers. Each layer adds a small score. When the total crosses the configured threshold, FormGhost takes action — usually a silent Ghost Response, so the bot never learns it was blocked.

  1. Honeypot — Daily-rotated, site-suffixed hidden fields. Different on every FormGhost site; resistant to “fill every field” bots.
  2. Timing — Encrypted submission timestamp. Submissions that arrive too fast (or with a replayed token) fail this layer.
  3. Proof-of-Work — Lightweight browser challenge solved by a WebWorker. Stops curl / wget / scripted submissions cold.
  4. Behavioral fingerprint — Mouse curvature, keystroke variance, scroll, focus and touch signals computed entirely in the browser. Only the resulting score is transmitted.
  5. Rate limiting — Per-IP and per-form submission caps with sliding windows and CIDR-aware whitelisting.
  6. Disposable email detection — Curated disposable-domain blocklist (extensible with your own block/allow lists), optional MX heuristic.
  7. Content patterns — Casino / SEO / pharma phrase detection with a self-learning twist.
  8. WordPress hardening — Disable XML-RPC, harden the REST users endpoint, generic login errors, optional Application Passwords lockdown.
  9. Optional CAPTCHA — Turnstile / hCaptcha / ALTCHA on the core WordPress forms you choose (comments, login, registration, password reset) if you want a visible challenge as a last line of defence. Off by default.

Form plugin compatibility

Built-in adapters for:

  • WordPress core comments, login, registration, password-reset
  • Contact Form 7
  • WPForms
  • Gravity Forms
  • Elementor Pro Forms
  • WooCommerce checkout & registration
  • Fluent Forms
  • Ninja Forms
  • Formidable Forms
  • Forminator
  • HTML Forms
  • Jetpack Forms
  • Bricks Builder forms
  • Kadence Blocks forms
  • Divi contact forms
  • BuddyPress signup & activity
  • bbPress topics & replies

Custom forms POSTing to wp-admin/admin-post.php or wp-admin/admin-ajax.php are picked up automatically by the generic adapter.

The Vault

Blocked submissions are stored encrypted for 30 days (configurable). Review them in the admin: see what was blocked, which page it was submitted from, and which inbox the notification was headed to. Mark false positives as legitimate and forward them by email with one click — the sender’s address becomes the Reply-To, so answering in your mail client reaches the person who filled the form. Passed (legitimate) submissions are logged too, so you can audit both sides of every decision.

Self-learning

When you mark a Vault entry as “spam” the engine extracts the email domain / content phrase signatures and stores them in a learned-rules table with a score modifier. Future submissions matching those signatures get extra points, automatically. Auto-confirmed rules from repeat offenders are added too. Decay over time keeps the rule set fresh. Review, re-weight, deactivate or delete every learned rule from the Learned Rules screen.

Privacy

  • The nine detection layers, the Vault and the self-learning system run entirely on your server. Two optional, off-by-default features talk to the outside: CAPTCHA verification (Cloudflare Turnstile / hCaptcha) and the DNS MX check — see “External services” below.
  • IPs are stored only as sha256(site_secret + "|" + ip) and cannot be recovered.
  • Vault payloads are encrypted at rest with AES-256-GCM (authenticated encryption).
  • Uninstalling the plugin removes every option, every table and every cron event. Nothing is left behind.

External services

FormGhost’s spam detection runs entirely on your own server. Two optional features, both off by default, connect to third parties. Nothing is sent unless you enable them in the settings.

Cloudflare Turnstile (Layer 9, optional CAPTCHA provider)
When you enable the CAPTCHA layer with Turnstile for a form, the plugin renders the widget container on that form (you add Cloudflare’s widget script https://challenges.cloudflare.com/turnstile/v0/api.js to your site yourself — the plugin does not load any vendor script), and on every submission of that form the plugin sends the widget’s response token, your Turnstile secret key and the visitor’s IP address to https://challenges.cloudflare.com/turnstile/v0/siteverify to verify the challenge.
Terms: https://www.cloudflare.com/terms/ — Privacy: https://www.cloudflare.com/privacypolicy/

hCaptcha (Layer 9, optional CAPTCHA provider)
When you enable the CAPTCHA layer with hCaptcha for a form, the plugin renders the widget container on that form (you add hCaptcha’s widget script https://js.hcaptcha.com/1/api.js to your site yourself — the plugin does not load any vendor script), and on every submission of that form the plugin sends the widget’s response token, your hCaptcha secret key and the visitor’s IP address to https://api.hcaptcha.com/siteverify to verify the challenge.
Terms: https://www.hcaptcha.com/terms — Privacy: https://www.hcaptcha.com/privacy

ALTCHA (Layer 9, optional CAPTCHA provider) is self-hosted: the challenge endpoint and the verification run on your server (admin-ajax.php?action=formghost_altcha_challenge); no data is sent anywhere. You add the ALTCHA widget script to your site yourself.

DNS MX lookup (Layer 6, optional “Check MX records” setting)
When enabled, the plugin asks your server’s DNS resolver for the MX records of the submitted email address’s domain (PHP getmxrr). This is a standard DNS query from your server, not a request to a third-party API; the email address itself is not transmitted, only its domain.

Privacy

FormGhost is designed for privacy-conscious operators.

Data stored on your server.

  • {prefix}formghost_vault — encrypted form payloads of blocked / passed submissions plus sha256(IP + site_secret) and sha256(User-Agent + site_secret) hashes. AES-256-GCM authenticated encryption keyed off the per-site secret. Configurable retention (default 30 days). Removed on uninstall.
  • {prefix}formghost_learned_rules — score modifiers learned from admin review and auto-confirmation. A rule may hold the sender email address of a submission you reviewed, or an IP stored only as sha256(IP + site_secret). Rules decay when stale and can be deleted from the Learned Rules screen. Removed on uninstall.
  • {prefix}formghost_log — block / pass counters per layer per form type for the dashboard. No PII. Removed on uninstall.
  • formghost_site_secret (option) — 64-char random secret used for IP / UA hashing, payload encryption and CSS class derivation. Removed on uninstall.

Data sent off your server. None by default. Only the optional services listed under “External services” send anything, and only after you enable them.

Cookies. FormGhost does not set cookies.

For full source, audit, and integration docs, see https://byabdalla.com/lab/formghost.

Details

Plugin code:
formghost
Plugin version:
1.2.4
Author:
Outdated:
No
WP version:
6.0 or higher
PHP version:
7.4 or higher
Test up to WP version:
7.1.1
Total installations:
0
Last updated:
2026-09-17
Rating:
Times rated:
0
antispam
captcha-alternative
gdpr
honeypot
spam