[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f_WrJRL5pQ2uiYsB-jN77jvwpRqBgVrnuy6IK7eX60Lk":3,"$fXxaZ7tAhtefpNEEXke24tcZs0VNsRnlLUW8lifNcXYY":380,"$f0ygfClb82Po-NZTAR1Msa7zGdyJ1pYHHENcKMwq0QgI":384},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":14,"last_updated":15,"tested_up_to":16,"requires_at_least":17,"requires_php":18,"tags":19,"homepage":25,"download_link":26,"security_score":13,"vuln_count":27,"unpatched_count":27,"last_vuln_date":28,"fetched_at":29,"discovery_status":30,"vulnerabilities":31,"developer":32,"crawl_stats":28,"alternatives":36,"analysis":141,"fingerprints":356},"spambanana-ai-spam-protection","SpamBanana – AI Spam Protection","1.0.6","famaserver","https:\u002F\u002Fprofiles.wordpress.org\u002Ffamaserver\u002F","\u003Cp>SpamBanana uses advanced Machine Learning (Logistic Regression + TF-IDF) to detect spam comments. Accuracy improves over time with admin feedback, reaching up to 99% after 2M feedbacks. No annoying CAPTCHAs needed!\u003C\u002Fp>\n\u003Ch4>Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>AI-Powered Detection with Machine Learning\u003C\u002Fli>\n\u003Cli>Accuracy improves over time (up to 99% with feedback)\u003C\u002Fli>\n\u003Cli>Real-time Dashboard with Statistics\u003C\u002Fli>\n\u003Cli>GeoIP Country Blocking\u003C\u002Fli>\n\u003Cli>Admin Feedback System to improve AI\u003C\u002Fli>\n\u003Cli>No CAPTCHA Required\u003C\u002Fli>\n\u003Cli>Fast & Lightweight\u003C\u002Fli>\n\u003Cli>Secure HMAC-SHA256 Authentication\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>How It Works\u003C\u002Fh4>\n\u003Col>\n\u003Cli>Install and activate the plugin\u003C\u002Fli>\n\u003Cli>Get your free API keys from spambanana.com\u003C\u002Fli>\n\u003Cli>Enter API keys in Settings\u003C\u002Fli>\n\u003Cli>All comments are automatically checked\u003C\u002Fli>\n\u003Cli>Provide feedback to improve AI accuracy\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch4>Admin Feedback System\u003C\u002Fh4>\n\u003Cp>Help improve the AI by providing feedback on spam detection:\u003Cbr \u002F>\n* Mark false positives as “Not Spam”\u003Cbr \u002F>\n* Mark false negatives as “Spam”\u003Cbr \u002F>\n* AI learns from your feedback\u003Cbr \u002F>\n* Accuracy improves over time\u003C\u002Fp>\n\u003Ch4>GeoIP Blocking\u003C\u002Fh4>\n\u003Cp>Block spam by country:\u003Cbr \u002F>\n* Real-time IP geolocation\u003Cbr \u002F>\n* Select countries to block\u003Cbr \u002F>\n* Cached for performance\u003C\u002Fp>\n\u003Ch4>Dashboard & Statistics\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Total comments checked\u003C\u002Fli>\n\u003Cli>Spam blocked count\u003C\u002Fli>\n\u003Cli>Daily trends (7-90 days)\u003C\u002Fli>\n\u003Cli>Top spam sources\u003C\u002Fli>\n\u003Cli>Beautiful charts\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>External Services\u003C\u002Fh3>\n\u003Cp>This plugin relies on external services to provide spam detection and geolocation features. Below is detailed information about each service:\u003C\u002Fp>\n\u003Ch4>SpamBanana API (api.spambanana.com)\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>What it does:\u003C\u002Fstrong> Analyzes comments using Machine Learning (Logistic Regression + TF-IDF) to detect spam.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>When data is sent:\u003C\u002Fstrong> Every time a comment is submitted on your WordPress site (unless the user is logged in and you’ve disabled checking for logged-in users).\u003C\u002Fp>\n\u003Cp>\u003Cstrong>What data is sent:\u003C\u002Fstrong>\u003Cbr \u002F>\n* Comment content (text)\u003Cbr \u002F>\n* Comment author name\u003Cbr \u002F>\n* Comment author email\u003Cbr \u002F>\n* Comment author IP address\u003Cbr \u002F>\n* Comment author website URL (if provided)\u003Cbr \u002F>\n* User agent string\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Why it’s needed:\u003C\u002Fstrong> WordPress servers have limited resources. By processing spam detection on our dedicated ML servers, we:\u003Cbr \u002F>\n* Reduce load on your WordPress server\u003Cbr \u002F>\n* Provide faster spam detection\u003Cbr \u002F>\n* Use advanced Machine Learning models that would be too resource-intensive to run locally\u003Cbr \u002F>\n* Continuously improve accuracy through centralized learning from millions of comments\u003Cbr \u002F>\n* Reduce AI costs for users by sharing infrastructure\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Data retention:\u003C\u002Fstrong> Comment data is stored temporarily for analysis and learning. Spam detection results are kept to improve the ML model accuracy over time.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Privacy & Terms:\u003C\u002Fstrong>\u003Cbr \u002F>\n* Service Terms: https:\u002F\u002Fspambanana.com\u002Fterms\u003Cbr \u002F>\n* Privacy Policy: https:\u002F\u002Fspambanana.com\u002Fprivacy\u003Cbr \u002F>\n* The service is GDPR compliant\u003Cbr \u002F>\n* No personal data is sold or shared with third parties\u003C\u002Fp>\n\u003Ch4>IP-API.com (ip-api.com)\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>What it does:\u003C\u002Fstrong> Provides geolocation data (country) based on IP addresses for the GeoIP blocking feature.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>When data is sent:\u003C\u002Fstrong> Only when GeoIP blocking is enabled in settings, and only for new IP addresses not in cache (cached for 7 days).\u003C\u002Fp>\n\u003Cp>\u003Cstrong>What data is sent:\u003C\u002Fstrong>\u003Cbr \u002F>\n* Visitor’s IP address only\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Why it’s needed:\u003C\u002Fstrong> To identify the country of origin for comments, allowing you to block spam from specific countries if desired.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Privacy & Terms:\u003C\u002Fstrong>\u003Cbr \u002F>\n* Service website: http:\u002F\u002Fip-api.com\u003Cbr \u002F>\n* Terms of Service: https:\u002F\u002Fip-api.com\u002Fdocs\u002Flegal\u003Cbr \u002F>\n* This is a free service with rate limiting (45 requests per minute)\u003C\u002Fp>\n\u003Ch3>Privacy Policy\u003C\u002Fh3>\n\u003Cp>\u003Cstrong>User Data Protection:\u003C\u002Fstrong>\u003Cbr \u002F>\n* All data transmission uses secure HTTPS connections\u003Cbr \u002F>\n* Data is only sent when actively processing comments\u003Cbr \u002F>\n* Users can disable the plugin at any time to stop data transmission\u003Cbr \u002F>\n* GeoIP feature is optional and can be disabled\u003Cbr \u002F>\n* No tracking cookies or scripts are added to your site\u003Cbr \u002F>\n* GDPR compliant\u003C\u002Fp>\n\u003Ch3>Support\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Support: info@famaserver.com\u003C\u002Fli>\n\u003Cli>Support: support@spambanana.com\u003C\u002Fli>\n\u003Cli>Website: https:\u002F\u002Fspambanana.com\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Credits\u003C\u002Fh3>\n\u003Cp>Developed by FamaServer Team\u003Cbr \u002F>\nWebsite: https:\u002F\u002Ffamaserver.com\u003C\u002Fp>\n","AI-powered spam detection for WordPress. Accuracy improves over time, reaching up to 99% with feedback. No CAPTCHA required!",10,267,100,1,"2025-12-04T06:41:00.000Z","6.8.6","5.0","7.4",[20,21,22,23,24],"ai","antispam","comments","spam","spam-protection","https:\u002F\u002Fspambanana.com","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fspambanana-ai-spam-protection.1.0.6.zip",0,null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":7,"display_name":7,"profile_url":8,"plugin_count":14,"total_installs":11,"avg_security_score":13,"avg_patch_time_days":33,"trust_score":34,"computed_at":35},30,94,"2026-08-30T03:54:38.812Z",[37,59,83,107,123],{"slug":38,"name":39,"version":40,"author":41,"author_profile":42,"description":43,"short_description":44,"active_installs":45,"downloaded":46,"rating":47,"num_ratings":48,"last_updated":49,"tested_up_to":50,"requires_at_least":51,"requires_php":52,"tags":53,"homepage":56,"download_link":57,"security_score":13,"vuln_count":14,"unpatched_count":27,"last_vuln_date":58,"fetched_at":29},"antispam-bee","Antispam Bee","2.11.12","pluginkollektiv","https:\u002F\u002Fprofiles.wordpress.org\u002Fpluginkollektiv\u002F","\u003Cp>Say Goodbye to comment spam on your WordPress blog or website. \u003Cem>Antispam Bee\u003C\u002Fem> blocks spam comments and trackbacks effectively, without captchas and without sending personal information to third party services. It is free of charge, ad-free and 100% GDPR compliant.\u003C\u002Fp>\n\u003Ch3>Feature\u002FSettings Overview\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Trust approved commenters.\u003C\u002Fli>\n\u003Cli>Trust commenters with a Gravatar.\u003C\u002Fli>\n\u003Cli>Consider the comment time.\u003C\u002Fli>\n\u003Cli>Allow comments only in a certain language.\u003C\u002Fli>\n\u003Cli>Block or allow commenters from certain countries.\u003C\u002Fli>\n\u003Cli>Treat BBCode links as spam.\u003C\u002Fli>\n\u003Cli>Use regular expressions.\u003C\u002Fli>\n\u003Cli>Search local spam database for commenters previously marked as spammers.\u003C\u002Fli>\n\u003Cli>Notify admins by e-mail about incoming spam.\u003C\u002Fli>\n\u003Cli>Delete existing spam after n days.\u003C\u002Fli>\n\u003Cli>Limit approval to comments\u002Fpings (will delete other comment types).\u003C\u002Fli>\n\u003Cli>Select spam indicators to send comments to deletion directly.\u003C\u002Fli>\n\u003Cli>Optionally exclude trackbacks and pingbacks from spam detection.\u003C\u002Fli>\n\u003Cli>Optionally spam-check comment forms on archive pages.\u003C\u002Fli>\n\u003Cli>Display spam statistics on the dashboard, including daily updates of spam detection rate and a total of blocked spam comments.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Support\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Community support via the \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Fplugin\u002Fantispam-bee\" rel=\"ugc\">support forums on wordpress.org\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Read \u003Ca href=\"https:\u002F\u002Fantispambee.pluginkollektiv.org\u002Fdocumentation\u002F\" rel=\"nofollow ugc\">the documentation\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>We don’t handle support via e-mail, Twitter, GitHub issues etc.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Contribute\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Active development of this plugin is handled \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fpluginkollektiv\u002Fantispam-bee\" rel=\"nofollow ugc\">on GitHub\u003C\u002Fa>.\u003C\u002Fli>\n\u003Cli>Pull requests for documented bugs are highly appreciated.\u003C\u002Fli>\n\u003Cli>If you think you’ve found a bug (e.g. you’re experiencing unexpected behavior), please post at the \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Fplugin\u002Fantispam-bee\" rel=\"ugc\">support forums\u003C\u002Fa> first.\u003C\u002Fli>\n\u003Cli>If you want to help us translate this plugin you can do so \u003Ca href=\"https:\u002F\u002Ftranslate.wordpress.org\u002Fprojects\u002Fwp-plugins\u002Fantispam-bee\" rel=\"nofollow ugc\">on WordPress Translate\u003C\u002Fa>.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Credits\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Author: \u003Ca href=\"https:\u002F\u002Fsergejmueller.github.io\u002F\" rel=\"nofollow ugc\">Sergej Müller\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Maintainers: \u003Ca href=\"https:\u002F\u002Fpluginkollektiv.org\" rel=\"nofollow ugc\">pluginkollektiv\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n","Sophisticated antispam plugin for effective daily comment and trackback spam-fighting. Built with data protection and privacy in mind.",700000,12569870,96,226,"2026-05-29T19:13:00.000Z","7.0.2","4.6","5.2",[54,21,22,55,24],"anti-spam","spam-filter","https:\u002F\u002Fantispambee.pluginkollektiv.org\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fantispam-bee.2.11.12.zip","2023-11-27 00:00:00",{"slug":60,"name":61,"version":62,"author":63,"author_profile":64,"description":65,"short_description":66,"active_installs":67,"downloaded":68,"rating":69,"num_ratings":70,"last_updated":71,"tested_up_to":72,"requires_at_least":73,"requires_php":74,"tags":75,"homepage":79,"download_link":80,"security_score":81,"vuln_count":14,"unpatched_count":27,"last_vuln_date":82,"fetched_at":29},"cryptx","CryptX","4.0.11","Ralf Weber","https:\u002F\u002Fprofiles.wordpress.org\u002Fd3395\u002F","\u003Cp>No more SPAM by spiders scanning your site for email addresses. With CryptX you can hide all your email addresses, with and without a mailto-link, by converting them using javascript or UNICODE.\u003C\u002Fp>\n\u003Cp>CryptX protects your email addresses from spambots while keeping them readable and functional for your visitors. The plugin automatically detects email addresses in your content and encrypts them using various methods including JavaScript encryption, Unicode conversion, and image replacement.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Key Features:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Automatic Email Detection\u003C\u002Fstrong> – Finds and encrypts email addresses in posts, pages, comments, and widgets\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Multiple Encryption Methods\u003C\u002Fstrong> – JavaScript, Unicode, image replacement, and custom text options\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Widget Support\u003C\u002Fstrong> – Works with text widgets and other widget content\u003C\u002Fli>\n\u003Cli>\u003Cstrong>RSS Feed Control\u003C\u002Fstrong> – Option to disable encryption in RSS feeds\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Whitelist Support\u003C\u002Fstrong> – Exclude specific domains from encryption\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Per-Post Control\u003C\u002Fstrong> – Enable\u002Fdisable encryption on individual posts and pages\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Shortcode Support\u003C\u002Fstrong> – Use \u003Ccode>[cryptx]email@example.com[\u002Fcryptx]\u003C\u002Fcode> for manual encryption\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Template Functions\u003C\u002Fstrong> – Developer-friendly functions for theme integration\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Ca href=\"http:\u002F\u002Fweber-nrw.de\u002Fwordpress\u002Fcryptx\u002F\" title=\"Plugin Homepage\" rel=\"nofollow ugc\">Plugin Homepage\u003C\u002Fa>\u003C\u002Fp>\n","No more SPAM by spiders scanning your site for email addresses!",10000,284032,88,19,"2025-12-18T08:01:00.000Z","6.9.5","6.7","8.3",[21,76,77,78,24],"email-encryption","mail","privacy","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fcryptx\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fcryptx.4.0.11.zip",99,"2025-12-04 20:35:36",{"slug":84,"name":85,"version":86,"author":87,"author_profile":88,"description":89,"short_description":90,"active_installs":91,"downloaded":92,"rating":93,"num_ratings":94,"last_updated":95,"tested_up_to":96,"requires_at_least":97,"requires_php":98,"tags":99,"homepage":104,"download_link":105,"security_score":106,"vuln_count":27,"unpatched_count":27,"last_vuln_date":28,"fetched_at":29},"recaptcha-in-wp-comments-form","reCAPTCHA in WP comments form","9.1.2","jmviade","https:\u002F\u002Fprofiles.wordpress.org\u002Fjmviade\u002F","\u003Cp>reCAPTCHA in WP comments form plugin is an \u003Cstrong>ANTISPAM tool\u003C\u002Fstrong> that adds the visible Google \u003Cstrong>reCAPTCHA field\u003C\u002Fstrong> inside the comments form of your WP theme when the user is not logged in preventing fraudulent or deceptive comments.\u003C\u002Fp>\n\u003Cp>The plugin also \u003Cstrong>introduces a second verification process\u003C\u002Fstrong> that detects the unauthorized direct accesses by spam robots to the WP comments system and allows you to decide what do you want to do with those comments.\u003C\u002Fp>\n\u003Cp>Finally, the plugin has got an optional \u003Cstrong>forced javascript output mode\u003C\u002Fstrong> that lets you to add a reCAPTCHA field \u003Cstrong>also in old WP themes\u003C\u002Fstrong> that didn’t use the new WP form comments functions but they make a direct output of its own comments form.\u003C\u002Fp>\n\u003Ch4>FEATURES LIST\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Basic Features\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>All variants\u003C\u002Fstrong> of Google reCAPTCHA field are available\u003C\u002Fli>\n\u003Cli>Two simple steps \u003Cstrong>Installation Wizard\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>Automatic \u003Cstrong>default configuration settings\u003C\u002Fstrong> for all plugin components\u003C\u002Fli>\n\u003Cli>Automatic default configuration for reCAPTCHA field\u003C\u002Fli>\n\u003Cli>Configuration settings for Plugin \u003C\u002Fli>\n\u003Cli>Configuration settings for \u003Cstrong>ANTISPAM operation\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>Four modes of operation in case of spam robots threats (SPAM, TRASH, DELETE or DIE)\u003C\u002Fli>\n\u003Cli>Visual configuration settings for Google reCAPTCHA: theme, size, type, align, language\u003C\u002Fli>\n\u003Cli>Dynamic comments form sample for viewing configuration settings changes\u003C\u002Fli>\n\u003Cli>Visual Help\u003C\u002Fli>\n\u003Cli>RTL Language support\u003C\u002Fli>\n\u003Cli>Admin Color scheme adapted\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Middle features\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Forced language option for reCAPTCHA field\u003C\u002Fli>\n\u003Cli>Plugin \u003Cstrong>blocks the submit button\u003C\u002Fstrong> while reCAPTCHA field is not verified\u003C\u002Fli>\n\u003Cli>Plugin \u003Cstrong>changes HTML structure of the comments form\u003C\u002Fstrong> to prevent malicious automatic sendings while reCAPTCHA field is not verified\u003C\u002Fli>\n\u003Cli>Plugin also blocks \u003Cstrong>other elements with \u003Ccode>[type=submit]\u003C\u002Fcode> inside form\u003C\u002Fstrong> in case of a theme customized comments form\u003C\u002Fli>\n\u003Cli>Plugin lets you to write your own \u003Cstrong>additional CSS for the reCAPTCHA field\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>New \u003Cstrong>restore default value buttons\u003C\u002Fstrong> in plugin configuration section for helping you in case of changing WP theme, accidental errors, test environtments, etc.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Advanced features\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>reCAPTCHA \u003Cstrong>verification process via AJAX before submitting the form\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Second security checking process\u003C\u002Fstrong> for preventing any security breach \u003Cstrong>before saving the comment\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>Supporting \u003Cstrong>four different WP comments form HTML structure types\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>Advanced plugin options \u003Cstrong>based on HTML queries\u003C\u002Fstrong> for inserting the reCAPTCHA plugin in all kinds of WP themes\u003C\u002Fli>\n\u003Cli>Optional \u003Cstrong>Forced javascript output\u003C\u002Fstrong> that allows you to use the plugin with old WP themes that didn’t use function \u003Ccode>comment_form()\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>Advanced ID’s tags settings for using this plugin with WP Themes that creates its own comments form HTML struct\u003C\u002Fli>\n\u003Cli>reCAPTCHA javascript initialization that prevents reCAPTCHA conflicts in case of that other plugins use reCAPTCHA.\u003C\u002Fli>\n\u003Cli>New mínimum CSS styles for recaptcha alignment\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>PLUGIN PAGE\u003C\u002Fh4>\n\u003Cp>To learn more about the plugin, visit the \u003Ca href=\"http:\u002F\u002Fwww.joanmiquelviade.com\u002Fplugin\u002Fgoogle-recaptcha-in-wp-comments-form\u002F\" title=\"Author's plugin page\" rel=\"nofollow ugc\">Plugin page\u003C\u002Fa>.\u003C\u002Fp>\n","reCAPTCHA in WP comments form is an ANTISPAM tool that adds a Google reCAPTCHA to the comments form and protects your site from the spam robots threat &hellip;",8000,73368,82,20,"2019-04-22T12:10:00.000Z","5.1.22","4.0.0","",[21,100,101,102,103],"antispam-protection","comments-antispam","comments-recaptcha","recaptcha","http:\u002F\u002Fwww.joanmiquelviade.com\u002Fplugin\u002Fgoogle-recaptcha-in-wp-comments-form\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Frecaptcha-in-wp-comments-form.9.1.2.zip",85,{"slug":108,"name":109,"version":110,"author":111,"author_profile":112,"description":113,"short_description":114,"active_installs":94,"downloaded":115,"rating":13,"num_ratings":14,"last_updated":116,"tested_up_to":50,"requires_at_least":117,"requires_php":18,"tags":118,"homepage":121,"download_link":122,"security_score":13,"vuln_count":27,"unpatched_count":27,"last_vuln_date":28,"fetched_at":29},"spamanvil","SpamAnvil – AI Anti-Spam & Comment Spam Protection","1.11.2","Alexandre Amato","https:\u002F\u002Fprofiles.wordpress.org\u002Faamato\u002F","\u003Cp>\u003Cstrong>SpamAnvil is a free, open-source WordPress anti-spam plugin — and a genuine Akismet alternative — that uses artificial intelligence to block comment spam.\u003C\u002Fstrong> Unlike Akismet (which requires a paid plan for commercial sites) or simple keyword-based filters, SpamAnvil leverages large language models (LLMs) to actually \u003Cem>understand\u003C\u002Fem> your comments and detect even the most sophisticated spam. It layers a honeypot, a time trap and per-IP rate limiting in front of the AI, so obvious bots are blocked for free.\u003C\u002Fp>\n\u003Cp>Traditional spam filters rely on static word lists and link counting. Spammers have evolved. \u003Cstrong>SpamAnvil fights back with AI that understands context, intent, and language patterns\u003C\u002Fstrong> – catching spam that looks legitimate and approving real comments that others would flag.\u003C\u002Fp>\n\u003Ch4>Why SpamAnvil?\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>100% Free\u003C\u002Fstrong> – No premium tier, no subscription, no hidden costs. Bring your own API key (free options available).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Smarter Than Rules\u003C\u002Fstrong> – AI understands context. A comment about “buying a new home” won’t be flagged just because it contains “buy”.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Defense in Depth\u003C\u002Fstrong> – Honeypot, time trap, per-IP rate limit and heuristics block obvious bots for free, so the AI is only spent on the subtle cases.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Open Mode\u003C\u002Fstrong> – Because the filtering is invisible and automatic, you can drop the usual barriers (name\u002Femail, login, moderation) and get more real comments – even anonymous ones – without opening the door to spam.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Works With Free AI Models\u003C\u002Fstrong> – Use OpenRouter’s free models for $0 cost, or connect premium models for maximum accuracy.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy-First\u003C\u002Fstrong> – Your data stays between you and your chosen AI provider. IP addresses are stored as salted, keyed hashes (HMAC-SHA-256), not recoverable without your site’s secret. GDPR\u002FLGPD compliant by design.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>No Cloud Lock-in\u003C\u002Fstrong> – Choose from 6+ AI providers. Switch anytime. Your anti-spam, your rules.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Supported AI Providers\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>OpenAI\u003C\u002Fstrong> (GPT-4o-mini, GPT-4o, etc.)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Anthropic Claude\u003C\u002Fstrong> (Claude Sonnet, Haiku, etc.)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Google Gemini\u003C\u002Fstrong> (Gemini 2.0 Flash, Pro, etc.)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>OpenRouter\u003C\u002Fstrong> (100+ models, including FREE ones)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Featherless.ai\u003C\u002Fstrong> (Open-source models)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Any OpenAI-compatible API\u003C\u002Fstrong> (LM Studio, Ollama via proxy, vLLM, etc.)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>A Swiss-Army-Knife of Defenses\u003C\u002Fh4>\n\u003Cp>SpamAnvil layers several spam defenses so cheap, invisible filters catch obvious bots for free and the AI only handles the subtle cases. Every layer is optional and runs before any paid API call:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Honeypot\u003C\u002Fstrong> – A hidden field bots fill but humans never see. Instant, free block.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Time trap\u003C\u002Fstrong> – Comments submitted faster than a human could type are flagged. Tamper-proof (signed) and fails open, so it never blocks a real visitor.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Per-IP rate limit\u003C\u002Fstrong> – Throttles comment floods from a single IP before they even reach the database.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Heuristics engine\u003C\u002Fstrong> – Regex\u002Fstatistical pre-analysis (URLs, spam words, gambling\u002FSEO author names, language mismatch, prompt-injection patterns) that auto-spams the obvious cases with no API call.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>AI verdict\u003C\u002Fstrong> – An LLM scores the rest 0-100 in context.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Key Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>AI-Powered Spam Detection\u003C\u002Fstrong> – Each comment is analyzed by an LLM that scores it 0-100 for spam probability. Works with reasoning models (their thinking is parsed correctly).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Layered Bot Defense\u003C\u002Fstrong> – Honeypot, time trap and per-IP rate limiting block obvious bots for free, before any AI call.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Model Picker\u003C\u002Fstrong> – Browse and search each provider’s live model list right from the settings page (OpenAI, OpenRouter, Featherless). OpenRouter shows a “free” badge and context size.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>“Open Mode”\u003C\u002Fstrong> – One toggle removes WordPress comment friction (no required name\u002Femail, no login, no moderation hold) so leaving a real, even anonymous, comment is effortless. Comments appear instantly and spam is removed in the background.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Verdict Cache\u003C\u002Fstrong> – Identical repeated spam reuses a recent AI verdict instead of calling the API again, cutting cost during floods.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Intelligent Heuristics Engine\u003C\u002Fstrong> – Pre-analyzes comments to catch obvious spam without API calls.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Async Background Processing\u003C\u002Fstrong> – Comments are queued and processed via WP-Cron so your site stays fast.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Smart IP Blocking\u003C\u002Fstrong> – Automatically blocks repeat offenders with escalating ban durations (24h, 48h, 96h…).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Automatic Retry with Backoff\u003C\u002Fstrong> – Failed API calls retry with exponential delays; a real “Test Connection” verifies actual classification, not just the HTTP status.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Encrypted API Key Storage\u003C\u002Fstrong> – Authenticated AES-256-GCM encryption, or wp-config.php constants for maximum security.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Statistics Dashboard & Logs\u003C\u002Fstrong> – Track spam caught by each layer, API usage and errors, with the AI’s reasoning for every comment. An admin warning surfaces silent failures (no provider, or a backlog of failed items).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Customizable AI Prompts, Fallback Providers, Prompt-Injection Defense, Configurable Threshold, Moderator Bypass.\u003C\u002Fstrong>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>How It Works\u003C\u002Fh4>\n\u003Col>\n\u003Cli>A visitor submits a comment.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Rate limit\u003C\u002Fstrong> – too many comments from this IP too fast? Throttled with an HTTP 429 (before anything is stored).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>IP block\u003C\u002Fstrong> – is the IP already banned for repeat spam? Blocked.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Form traps\u003C\u002Fstrong> – was the hidden honeypot filled, or the comment submitted implausibly fast? Marked as spam instantly, no API call.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Heuristics\u003C\u002Fstrong> – a quick regex\u002Fstatistical pre-analysis; obvious spam is auto-marked with no API call.\u003C\u002Fli>\n\u003Cli>Otherwise the comment is queued for AI analysis (or processed immediately in sync mode). Identical repeated content reuses a cached verdict.\u003C\u002Fli>\n\u003Cli>The AI analyzes the comment in context (post title, author info, heuristic data) and returns a spam score.\u003C\u002Fli>\n\u003Cli>Comments above your threshold are marked spam; clean comments are auto-approved. Repeat-offender IPs are escalated.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>With \u003Cstrong>Open Mode\u003C\u002Fstrong> on, comments publish instantly and any spam is removed in the background instead of being held for moderation.\u003C\u002Fp>\n\u003Ch4>Use Cases\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Blogs\u003C\u002Fstrong> receiving hundreds of spam comments per day\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WooCommerce stores\u003C\u002Fstrong> where comment spam affects SEO and credibility\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Membership sites\u003C\u002Fstrong> that need to protect community discussions\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Multilingual sites\u003C\u002Fstrong> – AI understands comments in any language, unlike keyword-based filters\u003C\u002Fli>\n\u003Cli>\u003Cstrong>High-traffic sites\u003C\u002Fstrong> – Async processing handles any volume without slowing down your site\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Sites tired of Akismet\u003C\u002Fstrong> – Free alternative with no cloud dependency and full data control\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Security\u003C\u002Fh4>\n\u003Cp>SpamAnvil follows WordPress security best practices throughout:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Authenticated AES-256-GCM encrypted API key storage\u003C\u002Fli>\n\u003Cli>wp-config.php constant support for API keys (never touch the database)\u003C\u002Fli>\n\u003Cli>Configurable trusted IP header (default REMOTE_ADDR) so a forged X-Forwarded-For cannot bypass IP blocking or rate limiting\u003C\u002Fli>\n\u003Cli>Nonce verification on all forms and AJAX requests\u003C\u002Fli>\n\u003Cli>Capability checks on all admin actions\u003C\u002Fli>\n\u003Cli>Prepared SQL statements on every database query\u003C\u002Fli>\n\u003Cli>Output escaping on all rendered content\u003C\u002Fli>\n\u003Cli>Prompt injection defense: boundary tags, system prompt hardening, heuristic injection detection, strict JSON validation, temperature 0\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Languages\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>English (default)\u003C\u002Fli>\n\u003Cli>Translation-ready (.pot file included)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Third-Party Services\u003C\u002Fh4>\n\u003Cp>SpamAnvil sends comment data (content, author name, email, and URL) to external AI services for spam analysis. The specific service used depends on your configuration. No data is sent until you configure and enable a provider.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>OpenAI\u003C\u002Fstrong> — \u003Ca href=\"https:\u002F\u002Fopenai.com\" rel=\"nofollow ugc\">https:\u002F\u002Fopenai.com\u003C\u002Fa> — \u003Ca href=\"https:\u002F\u002Fopenai.com\u002Fpolicies\u002Fterms-of-use\" rel=\"nofollow ugc\">Terms of Use\u003C\u002Fa> — \u003Ca href=\"https:\u002F\u002Fopenai.com\u002Fpolicies\u002Fprivacy-policy\" rel=\"nofollow ugc\">Privacy Policy\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Anthropic (Claude)\u003C\u002Fstrong> — \u003Ca href=\"https:\u002F\u002Fwww.anthropic.com\" rel=\"nofollow ugc\">https:\u002F\u002Fwww.anthropic.com\u003C\u002Fa> — \u003Ca href=\"https:\u002F\u002Fwww.anthropic.com\u002Fpolicies#terms\" rel=\"nofollow ugc\">Terms of Service\u003C\u002Fa> — \u003Ca href=\"https:\u002F\u002Fwww.anthropic.com\u002Fpolicies#privacy\" rel=\"nofollow ugc\">Privacy Policy\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Google Gemini\u003C\u002Fstrong> — \u003Ca href=\"https:\u002F\u002Fai.google.dev\" rel=\"nofollow ugc\">https:\u002F\u002Fai.google.dev\u003C\u002Fa> — \u003Ca href=\"https:\u002F\u002Fai.google.dev\u002Fgemini-api\u002Fterms\" rel=\"nofollow ugc\">Terms of Service\u003C\u002Fa> — \u003Ca href=\"https:\u002F\u002Fpolicies.google.com\u002Fprivacy\" rel=\"nofollow ugc\">Privacy Policy\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>OpenRouter\u003C\u002Fstrong> — \u003Ca href=\"https:\u002F\u002Fopenrouter.ai\" rel=\"nofollow ugc\">https:\u002F\u002Fopenrouter.ai\u003C\u002Fa> — \u003Ca href=\"https:\u002F\u002Fopenrouter.ai\u002Fterms\" rel=\"nofollow ugc\">Terms of Service\u003C\u002Fa> — \u003Ca href=\"https:\u002F\u002Fopenrouter.ai\u002Fprivacy\" rel=\"nofollow ugc\">Privacy Policy\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Featherless.ai\u003C\u002Fstrong> — \u003Ca href=\"https:\u002F\u002Ffeatherless.ai\u002F\" rel=\"nofollow ugc\">https:\u002F\u002Ffeatherless.ai\u003C\u002Fa> — \u003Ca href=\"https:\u002F\u002Ffeatherless.ai\u002Fterms\" rel=\"nofollow ugc\">Terms of Service\u003C\u002Fa> — \u003Ca href=\"https:\u002F\u002Ffeatherless.ai\u002Fprivacy\" rel=\"nofollow ugc\">Privacy Policy\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>When using the “Generic OpenAI-Compatible” option, data is sent to the URL you configure. You are responsible for ensuring compliance with the privacy policies of your chosen service.\u003C\u002Fp>\n","Free AI anti-spam & Akismet alternative. Uses ChatGPT, Claude, Gemini & other LLMs to block comment spam that traditional filters miss.",993,"2026-07-18T21:16:00.000Z","5.8",[20,21,119,120,24],"comment-spam","moderation","https:\u002F\u002Fsoftware.amato.com.br\u002Fspamanvil-antispam-plugin-for-wordpress\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fspamanvil.1.11.2.zip",{"slug":124,"name":125,"version":126,"author":127,"author_profile":128,"description":129,"short_description":130,"active_installs":27,"downloaded":131,"rating":27,"num_ratings":27,"last_updated":132,"tested_up_to":133,"requires_at_least":17,"requires_php":134,"tags":135,"homepage":98,"download_link":139,"security_score":106,"vuln_count":27,"unpatched_count":27,"last_vuln_date":28,"fetched_at":140},"ai-ban-spam-comment","AI Ban Spam Comment","1.2","naimgr83","https:\u002F\u002Fprofiles.wordpress.org\u002Fnaimgr83\u002F","\u003Cp>This plugin uses the OpenAI  gpt-4o and gpt-4-turbo models to analyze and filter comments made on your texts. You can choose to have spam comments either deleted without being added to your database or saved as junk comments.Optionally approve only positive comments. To use the plugin, you just need to enter your OpenAI key.\u003C\u002Fp>\n\u003Ch3>REQUIRES:\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>PHP 7.2 or higher\u003C\u002Fli>\n\u003Cli>WordPress 5.0.x or higher\u003C\u002Fli>\n\u003C\u002Ful>\n","This plugin uses the OpenAI  gpt-4o and gpt-4-turbo models to analyze and filter comments made on your texts.",853,"2024-07-25T06:17:00.000Z","6.6.5","7.2",[21,136,22,137,138],"chatgpt","gpt","openai","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fai-ban-spam-comment.zip","2026-04-16T10:56:18.058Z",{"attackSurface":142,"codeSignals":251,"taintFlows":308,"riskAssessment":348,"analyzedAt":355},{"hooks":143,"ajaxHandlers":221,"restRoutes":240,"shortcodes":241,"cronEvents":242,"entryPointCount":250,"unprotectedCount":250},[144,150,152,154,156,158,160,166,169,172,174,177,179,182,185,188,189,192,195,198,201,205,208,211,214,217],{"type":145,"name":146,"callback":147,"priority":81,"file":148,"line":149},"filter","pre_comment_approved","closure","includes\\class-spambanana-checker.php",143,{"type":145,"name":146,"callback":147,"priority":81,"file":148,"line":151},184,{"type":145,"name":146,"callback":147,"priority":81,"file":148,"line":153},190,{"type":145,"name":146,"callback":147,"priority":81,"file":148,"line":155},195,{"type":145,"name":146,"callback":147,"priority":81,"file":148,"line":157},200,{"type":145,"name":146,"callback":147,"priority":81,"file":148,"line":159},207,{"type":161,"name":162,"callback":163,"file":164,"line":165},"action","plugins_loaded","anonymous","includes\\class-spambanana.php",63,{"type":161,"name":167,"callback":163,"file":164,"line":168},"admin_menu",73,{"type":161,"name":170,"callback":163,"file":164,"line":171},"admin_enqueue_scripts",76,{"type":161,"name":170,"callback":163,"file":164,"line":173},77,{"type":145,"name":175,"callback":163,"file":164,"line":176},"comment_row_actions",87,{"type":145,"name":178,"callback":163,"file":164,"line":69},"bulk_actions-edit-comments",{"type":145,"name":180,"callback":163,"file":164,"line":181},"handle_bulk_actions-edit-comments",89,{"type":161,"name":183,"callback":163,"file":164,"line":184},"admin_notices",90,{"type":161,"name":186,"callback":163,"file":164,"line":187},"wp_dashboard_setup",97,{"type":161,"name":183,"callback":163,"file":164,"line":13},{"type":161,"name":190,"callback":163,"file":164,"line":191},"admin_init",103,{"type":145,"name":193,"callback":163,"file":164,"line":194},"preprocess_comment",113,{"type":161,"name":196,"callback":163,"file":164,"line":197},"comment_post",116,{"type":161,"name":199,"callback":163,"file":164,"line":200},"wp_set_comment_status",120,{"type":161,"name":202,"callback":203,"file":164,"line":204},"spambanana_auto_delete_spam","SpamBanana_Cron",124,{"type":145,"name":206,"callback":163,"file":164,"line":207},"wpcf7_validate",132,{"type":161,"name":209,"callback":163,"file":164,"line":210},"wpforms_process",137,{"type":145,"name":212,"callback":163,"file":164,"line":213},"registration_errors",141,{"type":145,"name":215,"callback":163,"file":164,"line":216},"authenticate",144,{"type":161,"name":190,"callback":218,"file":219,"line":220},"spambanana_check_requirements","spambanana-ai-spam-protection.php",55,[222,226,229,231,234,237],{"action":223,"nopriv":224,"callback":163,"hasNonce":224,"hasCapCheck":224,"file":164,"line":225},"spambanana_test_connection",false,80,{"action":227,"nopriv":224,"callback":163,"hasNonce":224,"hasCapCheck":224,"file":164,"line":228},"spambanana_submit_feedback",81,{"action":230,"nopriv":224,"callback":163,"hasNonce":224,"hasCapCheck":224,"file":164,"line":93},"spambanana_bulk_check",{"action":232,"nopriv":224,"callback":163,"hasNonce":224,"hasCapCheck":224,"file":164,"line":233},"spambanana_bulk_feedback",83,{"action":235,"nopriv":224,"callback":163,"hasNonce":224,"hasCapCheck":224,"file":164,"line":236},"spambanana_run_cron",84,{"action":238,"nopriv":224,"callback":163,"hasNonce":224,"hasCapCheck":224,"file":164,"line":239},"spambanana_get_stats",91,[],[],[243,246,247],{"hook":244,"callback":244,"file":245,"line":225},"spambanana_cleanup_logs","includes\\class-spambanana-activator.php",{"hook":202,"callback":202,"file":245,"line":233},{"hook":202,"callback":202,"file":248,"line":249},"includes\\class-spambanana-cron.php",13,6,{"dangerousFunctions":252,"sqlUsage":253,"outputEscaping":284,"fileOperations":14,"externalRequests":305,"nonceChecks":250,"capabilityChecks":306,"bundledLibraries":307},[],{"prepared":254,"raw":255,"locations":256},34,11,[257,261,265,267,269,271,273,275,276,278,282],{"file":258,"line":259,"context":260},"admin\\class-spambanana-admin.php",679,"$wpdb->get_results() with variable interpolation",{"file":262,"line":263,"context":264},"admin\\partials\\dashboard-page.php",14,"$wpdb->get_var() with variable interpolation",{"file":262,"line":266,"context":264},16,{"file":262,"line":268,"context":260},79,{"file":270,"line":70,"context":264},"admin\\partials\\stats-page.php",{"file":270,"line":272,"context":264},21,{"file":270,"line":274,"context":260},51,{"file":270,"line":168,"context":260},{"file":270,"line":277,"context":260},164,{"file":279,"line":280,"context":281},"uninstall.php",22,"$wpdb->query() with variable interpolation",{"file":279,"line":283,"context":281},24,{"escaped":200,"rawEcho":285,"locations":286},9,[287,290,292,293,295,298,300,302,303],{"file":262,"line":288,"context":289},41,"raw output",{"file":262,"line":291,"context":289},46,{"file":262,"line":274,"context":289},{"file":262,"line":294,"context":289},56,{"file":296,"line":297,"context":289},"admin\\partials\\queue-page.php",59,{"file":270,"line":299,"context":289},106,{"file":270,"line":301,"context":289},111,{"file":270,"line":197,"context":289},{"file":270,"line":304,"context":289},148,7,5,[],[309,328,336],{"entryPoint":310,"graph":311,"unsanitizedCount":27,"severity":327},"display_settings_page (admin\\class-spambanana-admin.php:363)",{"nodes":312,"edges":324},[313,318],{"id":314,"type":315,"label":316,"file":258,"line":317},"n0","source","$_POST",391,{"id":319,"type":320,"label":321,"file":258,"line":322,"wp_function":323},"n1","sink","update_option() [Settings Manipulation]",394,"update_option",[325],{"from":314,"to":319,"sanitized":326},true,"low",{"entryPoint":329,"graph":330,"unsanitizedCount":27,"severity":327},"\u003Cclass-spambanana-admin> (admin\\class-spambanana-admin.php:0)",{"nodes":331,"edges":334},[332,333],{"id":314,"type":315,"label":316,"file":258,"line":317},{"id":319,"type":320,"label":321,"file":258,"line":322,"wp_function":323},[335],{"from":314,"to":319,"sanitized":326},{"entryPoint":337,"graph":338,"unsanitizedCount":27,"severity":327},"\u003Cstats-page> (admin\\partials\\stats-page.php:0)",{"nodes":339,"edges":346},[340,342],{"id":314,"type":315,"label":341,"file":270,"line":263},"$_GET",{"id":319,"type":320,"label":343,"file":270,"line":344,"wp_function":345},"echo() [XSS]",128,"echo",[347],{"from":314,"to":319,"sanitized":326},{"summary":349,"deductions":350},"The spambanana-ai-spam-protection plugin v1.0.6 presents a moderate to high security risk primarily due to its substantial unprotected attack surface.  While the code signals indicate good practices like high percentages of prepared SQL statements and properly escaped output, and no critical taint flows, the fact that all 6 identified AJAX handlers lack authentication checks is a significant concern. This means any unauthenticated user could potentially interact with these handlers, leading to unintended consequences or further exploitation.  The plugin also has 6 nonce checks, but if these are not implemented correctly on the AJAX handlers, they offer no real protection. The absence of any recorded vulnerabilities in its history is a positive sign, suggesting a generally secure development history. However, this does not negate the immediate risks posed by the unprotected entry points.",[351,353],{"reason":352,"points":11},"All AJAX handlers lack authentication checks",{"reason":354,"points":305},"Large attack surface without authentication","2026-03-17T00:00:22.151Z",{"wat":357,"direct":370},{"assetPaths":358,"generatorPatterns":363,"scriptPaths":364,"versionParams":365},[359,360,361,362],"\u002Fwp-content\u002Fplugins\u002Fspambanana-ai-spam-protection\u002Fadmin\u002Fcss\u002Fspambanana-admin.css","\u002Fwp-content\u002Fplugins\u002Fspambanana-ai-spam-protection\u002Fadmin\u002Fjs\u002Fspambanana-admin.js","\u002Fwp-content\u002Fplugins\u002Fspambanana-ai-spam-protection\u002Fpublic\u002Fcss\u002Fspambanana-public.css","\u002Fwp-content\u002Fplugins\u002Fspambanana-ai-spam-protection\u002Fpublic\u002Fjs\u002Fspambanana-public.js",[],[360,362],[366,367,368,369],"spambanana-ai-spam-protection\u002Fadmin\u002Fcss\u002Fspambanana-admin.css?ver=","spambanana-ai-spam-protection\u002Fadmin\u002Fjs\u002Fspambanana-admin.js?ver=","spambanana-ai-spam-protection\u002Fpublic\u002Fcss\u002Fspambanana-public.css?ver=","spambanana-ai-spam-protection\u002Fpublic\u002Fjs\u002Fspambanana-public.js?ver=",{"cssClasses":371,"htmlComments":373,"htmlAttributes":374,"restEndpoints":375,"jsGlobals":377,"shortcodeOutput":379},[372],"spambanana-feedback-button",[],[],[376],"\u002Fwp-json\u002Fspambanana\u002Fv1\u002Ffeedback",[378],"spambanana_feedback_ajax_object",[],{"error":326,"url":381,"statusCode":382,"statusMessage":383,"message":383},"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fspambanana-ai-spam-protection\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":14,"versions":385},[386],{"version":6,"download_url":26,"svn_tag_url":387,"released_at":28,"has_diff":224,"diff_files_changed":388,"diff_lines":28,"trac_diff_url":28,"vulnerabilities":389,"is_current":326},"https:\u002F\u002Fplugins.svn.wordpress.org\u002Fspambanana-ai-spam-protection\u002Ftags\u002F1.0.6\u002F",[],[]]