B-Honeypot for WordPress
Lightweight honeypot anti-spam plugin for WordPress
Install
No release zip yet. The repository archive installs, but the folder name will carry the branch suffix and updates will not flow:
wp plugin install https://github.com/botheory/b-honeypot/archive/refs/heads/master.zipB-Honeypot is a configurable, lightweight honeypot anti-spam plugin for WordPress forms. It protects comments, subscriptions, popup forms, contact forms, and other front-end forms without requiring a CAPTCHA.
Features
- Random or fixed honeypot field names.
- Independent protection for comment, subscription, popup, and other forms.
- Server-side injection for forms in the initial HTML response.
- JavaScript instrumentation for dynamically inserted forms and accessible same-origin iframes.
- Client-side protection for external-action forms, including many AWeber and Brevo integrations.
- Optional database logging with timestamps, IP addresses, approximate locations, user agents, page URLs, and captured honeypot values.
- Sortable, paginated logs and configurable date-range statistics.
- WordPress privacy-policy integration and translation support.
- No dependency on the WordPress REST API.
Requirements
- WordPress 6.2 or newer.
- PHP 7.4 or newer.
Installation
- Download or clone this repository into
wp-content/plugins/b-honeypot. - Activate B-Honeypot for WordPress from the WordPress Plugins screen.
- Open Settings > B-Honeypot.
- Select the form categories and logging options that match your site.
For a production deployment, upload the plugin ZIP from Plugins > Add New > Upload Plugin.
Configuration
The settings page controls the honeypot field mode, the form categories to protect, and optional capture logging. Logging is disabled or enabled independently from form protection and can be cleared from the plugin's log screen.
Cross-origin iframe contents cannot be modified by browser scripts. Forms inside third-party iframes can only be protected when the provider exposes them in the same document or provides an integration hook.
Privacy
When logging is enabled, B-Honeypot stores captured submission data in the WordPress database. Public IP addresses may be sent over HTTPS to ipwho.is to obtain an approximate location; successful lookups are cached for seven days. Site owners are responsible for documenting this processing in their privacy information where required.
Sites behind a trusted reverse proxy can use the b_honeypot_client_ip filter to provide the client IP address.
Development
The repository contains the plugin source, assets, and translation template. No build step is required. Follow WordPress PHP, JavaScript, and accessibility coding standards when contributing.
Before opening a pull request, review the complete diff and test activation, settings changes, front-end form submission, logging, and uninstall behavior in a disposable WordPress installation.
Contributing
Bug reports and pull requests are welcome. Please include the WordPress and PHP versions used, clear reproduction steps, and any relevant error messages.
License
B-Honeypot for WordPress is released under the MIT License.