Spam Eater for PHP forms

Stop form spam on any PHP site without a CAPTCHA. Honeypot, JavaScript, timing and interaction checks, all on your own server. Free and MIT.

Spam Eater for PHP forms stops spam on any PHP website without a CAPTCHA. Your visitors never solve a puzzle or tick a box, there’s no account to create, and nothing is sent to an outside service: every check runs on your own server.

It’s the engine of AccessNow Spam Eater for WordPress, packaged for sites that don’t run WordPress: a hand-built contact form, a small business site, or your own PHP app. It adds two lines to your form and one to the code that receives it.

Features

  • Honeypot, JavaScript, timing and interaction checks, with no CAPTCHA
  • Blocks addresses that keep filling in the hidden field for 24 hours, using a one-way hash so no address is stored
  • Always allow and Always block lists of addresses and ranges (IPv4 and IPv6)
  • Your own words, phrases and patterns, for spam typed by people
  • Turns away about 9,000 throwaway email domains, from a list that comes with it
  • A short reference code for every refusal, so you can tell which check caught it
  • Works with page caching, proxies and CDNs, and a strict Content Security Policy
  • No cookies, no tracking and no outside services; what people type is never stored

Install

With Composer:

composer require accessnow/spam-eater

Without Composer, download the ZIP from the latest release on GitHub, put the folder on your server and require its autoload.php. Then:

$guard = new AccessNow\SpamEater\Guard( array(
    'secret'  => 'a long random string',
    'storage' => '/a/folder/outside/your/web/root',
) );

// In the form, and once after it:
echo $guard->field();
echo $guard->script();

// Where the form is received:
if ( $guard->check() ) {
    exit( 'Sorry, your message could not be sent. Reference: ' . $guard->failCode() );
}

The documentation on GitHub covers every option, login forms, forms added after the page loads, and keeping the block list in your own database.

Requirements

  • PHP 7.4 or later, with no other dependencies
  • A folder PHP can write to, outside the web root, if you want repeat bots blocked
  • MIT licence: free for any site, commercial or not

More projects

View all
Custom build
WordPress Plugin

SCK Stats

Cookieless visit stats and split testing for Sunshine Coast Karate: which pages and sources lead to trial bookings, with no cookies or IP addresses.

Free
Web App

AccessNow SSO

Central single sign-on for the AccessNow and Karate4Life apps, built on a focused subset of OpenID Connect.

Free
PWAWeb App

MyPB — My Personal Budget

Personal budgeting made simple: zero-based budgeting, multi-account tracking and reports. Free during early access.