Spam Eater for PHP forms

Stop form spam on any PHP site without a CAPTCHA. Honeypot, JavaScript, timing and interaction checks, all on your own server. Free and MIT.

Spam Eater for PHP forms stops spam on any PHP website without a CAPTCHA. Your visitors never solve a puzzle or tick a box, there’s no account to create, and nothing is sent to an outside service: every check runs on your own server.

It’s the engine of AccessNow Spam Eater for WordPress, packaged for sites that don’t run WordPress: a hand-built contact form, a small business site, or your own PHP app. It adds two lines to your form and one to the code that receives it.

Features

  • Honeypot, JavaScript, timing and interaction checks, with no CAPTCHA
  • Blocks addresses that keep filling in the hidden field for 24 hours, using a one-way hash so no address is stored
  • Always allow and Always block lists of addresses and ranges (IPv4 and IPv6)
  • Your own words, phrases and patterns, for spam typed by people
  • Turns away about 9,000 throwaway email domains, from a list that comes with it
  • A short reference code for every refusal, so you can tell which check caught it
  • Works with page caching, proxies and CDNs, and a strict Content Security Policy
  • No cookies, no tracking and no outside services; what people type is never stored

Install

With Composer:

composer require accessnow/spam-eater

Without Composer, download the ZIP from the latest release on GitHub, put the folder on your server and require its autoload.php. Then:

$guard = new AccessNow\SpamEater\Guard( array(
    'secret'  => 'a long random string',
    'storage' => '/a/folder/outside/your/web/root',
) );

// In the form, and once after it:
echo $guard->field();
echo $guard->script();

// Where the form is received:
if ( $guard->check() ) {
    exit( 'Sorry, your message could not be sent. Reference: ' . $guard->failCode() );
}

The documentation on GitHub covers every option, login forms, forms added after the page loads, and keeping the block list in your own database.

Requirements

  • PHP 7.4 or later, with no other dependencies
  • A folder PHP can write to, outside the web root, if you want repeat bots blocked
  • MIT licence: free for any site, commercial or not

More projects

View all
Free
WordPress Plugin

AccessNow Spam Eater

Stops form spam without CAPTCHAs, using hidden fields, JavaScript and timing checks. Works with core forms, WooCommerce, popular form plugins and your own forms.

Custom build
WordPress Theme

Sunshine Coast Karate Theme

The block theme behind Sunshine Coast Karate: presentation only, with a locked brand palette, section styles and patterns in place of a page builder.

Free
Simple Web App (1 file)

Responsive Preview

Preview a web page at popular phone, tablet and breakpoint sizes side by side.