Spam Eater for PHP forms stops spam on any PHP website without a CAPTCHA. Your visitors never solve a puzzle or tick a box, there’s no account to create, and nothing is sent to an outside service: every check runs on your own server.
It’s the engine of AccessNow Spam Eater for WordPress, packaged for sites that don’t run WordPress: a hand-built contact form, a small business site, or your own PHP app. It adds two lines to your form and one to the code that receives it.
Features
- Honeypot, JavaScript, timing and interaction checks, with no CAPTCHA
- Blocks addresses that keep filling in the hidden field for 24 hours, using a one-way hash so no address is stored
- Always allow and Always block lists of addresses and ranges (IPv4 and IPv6)
- Your own words, phrases and patterns, for spam typed by people
- Turns away about 9,000 throwaway email domains, from a list that comes with it
- A short reference code for every refusal, so you can tell which check caught it
- Works with page caching, proxies and CDNs, and a strict Content Security Policy
- No cookies, no tracking and no outside services; what people type is never stored
Install
With Composer:
composer require accessnow/spam-eater
Without Composer, download the ZIP from the latest release on GitHub, put the folder on your server and require its autoload.php. Then:
$guard = new AccessNow\SpamEater\Guard( array(
'secret' => 'a long random string',
'storage' => '/a/folder/outside/your/web/root',
) );
// In the form, and once after it:
echo $guard->field();
echo $guard->script();
// Where the form is received:
if ( $guard->check() ) {
exit( 'Sorry, your message could not be sent. Reference: ' . $guard->failCode() );
}
The documentation on GitHub covers every option, login forms, forms added after the page loads, and keeping the block list in your own database.
Requirements
- PHP 7.4 or later, with no other dependencies
- A folder PHP can write to, outside the web root, if you want repeat bots blocked
- MIT licence: free for any site, commercial or not



