{"id":318796,"date":"2026-05-29T18:44:18","date_gmt":"2026-05-29T18:44:18","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/mentoguard-behavioral-spam-blocker-for-contact-forms\/"},"modified":"2026-08-21T19:55:21","modified_gmt":"2026-08-21T19:55:21","slug":"mentoguard","status":"publish","type":"plugin","link":"https:\/\/ta.wordpress.org\/plugins\/mentoguard\/","author":6389499,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.8.6","stable_tag":"1.8.6","tested":"7.0.4","requires":"6.0","requires_php":"8.0","requires_plugins":null,"header_name":"MentoGuard - Spam Blocker & reCAPTCHA Alternative for Contact Form 7","header_author":"MentoTex","header_description":"GDPR-friendly behavioral spam protection for WordPress forms. No Google. No external servers. Zero page speed impact. Currently supports Contact Form 7.","assets_banners_color":"647e99","last_updated":"2026-08-21 19:55:21","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/mentotex.dev\/mentoguard","header_author_uri":"https:\/\/mentotex.dev","rating":0,"author_block_rating":0,"active_installs":0,"downloads":249,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.8.5":{"tag":"1.8.5","author":"hbakhtiari","date":"2026-05-29 18:43:55"},"1.8.6":{"tag":"1.8.6","author":"hbakhtiari","date":"2026-08-21 19:55:21"}},"upgrade_notice":{"1.8.5":"<p>Security and sanitization improvements. Recommended update for all users.<\/p>"},"ratings":[],"assets_icons":{"icon-256x256.png":{"filename":"icon-256x256.png","revision":3658468,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3658468,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3658468,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.8.5","1.8.6"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3658468,"resolution":"1","location":"assets","locale":"","width":2268,"height":1986},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3658468,"resolution":"2","location":"assets","locale":"","width":2222,"height":1466},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3658468,"resolution":"3","location":"assets","locale":"","width":2242,"height":756},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3658468,"resolution":"4","location":"assets","locale":"","width":2901,"height":1989},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3658468,"resolution":"5","location":"assets","locale":"","width":2208,"height":1410}},"screenshots":{"1":"Dashboard - spam statistics, recent blocked submissions, and quick actions","2":"Spam Logs - filterable table with date, IP, score, triggered signals, and bulk delete","3":"Top Spammers - IPs ranked by attempt count with one-click blacklist","4":"Settings - presets, behavioral signals, time protection, IP blacklist, and threshold controls","5":"Debug Log - step-by-step validation output for every form submission"}},"plugin_section":[],"plugin_tags":[2656,166108,1152,131785,599],"plugin_category":[42,54],"plugin_contributors":[261768,263797],"plugin_business_model":[],"class_list":["post-318796","plugin","type-plugin","status-publish","hentry","plugin_tags-anti-spam","plugin_tags-bot-protection","plugin_tags-contact-form-7","plugin_tags-gdpr","plugin_tags-spam","plugin_category-contact-forms","plugin_category-security-and-spam-protection","plugin_contributors-hbakhtiari","plugin_contributors-mentotex","plugin_committers-hbakhtiari"],"banners":{"banner":"https:\/\/ps.w.org\/mentoguard\/assets\/banner-772x250.png?rev=3658468","banner_2x":"https:\/\/ps.w.org\/mentoguard\/assets\/banner-1544x500.png?rev=3658468","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/mentoguard\/assets\/icon-256x256.png?rev=3658468","icon_2x":"https:\/\/ps.w.org\/mentoguard\/assets\/icon-256x256.png?rev=3658468","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/mentoguard\/assets\/screenshot-1.png?rev=3658468","caption":"Dashboard - spam statistics, recent blocked submissions, and quick actions"},{"src":"https:\/\/ps.w.org\/mentoguard\/assets\/screenshot-2.png?rev=3658468","caption":"Spam Logs - filterable table with date, IP, score, triggered signals, and bulk delete"},{"src":"https:\/\/ps.w.org\/mentoguard\/assets\/screenshot-3.png?rev=3658468","caption":"Top Spammers - IPs ranked by attempt count with one-click blacklist"},{"src":"https:\/\/ps.w.org\/mentoguard\/assets\/screenshot-4.png?rev=3658468","caption":"Settings - presets, behavioral signals, time protection, IP blacklist, and threshold controls"},{"src":"https:\/\/ps.w.org\/mentoguard\/assets\/screenshot-5.png?rev=3658468","caption":"Debug Log - step-by-step validation output for every form submission"}],"raw_content":"<!--section=description-->\n<p>Tired of spam emails flooding your inbox from your contact form? MentoGuard is a lightweight, privacy-first spam blocker that protects your Contact Form 7 forms from bots - without annoying your real visitors with image puzzles or checkbox challenges.<\/p>\n\n<p>If you are looking for a reliable reCAPTCHA alternative that is fully GDPR compliant, MentoGuard stops spam bots silently using behavioral analysis and server-side token verification. Zero data is sent to Google or any external server. Ever.<\/p>\n\n<p>Currently optimized for <strong>Contact Form 7 (CF7)<\/strong>, with support for more form builders coming in future releases.<\/p>\n\n<h4>How It Works<\/h4>\n\n<p>MentoGuard uses five independent protection layers that work together invisibly:<\/p>\n\n<ol>\n<li><strong>IP Blacklist<\/strong> - known bad IPs are blocked instantly before any other check runs. Supports IPv4, IPv6, and CIDR ranges.<\/li>\n<li><strong>Signed Token<\/strong> - every form load generates a unique one-time server-side token. Headless bots that submit without loading the page are blocked immediately.<\/li>\n<li><strong>Submission Timing<\/strong> - measures the time between page load and form submission entirely server-side. Bots submit in milliseconds; real users take seconds.<\/li>\n<li><strong>Behavioral Score<\/strong> - JavaScript silently tracks mouse movement, typing patterns, field interaction order, and paste vs keyboard input to generate an accurate spam score.<\/li>\n<li><strong>JS Bypass Detection<\/strong> - if a bot disables JavaScript entirely to avoid tracking, MentoGuard catches it server-side.<\/li>\n<\/ol>\n\n<p>Real users pass all five layers without ever knowing they exist.<\/p>\n\n<h4>Why Choose MentoGuard Over reCAPTCHA?<\/h4>\n\n<ul>\n<li><strong>No Google dependency<\/strong> - reCAPTCHA sends visitor data to Google servers. MentoGuard keeps everything on your own server.<\/li>\n<li><strong>No puzzles, no friction<\/strong> - real visitors never click a checkbox or identify traffic lights. Protection is completely invisible.<\/li>\n<li><strong>GDPR-friendly by design<\/strong> - no cookies, no third-party requests, no data leaving your server.<\/li>\n<li><strong>Zero page speed impact<\/strong> - scripts only load on pages that contain an active contact form. Every other page is completely unaffected.<\/li>\n<li><strong>No monthly fees<\/strong> - MentoGuard is free and open source. No API keys, no account registration, no renewal.<\/li>\n<\/ul>\n\n<h4>Key Features<\/h4>\n\n<ul>\n<li>Native Contact Form 7 tag - place [mentoguard] directly inside the CF7 form editor<\/li>\n<li>Three protection presets - Relaxed, Balanced, Strict - one click to configure<\/li>\n<li>Per-signal control - enable or disable each behavioral signal and adjust its point value<\/li>\n<li>Configurable block threshold - set exactly how aggressive the spam filter should be<\/li>\n<li>Page time protection - configurable minimum time in seconds or milliseconds<\/li>\n<li>Spam Log dashboard - every blocked submission logged with IP, score, signals, and page URL<\/li>\n<li>Top Spammers page - IPs ranked by blocked attempt count with one-click blacklist addition<\/li>\n<li>IP Blacklist - manually add IPs or CIDR ranges permanently blocked before any other check<\/li>\n<li>Test Mode - see live spam scores without blocking anyone, perfect for tuning<\/li>\n<li>Debug Log - step-by-step validation showing exactly what happened for every submission<\/li>\n<li>Bulk log management - select and delete individual entries or clear all at once<\/li>\n<li>Automatic log retention - configurable from 30 days to forever<\/li>\n<li>Translation ready - full i18n support with .pot file included<\/li>\n<\/ul>\n\n<h4>Privacy<\/h4>\n\n<p>MentoGuard stores only the IP address and spam score of blocked submissions - in your own WordPress database. No data is transmitted to any external service at any time. On uninstall, all data is removed completely.<\/p>\n\n<h4>Usage with Contact Form 7<\/h4>\n\n<p>Add [mentoguard] inside your CF7 form editor, before the submit button:<\/p>\n\n<p>[text* your-name]\n[email* your-email]\n[mentoguard]\n[submit \"Send\"]<\/p>\n\n<p>That is all. MentoGuard registers as a native CF7 form tag and activates automatically.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the mentoguard folder to \/wp-content\/plugins\/<\/li>\n<li>Activate through the Plugins menu in WordPress<\/li>\n<li>Add [mentoguard] inside your CF7 form editor before the submit button<\/li>\n<li>Go to MentoGuard &gt; Settings and choose a preset - Balanced is recommended<\/li>\n<li>Enable Test Mode first to verify real users score below the block threshold<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"is%20mentoguard%20a%20recaptcha%20alternative%3F\"><h3>Is MentoGuard a reCAPTCHA alternative?<\/h3><\/dt>\n<dd><p>Yes. MentoGuard replaces reCAPTCHA with server-side behavioral analysis and token verification. No Google account required, no data sent externally, fully GDPR compliant.<\/p><\/dd>\n<dt id=\"will%20it%20block%20real%20users%20by%20mistake%3F\"><h3>Will it block real users by mistake?<\/h3><\/dt>\n<dd><p>MentoGuard uses a scoring system across multiple independent signals. Real users rarely trigger enough signals to reach the block threshold. Enable Test Mode before going live to verify scores on your own site.<\/p><\/dd>\n<dt id=\"does%20it%20work%20with%20contact%20form%207%3F\"><h3>Does it work with Contact Form 7?<\/h3><\/dt>\n<dd><p>Yes. MentoGuard registers as a native CF7 form tag. Place [mentoguard] inside the CF7 form editor and it works immediately - no other configuration needed.<\/p><\/dd>\n<dt id=\"is%20it%20gdpr%20compliant%3F\"><h3>Is it GDPR compliant?<\/h3><\/dt>\n<dd><p>Yes. No data leaves your server. Only blocked submissions are logged in your own WordPress database. Log retention period is configurable. All data is deleted on plugin uninstall.<\/p><\/dd>\n<dt id=\"does%20it%20affect%20page%20speed%20or%20seo%3F\"><h3>Does it affect page speed or SEO?<\/h3><\/dt>\n<dd><p>No. MentoGuard scripts load only on pages containing a CF7 form with [mentoguard]. All other pages are completely unaffected - no scripts, no styles, no impact.<\/p><\/dd>\n<dt id=\"can%20i%20block%20specific%20ips%20permanently%3F\"><h3>Can I block specific IPs permanently?<\/h3><\/dt>\n<dd><p>Yes. The IP Blacklist supports individual IPv4 and IPv6 addresses as well as CIDR ranges (e.g. 192.168.0.0\/24). Blacklisted IPs are blocked before any other validation runs.<\/p><\/dd>\n<dt id=\"what%20is%20the%20debug%20log%3F\"><h3>What is the Debug Log?<\/h3><\/dt>\n<dd><p>Enable Debug Mode in Settings, submit a form, then go to MentoGuard &gt; Debug Log. You will see every validation layer - what was checked, what was found, and exactly why the submission was allowed or blocked.<\/p><\/dd>\n<dt id=\"will%20other%20form%20builders%20be%20supported%3F\"><h3>Will other form builders be supported?<\/h3><\/dt>\n<dd><p>Yes. The core protection engine is form-builder agnostic. Contact Form 7 is the first integration. More form builders are planned for future releases.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.8.6<\/h4>\n\n<ul>\n<li>Update: Plugin display name updated<\/li>\n<\/ul>\n\n<h4>1.8.5<\/h4>\n\n<ul>\n<li>Fix: IP validation in blacklist Ajax handler uses FILTER_VALIDATE_IP<\/li>\n<li>Fix: min_score filter uses absint() inline<\/li>\n<li>Fix: sanitize_time_value() capped at 9999<\/li>\n<\/ul>\n\n<h4>1.8.4<\/h4>\n\n<ul>\n<li>Fix: All inline script tags replaced with wp_add_inline_script()<\/li>\n<li>Fix: Each POST field individually sanitized with sanitize_text_field() and wp_unslash()<\/li>\n<li>Fix: CIDR mask validation now checks 0-32 for IPv4, 0-128 for IPv6<\/li>\n<\/ul>\n\n<h4>1.8.3<\/h4>\n\n<ul>\n<li>Fix: Plugin name trademark issue resolved<\/li>\n<li>Fix: Logger queries restructured to satisfy Plugin Check static analysis<\/li>\n<\/ul>\n\n<h4>1.8.0<\/h4>\n\n<ul>\n<li>Fix: All Plugin Check warnings resolved<\/li>\n<li>Fix: Score badge colors - blocked entries always orange or red, never green<\/li>\n<li>Fix: Emoji replaced with Dashicons throughout admin<\/li>\n<li>Add: README.md for GitHub<\/li>\n<li>Add: Debug Mode and Debug Log page<\/li>\n<\/ul>\n\n<h4>1.7.2<\/h4>\n\n<ul>\n<li>Fix: CF7 REST API token conflict resolved<\/li>\n<\/ul>\n\n<h4>1.7.0<\/h4>\n\n<ul>\n<li>Fix: CF7 submits via REST API - switched to wpcf7_spam filter<\/li>\n<li>Add: Token auto-refresh after successful CF7 submission<\/li>\n<\/ul>\n\n<h4>1.6.0<\/h4>\n\n<ul>\n<li>Add: IP Blacklist with CIDR range support<\/li>\n<li>Add: Top Spammers page with one-click blacklisting<\/li>\n<li>Add: Daily cron job for automatic log retention purge<\/li>\n<\/ul>\n\n<h4>1.5.0<\/h4>\n\n<ul>\n<li>Fix: All database queries use $wpdb-&gt;prepare()<\/li>\n<li>Fix: All input reads include wp_unslash() and inline sanitization<\/li>\n<li>Add: Silence files in all directories<\/li>\n<li>Add: languages\/ folder with .pot file<\/li>\n<\/ul>\n\n<h4>1.4.0<\/h4>\n\n<ul>\n<li>Add: Page time protection - server-side timing check<\/li>\n<li>Add: Configurable minimum time in seconds or milliseconds<\/li>\n<\/ul>\n\n<h4>1.3.0<\/h4>\n\n<ul>\n<li>Add: Signed one-time server-side token system<\/li>\n<li>Add: JS bypass detection<\/li>\n<\/ul>\n\n<h4>1.2.0<\/h4>\n\n<ul>\n<li>Add: Bulk delete in Spam Logs<\/li>\n<li>Fix: Score badge color logic<\/li>\n<li>Fix: Server-side blocking reads threshold settings correctly<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release<\/li>\n<\/ul>","raw_excerpt":"Stop contact form spam without Google reCAPTCHA. GDPR-friendly behavioral bot protection for Contact Form 7. No external servers. No puzzles.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ta.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/318796","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ta.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/ta.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/ta.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=318796"}],"author":[{"embeddable":true,"href":"https:\/\/ta.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/hbakhtiari"}],"wp:attachment":[{"href":"https:\/\/ta.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=318796"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/ta.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=318796"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/ta.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=318796"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/ta.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=318796"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/ta.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=318796"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/ta.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=318796"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}