=== DigiNex Spam Guard ===
Contributors: diginex
Tags: spam, anti-spam, honeypot, contact form, elementor
Requires at least: 5.8
Tested up to: 7.1
Requires PHP: 7.4
Stable tag: 1.0.0
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Invisible, CAPTCHA-free spam protection for Elementor Pro, Contact Form 7, WPForms, comments, WooCommerce reviews and registrations.

== Description ==

DigiNex Spam Guard stops form spam without annoying your visitors. No CAPTCHA, no puzzles, no third-party service: every check runs on your own server.

**Protects**

* Elementor Pro forms
* Contact Form 7
* WPForms (Lite & Pro)
* WordPress comments and WooCommerce product reviews
* WordPress registration form
* WooCommerce "My account" registration

**How it stops spam**

* **Honeypot** – an invisible field that only bots fill in.
* **JavaScript token** – blocks bots that post directly to your server without loading the page. Works behind page caches.
* **Minimum fill-in time** – humans need a few seconds, bots don't.
* **Gibberish detection** – blocks random strings such as `ojQcUdMpBwZQIhBEKWUN`.
* **Gmail dot trick** – blocks addresses like `aso.s.a.cz2.9@gmail.com`.
* **Link limit** and **blocked words**.
* **Rate limit** per IP address.
* **Blocked log** and statistics, so you can see what was stopped and why.

**DigiNex Spam Guard Pro** adds Tor exit node blocking, disposable email blocking, IP and email allow/block lists, a 1,000-entry log with CSV export and a weekly email report. [Learn more](https://diginex.gr/spam-guard/).

DigiNex Spam Guard is an independent plugin by DigiNex. It is not affiliated with or endorsed by Elementor, Contact Form 7, WPForms or WooCommerce; their names are used only to describe compatibility.

== Installation ==

1. Install and activate the plugin.
2. Go to **Settings → DigiNex Spam Guard**. Protection is on by default.
3. If you use a page cache, clear it once.
4. If a "delay JavaScript" optimizer is active (e.g. WP Rocket, LiteSpeed Cache, Perfmatters), exclude `dxsg.js` from delayed scripts.

== Frequently Asked Questions ==

= Does it work with page caching? =

Yes. The token has no expiry, so cached pages keep working.

= Do visitors need JavaScript? =

Yes, when the "JavaScript token" check is on. Virtually every browser runs JavaScript; you can turn the check off in the settings.

= Does it send data to external services? =

No. All checks run on your server.

= A real visitor was blocked. What do I do? =

Open **Settings → DigiNex Spam Guard → Blocked log** to see the reason, then turn off or relax that check.

= Developers =

Filters: `dxsg_form_selectors`, `dxsg_pre_check`, `dxsg_check_result`, `dxsg_skip`, `dxsg_log_limit`, `dxsg_default_settings`. Action: `dxsg_blocked`.

== Changelog ==

= 1.0.0 =
* First release.
