=== Veilo — Invisible Spam Shield ===
Contributors: adinax0926
Tags: spam, security, anti-spam, comments, forms
Requires at least: 5.8
Tested up to: 7.0
Requires PHP: 7.4
Stable tag: 1.1.0
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Invisible spam protection for comments and forms — no CAPTCHA, ever shown to visitors.

== Description ==

A working plugin scaffold, not a demo. It scores every submission using three signals — a honeypot field, submission speed, and pointer/touch movement — with no CAPTCHA ever shown to the visitor. Spam is blocked (or held for review) automatically.

**Free plan protects:**

* Native WordPress comments
* Contact Form 7
* WPForms

**Pro plan additionally protects:**

* Elementor Pro Forms
* Gravity Forms

...and unlocks Veilo → Pro Tools: full Activity Log history (configurable row limit, free is capped at the 10 most recent) and one-click CSV export.

= Protecting a custom or hand-coded form =

The signal script (`public/js/veilo-signals.js`) tags every `<form>` on the page automatically, so the three hidden fields are already present in `$_POST` for ANY form, built-in or custom. To act on them from your own form handler, call the public helper:

`
$result = veilo_check( $_POST, 'my-booking-form', $_POST['name'] ?? '' );

if ( 'allowed' !== $result['decision'] ) {
    // stop processing however fits this form — wp_die(), return an
    // error, redirect back with a message, etc.
    wp_die( 'Your submission looks automated and was not sent.' );
}

// otherwise continue processing the form as normal
`

The second and third arguments are optional and only affect what shows up in Veilo → Activity Log (a source label and a short preview text). This same function is what every built-in integration calls internally, so custom forms get identical scoring to comments, CF7, WPForms, Elementor, and Gravity Forms.

== Installation ==

1. Zip the `veilo` folder (the folder itself must be inside the zip, e.g. `veilo/veilo.php`).
2. In wp-admin: Plugins → Add New → Upload Plugin → choose the zip → Install → Activate.
3. Go to the new "Veilo" menu in the sidebar to choose which forms to protect and set the sensitivity threshold.
4. Submit a test comment or form entry, then check Veilo → Activity Log to see the score and reasons it was allowed or blocked.

== Frequently Asked Questions ==

= How does the score work? =

* Honeypot filled in → strong spam signal (bots fill every field)
* Submitted in under ~2 seconds → strong spam signal (too fast for a human)
* No mouse/touch/scroll at all → moderate spam signal
* Hidden fields missing entirely → the request likely skipped the browser/JS

Everything above 100% is capped; the threshold in Settings (default 50) decides where "probably spam" starts.

= Does this require Contact Form 7 or WPForms to be installed? =

Contact Form 7 support requires CF7 to be installed and active. WPForms support requires WPForms (free or Pro) to be installed and active. Elementor Forms support (Pro plan) requires Elementor Pro. Gravity Forms support (Pro plan) requires Gravity Forms. All integrations degrade gracefully — if the target plugin isn't installed, Veilo simply does nothing for that form type.

== Screenshots ==

1. Veilo Activity Log showing allowed and blocked submissions.

== Changelog ==

= 1.1.0 =
* Current release.

== Upgrade Notice ==

= 1.1.0 =
Current stable release.