WPPlugins AtoZ

Powered by WPPro AtoZ Host

Dante’s 9th Circle: Eternal Damnation for Email Form Spammers – Plugin Pulse: WP Plugins A to Z Unplugged #12

0:00 / 0:00
Dante’s 9th Circle: Eternal Damnation for Email Form Spammers – Plugin Pulse: WP Plugins A to Z Unplugged #12

Donate to the Show


cards
Powered by paypal

Watch The Video

TLDR Summary of Show

Show Summary
Episode 12 of Plugin Pulse: WP Plugins A to Z Unplugged is a solo deep dive with host John Overall, packed with unfiltered WordPress discussions, fresh plugin reviews, and practical tips. John opens the show with the usual high-energy welcome and announces a new interactive twist—live Google Meet sessions (limited to 2 people) to make the podcast more engaging moving forward. This week’s theme centers on unpopular ideas in the WordPress space, including a candid discussion on whether AI is poised to “kill” WordPress, alongside the usual mix of news, reviews, and community highlights.
The news segment spotlights a worrying wave of supply chain attacks hitting WordPress plugins, with detailed coverage of the WPFactory backdoor incident that led to over 80 plugins being pulled from the repository, plus additional incidents and proposed fixes from the community. On the plugin front, John reviews Security Ninja (rated 4 Dragons), praising its lightweight WAF, 50+ security checks, and vulnerability scanner while noting an irritating barrage of email confirmations during signup. He also live-tests Email Blacklist for Elementor Forms (5 Dragons), a simple but effective free tool for blocking spam emails and domains in Elementor Pro forms. The show’s featured premium plugin is ToggleWP, an all-in-one modular solution for agencies that includes client-proof site locks, white-labeling, admin guardrails, and built-in AI content tools to boost profitability and reduce churn.
John wraps up with actionable WordPress best practices—like fixing a sluggish admin dashboard, dequeuing bloat with advanced scripting techniques, generating clean SVG badges via Shieldcn.dev, and strong anti-spam strategies for Elementor forms (honeypots, domain blacklisting, etc.). He reminds listeners about the agency services at WPProAtoZ.com, encourages donations of time, talent, or treasure, and teases upcoming interviews. As always, the episode keeps it real, unplugged, and laser-focused on helping WordPress users and builders level up their sites.

Full Show Notes

Today I have discussions, opinions, plugins ……………. and more all coming up on Plugin Pulse: WP Plugins A to Z Unplugged.
Good Morning, Good Afternoon, Good Evening! — here..
Welcome to ‘Plugin Pulse: WP Plugins A to Z Unplugged!’ I’m your host, John Overall, bringing you the latest beat on all things WordPress. Where we dive in to spill the beans on the latest in the WordPress world, all unplugged and unfiltered, showcasing the freshest WordPress news, digging into a killer plugin demo, or exploring tips to level up your site. Today, I’ve got the mic to myself, and we’re pulsing through what’s hot, what’s new, and what you need to know. So, grab your coffee, fire up your dashboard, and let’s get into it!”

Today

Doing a weekly podcast can sometimes be a challenge to come up with content week after week, but lets get it started.
This week I am babbling about:
I am talking about unpopular ideas in WordPress today and I have a New Plugin review, discussion about Supply chain hacks, tips, plugin extras and more all coming up on Plugin Pulse: WP Plugins A to Z Unplugged.
Going to be doing something new and make this more interactive you can join the Google Meet https://meet.google.com/rph-jkui-rau limit 2 ppl this will continue for the next while and see how it goes.

The Weeks Discussions:

WordPress and Related News

More supply chain attacks on WordPress
and another
and another
possible solutions
A Fix for this mess by Austin Grinder

Checkout Summit Revamp

Plugin Reviews

Plugin 1

Security Ninja – WordPress Security & Firewall
The Lowdown:
Security Ninja is a lightweight WordPress security plugin that helps protect your site from common attacks and security mistakes — without turning your dashboard into a cockpit.
Free includes a basic Web Application Firewall (WAF) (based on the 8G ruleset) to block common malicious requests, plus 50+ security checks, a full vulnerability scanner, and a core integrity scanner to spot risky settings and unexpected file changes.
Upgrade to Pro if you need deeper protection like advanced malware scanning/cleanup, stronger WAF controls (e.g. country blocking), and more automation/alerting.
This plugin can be downloaded for free without any paid subscription from the official WordPress repository.
My only complaint is the number of email confirmations. I received over 10 of them in quick succession when I had hit skip for the email list and 3 days later another 20 emails asking me to confirm. This is irritating, what make it a bit more irritating is I never entered my email it grabbed it from the account I was using when I installed.
Rating 4 Dragons

V for V for the show

  If you get any value out of this show then donate that value back to the show. You can do so through time, talent, or treasure – or all 3!! – through our website wppluginsatoz.com.
Click on the ‘Treasure Donations’ link on the left-hand menu, or on the ‘Time, or Talent‘ pages to find out more!
Sign up for newsletter https://wppluginsatoz.com/news

Coding Tips:

Some great svg badges
Shieldcn is a free, open-source alternative to shields.io for generating README badges with shadcn/ui-inspired design quality. It offers 6 badge variants, 16 themes, 30,000+ built-in icons, and custom SVG upload support. Badges can be generated for GitHub, npm, Discord, and more via a simple URL-based builder.
In this article, we’re moving past basic enqueuing. We’ll show you how to interrogate the `$wp_scripts` global to identify hidden bloat and use high-priority dequeuing to strip away unnecessary assets without breaking your site’s critical dependencies. https://deliciousbrains.com/beyond-wp_enqueue/

This Shows Featured Promotion

 Every show I will be promoting a premium plugin I think might be useful for everyone. There is no affiliate links to them unless mentioned.  This is just to bring more attention to underknown premium plugins that can be of benefit.
This week the plugin is:

Toggle WP

The Lowdown:
The All-in-One Modular Plugin for WordPress Profitability. Stop firefighting support tickets and start scaling your margins. ToggleWP combines “Client-Proof” site locks with on-brand AI content creation to turn your maintenance plans into high-growth assets – all without the plugin bloat.
  • Agency Site Sync: Save hours with bulk site registration and settings sync across your entire portfolio.
  • White-label: ToggleWP is your secret sauce, brand it your way.
  • Admin Guardrails: Lock down critical plugins so clients can’t accidentally “deactivate” your hard work.
  • BYOK AI Content Hub: Upsell on-brand AI text services with zero monthly API markups. You keep 100% of the profit.
  • Revenue Retention: Give clients “sticky” features they can’t get from a budget host, drastically reducing your churn.
  • V1.1 includes 7 modules for free: What you get with ToggleWP free.

Plugin Reviews

Plugin 2

Doing it live Secondary Plugin:

Email Blacklist For Elementor Forms
The Lowdown:
If you need to prevent email addresses or entire email domains from being sent on an Elementor Form, this plugin will do that.
Stop unwanted Elementor Forms spam and create an email or domain name block list for your forms.
This is for Elementor Pro users only. This will not work with the free version of Elementor as it doesn’t support forms.
Rating: 5 Dragons We will see how it works out to how many Dragons

WordPress Items:

Tips on how to fix a slow dashboard.
See who’s online, although there is plugin for this.
If you’re a commercial plugin author, you can use free WP Plugin Info Card to add your plugin, enable a REST endpoint, and allow others to subscribe to your data.

Tip of The Day:

Form Spamers Deserve the 9th Level of Inferno – Here’s How to Banish Them

Elementor’s built-in Form widget (Pro) offers these main anti-spam options beyond CAPTCHA:

1. Honeypot Field (Built-in, Recommended First Step)

This is Elementor’s primary silent anti-spam tool. It adds a hidden field that humans don’t see or fill out, but bots often do.
  • Edit your form in Elementor.
  • Go to Form FieldsAdd Item.
  • Set Type to Honeypot.
  • Optionally customize the Label (e.g., something generic like “Website” or “Confirm Email”) — it stays hidden on the frontend.
  • Save and test. Any submission with content in the honeypot field is automatically rejected.
Tip: Add multiple honeypots with different labels for better protection against sophisticated bots.
Talk about us WPProAtoZ.com as an agency and what we do

Other Built-in or Simple Options

  • reCAPTCHA v2/v3 (or hCaptcha in some setups) — already mentioned, configurable in form settings.
  • Custom validation via code snippets (e.g., math questions or keyword blocks) is possible but not “built-in” UI.
For stronger protection, many users combine Honeypot + reCAPTCHA v3 + Akismet, or add third-party plugins like CleanTalk, OOPSpam, or Shield Security.

How to Block Specific Email Domains

Elementor does not have built-in domain blacklisting. Use one of these straightforward methods:

Easiest: Free Plugin (Recommended)

Install the Email Blacklist For Elementor Forms plugin (free on WordPress.org).
  • After activation, edit your form.
  • In the Content tab, you’ll see a new Email Blacklist field.
  • Add a comma-separated list, e.g.: bad@domain.com, @yandex.com, @spamdomain.ru
  • It blocks the submission and shows an error if the email matches.
This works per form and supports full emails or entire domains (prefix with @ for domains).

Alternatives

  • Custom code snippet (add to functions.php or a code plugin like WPCode): Check the email domain and add an error. Examples are available in various tutorials.
  • Advanced plugins like Maspik, SpamLock, or OOPSpam for global blacklists, IP blocking, keyword filtering, etc.
  • Code-based business-email-only filters (block free providers like @gmail.com).
Test thoroughly after setup (use incognito mode and dummy spam-like submissions). Honeypot + Akismet often reduces spam significantly without plugins. If spam persists, layer on domain blocking or a dedicated anti-spam service.

Pet Peeve This Week Or WP drama:

My continuing pet peeve is the search function for the plugin repo you search for an exact name of a plugin and it is way down the page or even more pages in.

Upcoming Interviews and Available times:

    Reminder that we have more interviews coming up in the coming weeks with more developers and community members https://wppluginsatoz.com/book-an-interview-on-wp-plugins-a-to-z-podcast/
Available interview dates:  June 1, 15 & 29th, July 13 & 27th  2026.

Other Shows and places to get WP Info & Training

The WP Builds Podcast
WP Roads
WP-Tonic
Worlds Worst Web Developer
WP Mayor
wp Minute

Table of Contents

Affiliate Links
  • Termageddon Use Termageddon to help comply with privacy laws such as the CPRA, GDPR, UK DPA, CalOPPA, PIPEDA, and more. They will also help you comply with consumer protection laws, provide eCommerce disclosures, and limit your liability. Click on our link here!
    Termageddon
  • Rank Math Rank Math is a fantastic company to work with on your sites SEO. The Free version will give you everything you need to get started and get your SEO up to a place where you will get noticed! The Premium version is like getting VIP Treatment when it comes to the tools available. The documentation they have available is in easy to read, every day language so that it does not require a degree to understand how to use the tools!
    Rank Math
  • Bunny.net Quick easy CDN that is affordable. Great prices, easy to use! Click on our link here!
    Bunny.net
  • Glow WP Maintenance Manager Use coupon code WPPAZ10 10% discount on their subscription, for life.
    Glow WP Maintenance Manager

Your Hosts

John Overall

Over 16 years a counting for WP Plugins A to Z more about John click this.

Amber Linn

Since 2020 Amber has been making WP Plugins A to Z the place to be more about Amber click this.

Highlighted Links
Categories
Archives

WP PLUGINS A to Z

SUBSCRIBE to the WP Plugins A to Z newsletter and get exclusive insights delivered straight to your inbox. – DON’T MISS OUT!

We don’t spam! Read our privacy policy for more info.

Book an Interview on WPPluginsAtoZ

If You're a Plugin/Theme Developer or WP Community Member

Book your interview now.