Filters comment and form spam through Automattic’s cloud anti-spam service, reducing manual moderation on WordPress sites.
WP Armour
WP Armour is a WordPress anti-spam plugin built around an invisible honeypot rather than a remote spam-scoring API. Its appeal is simple: activate it, let it add hidden fields to supported forms, and block automated submissions without showing visitors a CAPTCHA.
Quick take
WP Armour fits sites whose spam problem is mainly automated bots hitting WordPress comments, registrations, and popular form plugins. The free version supports WordPress comments and registration plus Contact Form 7, WPForms, Formidable Forms, Elementor Forms, Fluent Forms, Divi forms, bbPress, Toolset Forms, Theme My Login, and supported Gravity Forms configurations. It does not rely on an external anti-spam API, so its privacy model and detection method differ from services such as Akismet or CleanTalk.
Best fit: CAPTCHA-free local honeypot protection for WordPress comments and forms.
Free version: Yes.
Operating model: Local JavaScript-assisted honeypot filtering.
How WP Armour blocks automated spam
The plugin inserts a hidden honeypot field that normal visitors never need to complete. Bots that fill fields indiscriminately can reveal themselves by interacting with that field, allowing the submission to be rejected. WP Armour also generates a unique honeypot field name for each installation, which is intended to make one generic bypass less reusable across many websites.
This is materially different from a cloud reputation service. A remote service can score content, addresses, or reputation signals against a broader network. WP Armour instead focuses on detecting bot behavior locally. That keeps the workflow lightweight, but the two approaches should not be treated as identical.
Form coverage
The free edition documents protection for WordPress comments and registration plus many common form systems. This matters because spam often arrives through more than the native comment form. A site using a contact form, public registration, and comments can apply one honeypot layer across several entry points without configuring a separate CAPTCHA service.
WP Armour Extended adds more coverage and administration tools. The official listing describes spam submission records, spam-bot IP logging, repeat-IP blocking, keyword filtering, WooCommerce checkout and registration protection, Easy Digital Downloads, BuddyPress, BuddyBoss, SureForms, JetFormBuilder, MailPoet, Brevo, and additional form integrations.
Privacy and visitor experience
The free plugin states that it does not use tracking, cookies, or external server calls for spam filtering. Visitors also do not solve image puzzles or CAPTCHA challenges. That can be useful when accessibility, friction, or minimizing third-party processing is important.
Because the honeypot is inserted with JavaScript, test the actual forms after activation rather than assuming every custom front-end setup behaves identically. WP Armour includes an administrator-facing test panel for confirming whether protection is active on supported forms.
Free versus Extended
The free edition can be enough when you need basic bot protection on standard comments, registrations, and supported forms. Extended becomes more relevant when you need spam records, IP-based controls, keyword filtering, ecommerce checkout protection, BuddyPress or BuddyBoss coverage, or integrations outside the free list. Check the vendor’s current Extended offer before purchasing because pricing is not presented as a stable figure in the WordPress.org listing.
Trade-offs to consider
WP Armour is not trying to be a global content or reputation-scoring network. That is part of why it is lightweight, but it also defines the trade-off. Sites dealing mainly with automated bot submissions may fit the honeypot model well. Sites facing sophisticated human spam, disposable-email abuse, geographic abuse patterns, or high-risk ecommerce submissions may need additional signals from a cloud-based anti-spam service.
PluginSuggest verdict
WP Armour is worth considering when you want a low-friction, CAPTCHA-free anti-bot layer that stays local and supports more than native WordPress comments. Match its documented integration list to your forms and test each entry point after activation. If your workflow depends on reputation databases, content scoring, country controls, or more advanced abuse detection, compare a cloud service alongside it.
Frequently Asked Questions
Is WP Armour free?
Yes. The free edition protects WordPress comments, registration, and a documented list of popular form plugins. A paid Extended edition adds more integrations and controls.
Does WP Armour use CAPTCHA?
No. It uses an invisible honeypot technique, so normal visitors do not solve a challenge.
Does WP Armour send form data to an external anti-spam service?
The free plugin states that its spam filtering does not use external server calls, tracking, or cookie storage.
Can WP Armour replace Akismet?
It can replace Akismet when your main requirement is blocking automated spam on supported comments and forms. The detection model is different, so compare carefully if you rely on remote reputation or content scoring.
Does WP Armour work with WooCommerce?
The free listing includes WooCommerce Reviews Pro support, while Extended documents WooCommerce checkout and registration protection.
Compare before you install
Similar Plugins
Block WordPress comment and trackback spam without CAPTCHA or a paid service account, with privacy-focused filtering and flexible spam rules.
Cloud-based anti-spam for WordPress forms, comments, registrations, WooCommerce, logins, and other submissions without visitor CAPTCHAs.