=== Spam Trap ===
Contributors: yodsira
Tags: anti-spam, honeypot, spam, comments, registration
Requires at least: 6.5
Tested up to: 7.1
Requires PHP: 8.0
Stable tag: 1.1.0
License: GPL-2.0-or-later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Anti-spam without captcha or clouds: a honeypot field and a submission-time check on comments and registration. Nothing leaves the site.

== Description ==

Spam bots fill every field they see and submit instantly. Spam Trap
uses exactly that against them: a hidden field they cannot resist and
a speed check humans never fail - no captcha, no puzzles, no clouds.

= What it does =

* A hidden honeypot field on comment and registration forms. Bots fill
  it; the submission is silently dropped.
* A submission-time check: guests submitting within seconds of the
  page load are blocked.
* A local block log: form, trigger, time. No IPs, no submitted
  content - nothing personal is stored.
* Every check runs on your site; nothing is sent to anti-spam clouds.
* Works with High-Performance Order Storage (HPOS) - and with every
  caching setup, because the checks are form-side and stateless.

= Spam Trap Pro =

The Pro companion adds weekly reports, per-form statistics and a
Telegram alert when a bot wave hits. Learn more:
https://yodsira.com/en/product/spam-trap/

== Installation ==

1. Install the plugin through the WordPress plugins screen (Plugins ->
   Add New -> Upload Plugin) and activate it.
2. Done. The traps attach to comment and registration forms
   automatically.

== Frequently Asked Questions ==

= Will real users ever be blocked? =

The honeypot is invisible to humans. The time check applies only to
guests submitting instantly - real people take longer.

= Where is the data stored? =

In your own WordPress database: a small log of blocked submissions
(form, trigger, time). No IPs, no content.

= Is anything sent to third parties? =

No. Spam Trap works entirely on your site and sends nothing anywhere.

== Changelog ==

= 1.0.0 =
* First release: honeypot + time traps on comments and registration,
  local block log, admin settings.

== Privacy & Data ==

Spam Trap stores settings and a small block log in your own WordPress
database. Nothing is sent to any external service.
