=== Spamadin ===
Contributors: brandify
Tags: spam, antispam, contact form, comments, privacy
Requires at least: 6.6
Tested up to: 7.1
Requires PHP: 8.1
Stable tag: 1.1.0
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Protect comments and contact forms with contextual spam checks. No CAPTCHA, with recovery paths for legitimate messages.

== Description ==

Spamadin connects your WordPress website to the Spamadin spam-checking service. An active Spamadin subscription is required. Website and monthly spam-check limits depend on your plan.

* WordPress comments: spam goes to the spam queue; uncertain or unavailable checks go to moderation. Other moderation rules remain in effect.
* Contact Form 7, WPForms, Gravity Forms, Fluent Forms and Elementor Pro: supported server-side hooks check message fields before normal notifications or form actions.
* Private recovery inbox: held form messages stay in Settings → Spamadin for up to 30 days. Review messages and contact genuine senders directly. Spamadin does not replay emails, payments or other form actions.
* Optional invisible form evidence: bounded interaction counts and signed timing tokens support classification. Paste, autofill, fast submission, shared networks or missing JavaScript alone never establish spam.
* Moderator corrections: changing a comment to spam or restoring it, or correcting a held message, sends a check reference and label to Spamadin. It does not share the message body for training.

The recovery inbox is limited to 500 messages, each at most 64 KiB. If it is full, busy or unavailable, the plugin preserves the normal form workflow instead of discarding a message. An administrator warning signals the issue. The website's other spam filters can still block messages.

WordPress has no built-in contact form. Arbitrary custom forms, login/registration forms, WooCommerce checkout, and plugins not listed above are not automatically intercepted. Developers can integrate custom forms with the Spamadin server API.

= External service and privacy =

Connecting requires explicit confirmation before sending messages. Spamadin receives the site URL, message text, submission type, limited form/page context and optional browser evidence. Connection also sends your public website name and description to categorize the website. Visitor IP forwarding is off by default and can be enabled separately.

The browser script collects only counts and flags. It does not record typed text, clipboard contents, mouse trails, cookies or persistent visitor identifiers. It contacts your own WordPress server; your service API key never appears in browser requests.

Routine checks do not retain message bodies on Spamadin. The service requires zero-data-retention AI provider routes. Check and usage metadata follow Spamadin's privacy policy. Comments and held form messages remain in your own WordPress database. Held messages support WordPress's personal data export/erasure tools when an email field identifies the sender. Scheduled cleanup needs working WP-Cron or a server cron.

The plugin uses only https://spamadin.com/api/v1/ endpoints. No AI provider API key is needed. The hostname comes from WordPress's configured home URL and is enforced by Spamadin's backend. Blocking a website in Spamadin stops its checks and frees its plan slot. Plugin disconnection only stops local checks. Block the website in the Spamadin dashboard to free its slot.

Service terms: https://spamadin.com/terms
Privacy policy: https://spamadin.com/privacy
API documentation: https://spamadin.com/docs
Support: support@spamadin.com

== Installation ==

1. Upload spamadin.zip through Plugins → Add New → Upload Plugin, then activate it.
2. Subscribe to Spamadin and verify your account email.
3. In your Spamadin dashboard create your account API key. Use this same key for every website in your plan.
4. In WordPress open Settings → Spamadin, paste the account API key, confirm the privacy notice, and connect.
5. Comments and supported contact forms are protected by default. Choose your optional settings and review held messages regularly.

Connecting adds your website automatically within the plan limit. Reconnecting the same website is safe. Block a website in Spamadin to stop its requests and free its plan slot; it remains blocked until you explicitly allow it again. Rotating or revoking the account key affects every website using it. After rotation, paste the replacement key into each integration.

API keys are encrypted using authenticated encryption and WordPress's authentication salts. Changing those salts requires reconnection. OpenSSL is required. Never share database backups or WordPress configuration files containing your salts.

Multisite uses separate settings and credentials for each blog. Each distinct enabled hostname uses a plan slot; sites sharing one hostname share Spamadin's hostname scope. Configure each blog explicitly.

== Frequently Asked Questions ==

= Does it delete comments or send training data automatically? =

No. Comments use WordPress queues and normal WordPress retention. Held form messages are private local records with scheduled 30-day cleanup. Corrections send metadata only. Sharing training examples is a separate, explicit opt-in feature of the Spamadin API; this plugin does not enable it.

= What happens when checks cannot complete? =

Comments are preserved for moderation. Supported forms are held in the local recovery inbox when storage is available. Other spam filters and native validation remain authoritative. Monitor administrator notices and inbox capacity.

= Will this run alongside other spam filters? =

Existing spam or validation failures are respected and skip unnecessary checks. Test your specific theme, caching rules and form add-ons before launch. Uncertain verdicts never override another filter's spam decision.

== Changelog ==

= 1.1.0 =
Reusable account API key, automatic website registration, account-scoped website blocks, comments, five form adapters, optional browser evidence, private recovery inbox, moderator feedback and local privacy tools.
