Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
71 commits
Select commit Hold shift + click to select a range
5a2df8e
Udp.Code. frontend_data logger
datorik Aug 20, 2026
16f70c4
Udp.Code. frontend_data logger fix
datorik Aug 21, 2026
a7daff5
Potential fix for pull request finding
alexander-b-clean Aug 21, 2026
9de7a7f
Udp.Code. frontend_data logger fix. Code review
datorik Aug 21, 2026
5d524ea
Merge remote-tracking branch 'origin/frontend_data-logger.ab' into fr…
datorik Aug 21, 2026
6b431ce
Merge branch 'dev' into frontend_data-logger.ab
datorik Aug 21, 2026
80501e9
Fix errors psalm
AntonV1211 Aug 24, 2026
4c2e528
New. Code. IMetric service. Integrations performance metrics.
alexandergull Sep 2, 2026
6e3f1bf
New. Code. IMetric service. Ninja forms ready.
alexandergull Sep 2, 2026
876f0c8
New. Code. IMetric service. Woocommerce forms ready.
alexandergull Sep 2, 2026
2bddb2d
Merge branch 'refs/heads/dev' into integration-metrics.ag
alexandergull Sep 2, 2026
e5a8806
Fix. Auto-test. Before new units.
alexandergull Sep 2, 2026
2d61cf6
Upd. Dock blocks and comments.
alexandergull Sep 2, 2026
73e4218
Upd. Code. New units for iMetric.
alexandergull Sep 2, 2026
367910f
CP. Span lease logic updated.
alexandergull Sep 2, 2026
c9fd568
Cp. dumpVarsSize updated to prevent mutations if DTO not released.
alexandergull Sep 2, 2026
c6b8074
CP. Delete unused imports.
alexandergull Sep 2, 2026
a2200bf
CP. Fixed exception type.
alexandergull Sep 2, 2026
c25ceee
CP. Fixed dto-version set.
alexandergull Sep 2, 2026
c867c68
CP. Fixed indents.
alexandergull Sep 2, 2026
2616c75
Version: 6.87.99-dev.
Glomberg Sep 2, 2026
a77c69c
Version: 6.87.99-fix.
Glomberg Sep 2, 2026
f2102e1
Fix. Alt cookies. Validation `apbct_antiflood_passed` fixed.
Glomberg Sep 2, 2026
d84bf9f
Fix. Imetric. Cast to int float values.
alexandergull Sep 2, 2026
7602cec
Merge branch 'dev' into frontend_data-logger.ab
alexandergull Sep 2, 2026
6f86905
Fix. Cookie. Renaming the wordpress_apbct_antibot cookie
AntonV1211 Sep 3, 2026
9f73ac8
Merge fix
AntonV1211 Sep 3, 2026
8346aa4
Upd. BotDetectorService. FD log updates.
alexandergull Sep 3, 2026
43f4f32
Fix. AltSession. Editing in rest alt session endpoint
AntonV1211 Sep 3, 2026
5d382b6
CP. Fixed default statement.
alexandergull Sep 4, 2026
50d9f80
CP. Docblock updated.
alexandergull Sep 4, 2026
57db974
CP. Cookie prefix added.
alexandergull Sep 4, 2026
36484fd
Fix. Moderate url fixed.
alexandergull Sep 4, 2026
df91d2b
Fix. RemoteCalls. Edits by update_settings
AntonV1211 Sep 4, 2026
454a505
Fix. RemoteCalls. Edits by update_settings
AntonV1211 Sep 4, 2026
3840764
Upd. IMetricDTOTrait. Now integration metrics can be disabled via con…
alexandergull Sep 4, 2026
66fee98
Fix. ContactEncoder. Shortcode edits
AntonV1211 Sep 4, 2026
b706924
Fix unit tests
AntonV1211 Sep 4, 2026
5319141
Fix. Code. Edit check_value
AntonV1211 Sep 4, 2026
3ca367f
Fix. ContactEncoder. Unfreeze composer version. (#881)
svfcode Sep 7, 2026
11e64d7
Merge pull request #875 from CleanTalk/integration-metrics.ag
alexandergull Sep 7, 2026
cd6cf61
Upd. Settings. On wpms improve warnings appears. (#878)
svfcode Sep 7, 2026
747b4aa
Merge pull request #879 from CleanTalk/vuln_upd_settings_av
AntonV1211 Sep 7, 2026
f5b7eb8
Merge pull request #880 from CleanTalk/vuln_cont_encoder_av
AntonV1211 Sep 7, 2026
c9f3d81
Fix. SFW. Clearing SFW Outdated errors when updating by cron or in ma…
AntonV1211 Sep 7, 2026
aefef65
Upd. Frontend Data log. AltSession transport implemented.
alexandergull Sep 7, 2026
5e4ace0
CP. Fixed some cases.
alexandergull Sep 7, 2026
3196436
Merge pull request #882 from CleanTalk/sfw_outdate_av
AntonV1211 Sep 8, 2026
b6df611
Upd. Code. Make patterns for case-insensitivity and improve helper me…
svfcode Sep 8, 2026
914e29c
Mod. Banners. Editing texts in trial and renew banners
AntonV1211 Sep 8, 2026
ed00e2d
Upd. Frontend data log. AltSessions transport removed. Transport enab…
alexandergull Sep 8, 2026
799de6a
CP. Some fixes.
alexandergull Sep 8, 2026
11b9c2d
Upd. Removed altsessions artefact.
alexandergull Sep 8, 2026
d5a42c0
Merge pull request #864 from CleanTalk/frontend_data-logger.ab
alexandergull Sep 8, 2026
d317e7c
Merge pull request #876 from CleanTalk/nonce_alt_session_av
AntonV1211 Sep 9, 2026
4a127fb
Upd. ContactEncoder. Imrove area-label processing. (#866)
svfcode Sep 9, 2026
23cf05d
Merge branch 'fix' into dev
svfcode Sep 9, 2026
e77ac93
Fix. TRP. Editing styles
AntonV1211 Sep 9, 2026
51f9f95
Merge branch 'fix' of https://github.com/CleanTalk/wordpress-antispam…
AntonV1211 Sep 9, 2026
bd22469
Upd. ContactEncoder. Improve shortcode flow. (#884)
svfcode Sep 9, 2026
03a6a6c
Udp.Code. Add ip to white list
alexander-b-clean Sep 9, 2026
fe39e04
Fix. Psalm doc-block notice.
alexandergull Sep 11, 2026
1b1fab3
Upd. Settings. Cookie mode change notice. Changed the notice reason. …
alexandergull Sep 11, 2026
aef5c0c
New. ContactEncoder. Add option to exclude selected contact data. (#887)
svedge Sep 11, 2026
f37f12e
Fix. Code. Fixed compatibility with php8.5. (#888)
svedge Sep 11, 2026
7a620e2
Upd. Code. Remove unnecessary dependency.
svedge Sep 14, 2026
656d1d3
Udp.Code.Unit tests
alexander-b-clean Sep 14, 2026
3fdb754
Upd. Integrations. Improve ajax prefilter. (#889)
svedge Sep 15, 2026
a65b515
Merge fix into beta
svedge Sep 15, 2026
2669570
Merge dev into beta
svedge Sep 15, 2026
085ceb0
Update version
svedge Sep 15, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
47 changes: 13 additions & 34 deletions cleantalk.php
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
Plugin Name: Anti-Spam by CleanTalk
Plugin URI: https://cleantalk.org
Description: Max power, all-in-one, no Captcha, premium anti-spam plugin. No comment spam, no registration spam, no contact spam, protects any WordPress forms.
Version: 6.87
Version: 6.88
Author: CleanTalk - Anti-Spam Protection <welcome@cleantalk.org>
Author URI: https://cleantalk.org
Text Domain: cleantalk-spam-protect
Expand All @@ -15,6 +15,7 @@
use Cleantalk\Antispam\ProtectByShortcode;
use Cleantalk\ApbctWP\Activator;
use Cleantalk\ApbctWP\AdminNotices;
use Cleantalk\ApbctWP\BotDetectorService;
use Cleantalk\ApbctWP\Constant;
use Cleantalk\ApbctWP\ContactsEncoder\ContactsEncoder;
use Cleantalk\ApbctWP\Antispam\ForceProtection;
Expand Down Expand Up @@ -152,7 +153,7 @@
}

if ( ! defined('APBCT_BOT_DETECTOR_SCRIPT_URL') ) {
define('APBCT_BOT_DETECTOR_SCRIPT_URL', 'https://fd.cleantalk.org/ct-bot-detector-wrapper.js');
define('APBCT_BOT_DETECTOR_SCRIPT_URL', BotDetectorService::getWrapperUrl());
}

/**
Expand Down Expand Up @@ -1879,6 +1880,8 @@ function apbct_sfw_update__end_of_update($is_first_updating = false)

// Delete update errors
$apbct->errorDelete('sfw_update', true);
// Delete outdated errors
$apbct->errorDelete('sfw_outdated', true);

// Running sfw update once again in 12 min if entries is < 4000
if ( $is_first_updating &&
Expand Down Expand Up @@ -2349,35 +2352,6 @@ function apbct_rc__uninstall_plugin__check_deactivate()
$apbct->plugin_deactivated = true;
}

/**
* @param $source
*
* @return bool
*/
function apbct_rc__update_settings($source)
{
global $apbct;

foreach ( $apbct->default_settings as $setting => $def_value ) {
if ( array_key_exists($setting, $source) ) {
if ($setting === 'apikey') {
continue;
}
$var = $source[$setting];
$type = gettype($def_value);
settype($var, $type);
if ( $type === 'string' ) {
$var = preg_replace(array('/=/', '/`/'), '', $var);
}
$apbct->settings[$setting] = $var;
}
}

$apbct->save('settings');

return true;
}

/**
* @param string $key
* @param string $plugin
Expand All @@ -2390,7 +2364,7 @@ function apbct_rc__insert_auth_key($key, $plugin)
require_once(ABSPATH . '/wp-admin/includes/plugin.php');

if ( is_plugin_active($plugin) ) {
$key = trim($key);
$key = trim($key, " \n\r\t\v\x00");

if ( $key && preg_match('/^[a-z\d]{3,30}$/', $key) ) {
$result = API::methodNoticePaidTill(
Expand Down Expand Up @@ -2656,7 +2630,7 @@ function apbct_cookie()
// Cookie names to validate
$cookie_test_value = array(
'cookies_names' => array(),
'check_value' => $apbct->api_key . $apbct->data['salt'],
'check_value' => $apbct->api_key . $apbct->data['salt'] . '_apbct_cookies_test',
);

// We need to skip the domain attribute for prevent including the dot to the cookie's domain on the client.
Expand Down Expand Up @@ -2751,7 +2725,7 @@ function apbct_cookies_test()
return 0;
}

$check_string = $apbct->api_key . $apbct->data['salt'];
$check_string = $apbct->api_key . $apbct->data['salt'] . '_apbct_cookies_test';
// generate value
$cookie_names = TT::getArrayValueAsArray($cookie_test, 'cookies_names');
foreach ( $cookie_names as $cookie_name ) {
Expand Down Expand Up @@ -3197,6 +3171,11 @@ function apbctGetContactsEncoder()
$contacts_encoder_params->obfuscation_text = $apbct->settings['data__email_decoder_obfuscation_custom_text'];
$contacts_encoder_params->do_encode_emails = (int)$apbct->settings['data__email_decoder_encode_email_addresses'];
$contacts_encoder_params->do_encode_phones = (int)$apbct->settings['data__email_decoder_encode_phone_numbers'];
$contacts_encoder_params->excluded_strings = \Cleantalk\Common\ContactsEncoder\Exclusions\ExclusionsService::parseExcludedStrings(
isset($apbct->settings['data__email_decoder_excluded_strings'])
? $apbct->settings['data__email_decoder_excluded_strings']
: ''
);

return ContactsEncoder::getInstance($contacts_encoder_params);
}
11 changes: 9 additions & 2 deletions composer.json
Original file line number Diff line number Diff line change
Expand Up @@ -16,11 +16,18 @@
"yoast/phpunit-polyfills": "^1.0",
"ext-dom": "*",
"wp-cli/wp-cli-bundle": "*",
"mockery/mockery": "*",
"cleantalk/apbct-installer": "*",
"cleantalk/contacts-encoder": "2.0.18.7",
"cleantalk/contacts-encoder": "^2.2.0",
"cleantalk/rate-limiter": "*"
},
"replace": {
"cleantalk/antispam": "*",
"cleantalk/helper": "*",
"cleantalk/http": "*",
"cleantalk/variables": "*",
"cleantalk/cleaner": "*",
"cleantalk/mloader": "*"
},
"scripts": {
"test": [
"vendor/bin/phpunit --configuration tests/phpunit.xml --coverage-clover=coverage.xml",
Expand Down
2 changes: 1 addition & 1 deletion css/cleantalk-admin-settings-page.min.css

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion css/cleantalk-trp.min.css

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

4 changes: 4 additions & 0 deletions css/src/cleantalk-admin-settings-page.css
Original file line number Diff line number Diff line change
Expand Up @@ -59,6 +59,10 @@ i.animate-spin {
font-size: 14px;
vertical-align: top;
}
.apbct_settings-field_title--with-help{
width: auto;
white-space: nowrap;
}
.apbct_settings-field_title--radio{
display: inline-block;
margin: 0;
Expand Down
5 changes: 0 additions & 5 deletions css/src/cleantalk-trp.css
Original file line number Diff line number Diff line change
Expand Up @@ -55,11 +55,6 @@
flex-direction: column;
gap: 1px;
}
@media (min-width: 768px) {
.apbct-real-user-popup-content_row {
white-space: nowrap;
}
}

.apbct-real-user-popup-content_row * {
color: grey;
Expand Down
6 changes: 5 additions & 1 deletion inc/apbct-sync-react.php
Original file line number Diff line number Diff line change
Expand Up @@ -42,7 +42,11 @@ function apbct_react_access_key_check()
);
}

$apbct->errorDeleteAll(true);
$clear_all_blogs = APBCT_WPMS
&& is_main_site()
&& isset($apbct->network_settings['multisite__work_mode'])
&& (int) $apbct->network_settings['multisite__work_mode'] === 2;
apbct_settings__clear_errors($clear_all_blogs);

$account_is_ok = (bool) ct_account_status_check($apbct->settings['apikey']);
$connection_error = ! empty($apbct->errors['account_check'])
Expand Down
2 changes: 1 addition & 1 deletion inc/cleantalk-admin.php
Original file line number Diff line number Diff line change
Expand Up @@ -48,7 +48,7 @@ function apbct_admin_set_cookie_for_anti_bot()
echo
'<script ' . (class_exists('Cookiebot_WP') ? 'data-cookieconsent="ignore"' : '') . '>
var ctSecure = location.protocol === "https:" ? "; secure" : "";
document.cookie = "wordpress_apbct_antibot=' . apbct_get_anti_bot_cookie_hash() . '; path=/; expires=0; samesite=lax" + ctSecure;
document.cookie = "apbct_antibot=' . apbct_get_anti_bot_cookie_hash() . '; path=/; expires=0; samesite=lax" + ctSecure;
</script>';
}
}
Expand Down
146 changes: 16 additions & 130 deletions inc/cleantalk-common.php
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,7 @@
use Cleantalk\Antispam\CleantalkResponse;
use Cleantalk\ApbctWP\API;
use Cleantalk\ApbctWP\BaseCall\DefaultParams;
use Cleantalk\ApbctWP\BotDetectorService;
use Cleantalk\ApbctWP\CleantalkSettingsTemplates;
use Cleantalk\ApbctWP\Constant;
use Cleantalk\ApbctWP\Cron;
Expand Down Expand Up @@ -744,7 +745,7 @@ function apbct_get_pixel_url($direct_call = false)
*/
function apbct_email_check_before_post()
{
$email = trim(TT::toString(Post::get('email')));
$email = trim(TT::toString(Post::get('email')), " \n\r\t\v\x00");

if ( $email ) {
$result = \Cleantalk\ApbctWP\API::methodEmailCheck($email);
Expand All @@ -762,7 +763,7 @@ function apbct_email_check_before_post()
function apbct_email_check_exist_post()
{
global $apbct;
$email = trim(TT::toString(Post::get('email')));
$email = trim(TT::toString(Post::get('email')), " \n\r\t\v\x00");
$api_key = $apbct->api_key;
$brandname = $apbct->data['wl_mode_enabled'] ? $apbct->data['wl_brandname'] : 'Anti-Spam by CleanTalk';
if ( $email && $api_key ) {
Expand Down Expand Up @@ -1152,7 +1153,7 @@ function ct_get_fields_any($arr, $email = '', $nickname = '')
foreach ( $nickname as $value ) {
$nickname_str .= ($value ? $value . " " : "");
}
$nickname = trim($nickname_str);
$nickname = trim($nickname_str, " \n\r\t\v\x00");
}

return ct_gfa($arr, TT::toString($email), TT::toString($nickname));
Expand Down Expand Up @@ -1813,156 +1814,41 @@ function apbct_get_event_token($params)
}

/**
* Do prepare exclusions for skippping bot-detector event token field.
* Prepare exclusions for skippping bot-detector event token field.
* @deprecated since 6.88, use BotDetectorService::getPreparedExclusions() instead
* @return string JSOn
*/
function apbct__bot_detector_get_prepared_exclusion()
{
global $apbct;
$bot_detector_exclusions = array();

//start exclusion there

//todo if do need to add a built-ib exclusion, use $exlusion_format
//set regexp to chek within attributes
// $exlusion_format = array(
// 'exclusion_id' => '',
// 'signs_to_check' => array(
// 'form_attributes' => '',
// 'form_children_attributes' => '',
// 'form_parent_attributes' => ''
// )
// );
if ($apbct->settings['exclusions__bot_detector']) {
$bot_detector_exclusions = array_merge(
$bot_detector_exclusions,
apbct__bot_detector_get_custom_exclusion_from_settings()
);
}

//start validate
$bot_detector_exclusions_valid = array();
foreach ($bot_detector_exclusions as $exclusion) {
if (
empty($exclusion['exclusion_id']) ||
(
empty($exclusion['signs_to_check']['form_attributes']) &&
empty($exclusion['signs_to_check']['form_children_attributes']) &&
empty($exclusion['signs_to_check']['form_parent_attributes'])
)
) {
continue;
}
$bot_detector_exclusions_valid[] = $exclusion;
}

//prepare for early localize
$bot_detector_exclusions_valid = json_encode($bot_detector_exclusions_valid);
return $bot_detector_exclusions_valid !== false ? $bot_detector_exclusions_valid : '{}';
return BotDetectorService::getPreparedExclusions();
}

/**
* @deprecated since 6.88, use BotDetectorService::getFrontendDataLog() instead
* @return string
*/
function apbct__bot_detector_get_fired_exclusions()
{
return Cookie::get('ct_bot_detector_form_exclusion');
return BotDetectorService::getFiredExclusions();
}

/**
* Return bot detector frontend data log from Alt Sessions if data found.
* Format: JSON.
*
* @deprecated since 6.88, use BotDetectorService::getFrontendDataLog() instead
* @return string JSON encoded bot detector frontend data log.
*/
function apbct__bot_detector_get_fd_log()
{
$result = array(
'plugin_status' => 'OK',
'error_msg' => '',
'frontend_data_log' => ''
);
// Initialize result array with default values

if (Constant::is(Constant::APBCT_SERVICE__DO_NOT_COLLECT_FRONTEND_DATA_LOGS)) {
$result['plugin_status'] = 'OK';
$result['error_msg'] = 'bot detector logs collection is disabled via constant definition';
return json_encode($result);
}

try {
if ( ! apbct__is_bot_detector_enabled() ) {
throw new \Exception('bot detector library usage is disabled');
}
// Retrieve bot detector frontend data log from Alt Sessions
$alt_sessions_fd_log = AltSessions::get('ct_bot_detector_frontend_data_log');
// Check if the retrieved data is a string
if ( !is_string($alt_sessions_fd_log) || '' === $alt_sessions_fd_log ) {
throw new \Exception('no log found in alt sessions');
}
// Encode the retrieved data to JSON format
$param_bot_detector_fd_log = json_decode($alt_sessions_fd_log, true);
// Check if the JSON encoding was successful
if ( empty($param_bot_detector_fd_log) ) {
throw new \Exception('can not decode data from alt sessions');
}
} catch (Exception $e) {
$result['plugin_status'] = 'ERROR';
$result['error_msg'] = $e->getMessage();
return json_encode($result);
}
$result['frontend_data_log'] = $param_bot_detector_fd_log;
// Return the result as a JSON encoded string
return json_encode($result);
}

function apbct__bot_detector_get_custom_exclusion_from_settings()
{
global $apbct;

$exlusion_format = array(
'exclusion_id' => '',
'signs_to_check' => array(
'form_attributes' => '',
'form_children_attributes' => '',
'form_parent_attributes' => ''
)
);

$exclusions = array();
if (!$apbct->settings['exclusions__bot_detector']) {
return $exclusions;
}

foreach ($exlusion_format['signs_to_check'] as $sign => $_val) {
$setting_name = 'exclusions__bot_detector__' . $sign;
if (!empty($apbct->settings[$setting_name])) {
$regexps = explode(',', $apbct->settings[$setting_name]);
for ( $i = 0; $i < count($regexps); $i++ ) {
$form_exclusion = $exlusion_format;
$form_exclusion['exclusion_id'] = 'exclusion_' . $i;
$form_exclusion['signs_to_check'][$sign] = $regexps[$i];
$exclusions[] = $form_exclusion;
}
}
}
return $exclusions;
return BotDetectorService::getFrontendDataLog();
}

/**
* Check if Bot-Detector is enabled/disabled
*
* @deprecated since 6.88, use BotDetectorService::isEnabled() instead
* @return bool
*/
function apbct__is_bot_detector_enabled()
{
global $apbct;

// Constant is preferred
if ( Constant::is(Constant::APBCT_SERVICE__BOT_DETECTOR_ENABLED) ) {
return (bool) Constant::getValue(Constant::APBCT_SERVICE__BOT_DETECTOR_ENABLED);
}
// Check by $apbct->data
if ( isset($apbct->data['bot_detector_enabled']) ) {
return (bool) $apbct->data['bot_detector_enabled'];
}
// By default - enabled
return true;
return BotDetectorService::isEnabled();
}
2 changes: 1 addition & 1 deletion inc/cleantalk-public-integrations.php
Original file line number Diff line number Diff line change
Expand Up @@ -178,7 +178,7 @@ function ct_woocommerce_wishlist_check($args)
$subject = '';
$email = $args['wishlist_owner_email'];
if ( $args['wishlist_first_name'] !== '' || $args['wishlist_last_name'] !== '' ) {
$nickname = trim($args['wishlist_first_name'] . " " . $args['wishlist_last_name']);
$nickname = trim($args['wishlist_first_name'] . " " . $args['wishlist_last_name'], " \n\r\t\v\x00");
} else {
$nickname = '';
}
Expand Down
Loading
Loading