Signed browser proof
An expiring, server-verifiable token separates ordinary visitors from blind submission bots.
RockSolid by Klyrone
Layered WordPress form protection without CAPTCHAs, visitor tracking, or sending private submissions to another company.
ALLOW signed_token · normal_velocity
FLAG token_missing · score_35
BLOCK honeypot · duplicate_content
DEFENSE IN DEPTH
RockSolid combines independent signals into an explainable score, making it harder for bots to bypass protection and easier for you to tune it.
An expiring, server-verifiable token separates ordinary visitors from blind submission bots.
Automated field-fillers reveal themselves without making people solve a challenge.
Implausibly fast submissions contribute to a combined risk score instead of causing brittle one-rule blocks.
Link density, configurable phrases, gibberish, and duplicate messages expose common outreach spam.
Atomic per-IP and per-email counters slow repeated attacks while failing open if storage is unavailable.
Review scores and reason codes without duplicating names, emails, messages, or raw IP addresses.
CONTROLLED ROLLOUT
Every site has different traffic. RockSolid starts in monitor mode so you can inspect real scores before enforcement.
In WordPress, open Plugins → Add New → Upload Plugin, then activate RockSolid.
Review privacy-safe scores and reason codes under Settings → RockSolid Anti-Spam.
Tune thresholds if needed, switch to Enforce, and keep the independent protection layers active.
BUILT BY KLYRONE
Install the complete local protection layer today. WordPress.org distribution is in preparation.