Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
40 commits
Select commit Hold shift + click to select a range
7b460ae
Fix. Integrations. Improve statement to attaching assets on login page.
svfcode Aug 18, 2026
9d02123
Fix. ContactEncoder. Improve compatibility with WP Grid Builder.
svfcode Aug 18, 2026
9aa56cd
New. Integrations. Add compatibility with WebMagicStudio. (#860)
svfcode Aug 18, 2026
59767a2
Upd version 6.86.99-dev
AntonV1211 Aug 19, 2026
4864655
Merge master, rebuild react js
AntonV1211 Aug 19, 2026
d0762b8
Upd version 6.86.99-fix
AntonV1211 Aug 19, 2026
a7e26c2
Fix. ContactEncoder. Improve shortcode statement. (#861)
svfcode Aug 19, 2026
5417499
Fix. ContactEncoder. Improve shortcode statement.
svfcode Aug 19, 2026
e4197ab
fix test
svfcode Aug 19, 2026
3a82ac5
fix psalm
svfcode Aug 19, 2026
9a8cc03
Fix. FW. Improve AC module to correct processing loopback. (#862)
svfcode Aug 20, 2026
0c2da87
Fix. FW. Improve flow on block page to reduce duplicate headers.
svfcode Aug 20, 2026
95ac965
Fix. ContactEncoder. Improve shortcode statement. (#863)
svfcode Aug 20, 2026
d571fdd
Upd. Code. Security review
alexander-b-clean Aug 21, 2026
d9bcedf
Fix. Settings. Update notify statement for approved comments.
svfcode Aug 21, 2026
a1bad4a
Ref. Cookie. Removing unnecessary code
AntonV1211 Aug 24, 2026
5fafddf
Fix error test
AntonV1211 Aug 24, 2026
cb0e3b5
Fix errors psalm
AntonV1211 Aug 24, 2026
4624eea
Merge pull request #865 from CleanTalk/gfa_check_av
AntonV1211 Aug 24, 2026
a27a1d7
New. Settings. Add CSP nonce support. (#868)
svfcode Aug 26, 2026
7ab3f42
Fix. Settings. Add localize to form sign.
svfcode Aug 26, 2026
c76cbca
Fix. Settings. Improve template processing.
svfcode Aug 26, 2026
f5d8065
Fix. ContactEncoder. Skip encoding inside excluded HTML attributes. (…
svfcode Aug 27, 2026
433ec83
New. Settings. Warn user before cookie mode changed if a cache detect…
alexandergull Aug 28, 2026
5d607c6
CP. Typo fix.
alexandergull Aug 28, 2026
b0602ca
Fix. Connection reports. Deleted old (6 months) reports. (#871)
Glomberg Aug 31, 2026
6fcdb36
Fix. Request. Fallback to socket when cURL is unavailable
AntonV1211 Aug 31, 2026
d179808
Fix errors
AntonV1211 Aug 31, 2026
2c7b891
Fix errors
AntonV1211 Aug 31, 2026
833cefa
Unit tests
AntonV1211 Aug 31, 2026
8b8ea5a
Merge pull request #872 from CleanTalk/fallback_request_av
AntonV1211 Aug 31, 2026
b4e571d
Merge pull request #870 from CleanTalk/warn-cookies-change.ag
alexandergull Aug 31, 2026
8e3f372
Merge remote-tracking branch 'origin/fix' into dev
Glomberg Sep 1, 2026
2b4771b
Fix. Code. JS re-minified.
Glomberg Sep 1, 2026
13c46ef
Upd. Version. Version up to 6.87.
Glomberg Sep 1, 2026
d76ea06
Upd. Readme. Changelog updated.
Glomberg Sep 1, 2026
48d67e1
Fix. SFW. User agents priority fixed. (#874)
Glomberg Sep 1, 2026
e442eef
Merge remote-tracking branch 'origin/dev' into beta
Glomberg Sep 1, 2026
920776f
Upd. Readme. Changelog updated.
Glomberg Sep 1, 2026
4dd14d7
Upd. Readme. Changelog updated.
Glomberg Sep 2, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
153 changes: 153 additions & 0 deletions changelog.txt
Original file line number Diff line number Diff line change
@@ -1,5 +1,158 @@
== Changelog ==


= 6.78 29.04.2026 =
* Removing the link to install "Gravity Forms to doBoard" (#784)
* Mod. BloomForms. Editing the integration with BloomForms
* Update inc/cleantalk-settings.php
* Upd. Integrations. Improve Divi newsletters flow to attach meta data to request.
* Add "Read more" link to cleantalk page (#782)
* New. BaseCall. Default params class.
* Fix. REST API. Updated 'email' argument type from 'email' to 'string' in callbacks.
* Fix. GFA. Replaced email regex with isEmailLike method and added unit tests for validation.
* Upd. Integrations. Improve Divi newsletters flow to attach meta data to request. (#786)
* Ref. AntiCrawler. Module flow refactored. (#788)

= 6.77 16.04.2026 =
* Fix. AltSession. Correcting the issue of array conversion
* New. BookingCalendar. New integration with BookingCalendar
* Upd. Settings. Updated flow to check pingback. (#764) (#773) (#774)
* Fix. CF7. Edit honeypot
* Fix. Integration. EDD integration fixed. (#770)
* Fix. Code. Editing the bot detector settings
* Fix. Exclusion. Skip request from Metorik Helper
* Fix. Common. Add bot detector state to ct_options. (#778)
* Fix. WPMS. Errors output for WPMS mutual-mutual mode fixed. (#772)
* Fix. WPMS. Settings for `mutual/mutual` fixed.
* Fix. WPMS. Settings page error fixed.

= 6.76 02.04.2026 =
* Mod. ForceAltCookies. Removed the use of force alt cookies for integration with piotnet-addons-for-elementor
* Upd. Integrations. Improve FluentBooking flow to attach meta data to request.
* Upd. Settings. Updated flow to check pingback.
* Upd. Settings. Bot Detector setting - bot-detector setting removed.
* Fix. Code. Unit tests fixed: TestFluentForms, TestNinjaForms.
* Fix. JS. Gathering. Passing js_on independent of gathering loaded.
* Fix. Integrations. QuForm. Fixed js_on param gathering.

= 6.75 19.03.2026 =
* Upd. JS. catchJqueryAjax. Refactored to also use ajaxPrefilter. Bloomform now skip using force alt-sessions.
* Upd. ContactEncoder. Improve aria labels protect.
* Upd. Integration. HivePress forms protection improved.
* Upd. Settings. SFW outdated message refactored.
* Upd. Settings. Error. Fixed case when SFW outdated error is not removable.
* Upd. TRP. TRP popup text and styles updated.
* Fix. Integrations. Improve statement to protect memberpress.
* Fix. Integrations. Improved membershippro processing statement.
* Fix. Integration. Gravity forms integration fixed.
* Add. Integrations. Added Elfsight compability.
* Fix. RemoteCalls. Changes to the RC functionality
* Upd. Settings. Improved copability.
* Fix. Contacts Encoder. Shortcode for exclude encoding.
* Upd. BotDetector. Update load strategy.
* Upd. BotDetector. Update load strategy for fluent booking and fluent form.

= 6.74 05.03.2026 =
* Mod. SFW. Atomic approach to updating SFW
* Upd. Exclusions. Ajax. Plugin "cart-recovery".
* Fix. Code. JS loading by defer fixed.
* Mod. OtterForms. Changing integration from a hook to a route
* Mod. OtterForms. Changing the integration, renaming the request interception method
* Upd. Connection reports. Email subject updated.
* Fix. JS. catchFetchRequest. Origin fetch definitions.
* Upd. Exclusions. Ajax. Plugin "invoicing".
* Upd. Gravity Forms. Skipped request extended log.
* Fix. Translate. Fixed msgids.
* Upd. Connection reports. Email title edited.
* Upd. Connection reports. Service id added.
* Fix. SubmitTime. Calculation of the submit time when enabling the gathering script
* Upd. SFW updates sentinel. Updated report.
* Upd. Settings. Updated RC to init settings update.
* Fix. SubmitTime. Editing the creation of a timestamp

= 6.73.1 19.02.2026 =
* Fix. Code. JS loading by `defer` fixed.

= 6.73 19.02.2026 =
* Upd. Code. SFW Update. HTTP multi request refactored.
* New. ShadowrootProtection. Implementation of form protection in Shadowroot elements, integration with Mailchimp shadowroot
* Mod. ShadowrootPrt. Architectural changes in logic, the addition of situational callbacks
* Fix. CurlMulti. Editing implementation comments
* Fix. Integration. Ninja forms. Filter NF common fields before processing.
* Fix. Exclusions. "woocommerce-abandoned-cart"
* Fix. Exclusions. "woo-abandoned-cart-recovery"
* Fix. Exclusions. "abandoned-cart-capture"
* Fix. Code. Returned the lost code during the merge
* Fix. FluentForm. Vendor integration compliance fixed.
* Upd. Integrations. Elementor UltimateAddons Register integration handler to use ajax middleware.
* Fix. IntegMailChimp. Clearing all fields except for the field whose name contains message
* Fix. Code. Edit Remote Calls
* Fix. AdminActions. Checking permissions for Actions
* Upd. Exclusions. Ajax. Plugin "wp-multi-step-checkout".
* Fix. Exclusions. Ajax. Plugin "woo-abandoned-cart-recovery". Fixed condition.
* Code. Unit tests for apbct_is_skip_request() refactored.
* Fix. Code. Escaping woocommerce order data
* Upd. Exclusions. Ajax. Plugin "woocommerce-sendinblue-newsletter-subscription"
* Fix. Remote Calls. Skip check if no sign of RC action provided in Request.
* Fix. Exclusion. Added path invoice4u/v1/callback.
* Fix. Contact Encoder. Every hook that has actions BEFORE modify now have actions AFTER.
* Fix. Enqueue. Script individual-disable-comments.js renamed to cleantalk-individual-disable-comments.js
* Upd. CommentsCheck. Improve statement.
* Upd. JS parameters. Gathering dynamic lod implemented.
* Fix. Connection reports. Email for reports fixed.
* Fix. Integration. SmartQuizBuilder integration fixed.
* Fix. ContentEncoder. Editing the data type in the 3rd str_replace argument

= 6.72 05.02.2026 =
* Upd. WooCommSpamOrders. Added a hint for the disabled option to save spam orders.
* Fix. Integrations. Fluent Forms. Visible fields collection fixed.
* Fix. Integrations. Skip encoding for woo registration button. (#722)
* Upd. Integration. Mailpoet. Visible fields gathering.
* Upd. Visible fields extractor. Static method to get a new extractor.
* Fix. Integration. Exclusions for WC requests fixed.
* Fix. Integrations. GiveWP multi-page form. Exclude requests without email.
* Fix. Integrations. GiveWP. Skip external forms check.
* Fix. Integrations. GiveWP. Bot detector token. Intercept iframe fetch to add field if available.
* Fix. Integrations. Fixed fetch request fields assignment (NoCookie|EventToken)
* Fix. Woocommerce. Stored oreders. Fixed code error.
* Mod. ContentEncoder. The ability to exclude the main page by hook
* Fix. Code. Getting cleantalk addresses fixed.
* Fix. Integrations. Add event token in jQuery catching for forms of "wpr_form_builder_email" action.
* Upd. Footer. Footer promo link added. (#729)
* Fix. Integrations. WooCommerce. Stripe express checkout address normalize excluded.
* Fix. Integrations. Paid Membership Pro. Login form excluded.
* Upd. Updater. Add index update mechanism. (#721)
* Fix. Skip Elementor login widget request for WooCommerce checkout.
* Fix. Integration. Mailpoet integration fixed.

= 6.71.1 26.01.2026 =
* Fix. Promotion. GF2DB promo setting and message reverted.

= 6.71 22.01.2026 =
* Fix. Integration. Woocommerce (checkout by REST) integration fixed.
* Fix. Integration. Fluent forms integration fixed
* Fix. Integration. Klaviyo (external forms) integration fixed.
* Upd. PHPUnit. testIsAllowMessage/User refactored
* Fix. Settings. Description for Send connection reports fixed.
* Fix. Contacts Encoder. Exclusions fixed.
* Fix. Contacts Encoder. Regex pattern for emails fixed.
* Upd. Links. UTM preset for bbPress spam scanner added.
* Fix. Fetch request catching. Fixed case with empty GET requests from pojo-accessebility plugin.
* Fix. SFW pages. Fixed bundle name with resolver.
* Fix. Common. Helper. PHP 8.4. Function str_getcsv() escape argument added
* Fix. Workflow. Make the zip with subfolder instead of zip-root.
* Fix. Exclusions by URL. Fixed validation and URL gain for ajax requests.
* Upd. Requirements Checker. Modified curl_multi_exec to curl_multi array of functions.
* Upd. SFW update. Do not start update if curl multi funcs are not available.
* Fix. Integrations. Excluded recaptcha from cloning and ensured it is reinserted into the origin form during processing.
* Fix. Integrations. Update condition to skip check of account update for logged in users.
* New. Promotions. GF2DB.
* New. Settings. Added RC to init settings update.
* New. Integration. Bit Form integration implemented.
* Upd. Code. PHP compatibility increased to 7.2.
* New. Settings. Added project management menu item.
* Fix. SFW. User agents priority fixed. (#874)

= 6.70.1 19.12.2025 =
* Fix. Integration. Fluent forms integration fixed (fix for commit ae74511a96417b607f2b79b83ef984de7eac0588).

Expand Down
14 changes: 8 additions & 6 deletions cleantalk.php
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
Plugin Name: Anti-Spam by CleanTalk
Plugin URI: https://cleantalk.org
Description: Max power, all-in-one, no Captcha, premium anti-spam plugin. No comment spam, no registration spam, no contact spam, protects any WordPress forms.
Version: 6.86
Version: 6.87
Author: CleanTalk - Anti-Spam Protection <welcome@cleantalk.org>
Author URI: https://cleantalk.org
Text Domain: cleantalk-spam-protect
Expand Down Expand Up @@ -347,6 +347,7 @@ function apbct_register_my_rest_routes()
&& empty(Post::get('action')) //bbPress
&& ! \Cleantalk\Variables\Server::inUri('/favicon.ico') // /favicon request rewritten cookies fix
&& ! apbct__is_wp_rocket_preloader_request()
&& ! apbct__is_wordpress_loopback_request()
) {
if ( $apbct->data['cookies_type'] !== 'alternative' ) {
if ( !$apbct->settings['forms__search_test'] && !Get::get('s') ) { //skip cookie set for search form redirect page
Expand All @@ -357,7 +358,8 @@ function apbct_register_my_rest_routes()
}
if (
empty($_POST) &&
$apbct->data['key_is_ok']
$apbct->data['key_is_ok'] &&
! apbct_is_wp_login_excluded_from_protection()
) {
if ( (isset($_GET['q']) && $_GET['q'] !== '') || empty($_GET) ) {
apbct_cookie();
Expand Down Expand Up @@ -613,11 +615,11 @@ function apbct_write_js_errors($data)


add_action('mec_booking_end_form_step_2', function () {
echo "<script>
if (typeof ctPublic.force_alt_cookies == 'undefined' || (ctPublic.force_alt_cookies !== 'undefined' && !ctPublic.force_alt_cookies)) {
echo apbct_get_inline_script_tag(
"if (typeof ctPublic.force_alt_cookies == 'undefined' || (ctPublic.force_alt_cookies !== 'undefined' && !ctPublic.force_alt_cookies)) {
ctNoCookieAttachHiddenFieldsToForms();
}
</script>";
}"
);
});

// Public actions
Expand Down
2 changes: 1 addition & 1 deletion composer.json
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@
"wp-cli/wp-cli-bundle": "*",
"mockery/mockery": "*",
"cleantalk/apbct-installer": "*",
"cleantalk/contacts-encoder": "2.0.18",
"cleantalk/contacts-encoder": "2.0.18.7",
"cleantalk/rate-limiter": "*"
},
"scripts": {
Expand Down
6 changes: 6 additions & 0 deletions i18n/cleantalk-spam-protect.pot
Original file line number Diff line number Diff line change
Expand Up @@ -1539,6 +1539,12 @@ msgstr ""
msgid "Protect logged in Users"
msgstr ""

#. %s: HTML link to CleanTalk Anti-Spam
#: inc/cleantalk-public.php:1337
#, php-format
msgid "Protected by %s"
msgstr ""

#: inc/cleantalk-settings.php:1817
msgid "Protection is active"
msgstr ""
Expand Down
1 change: 0 additions & 1 deletion inc/cleantalk-ajax.php
Original file line number Diff line number Diff line change
Expand Up @@ -894,7 +894,6 @@ function ct_ajax_hook($message_obj = null)
'message' => $ct_result->comment
)
);
die();
}

// Plugin Name: eForm - WordPress Form Builder; ajax action ipt_fsqm_save_form
Expand Down
2 changes: 1 addition & 1 deletion inc/cleantalk-common.php
Original file line number Diff line number Diff line change
Expand Up @@ -1630,7 +1630,7 @@ function apbct_validate_api_response__service_template_get($template_id, $templa
$services_templates_get_error = 'Parse services_templates_get API error: template_id is empty';
break;
}
if ( $template['template_id'] === (int)$template_id ) {
if ( (int)$template['template_id'] === (int)$template_id ) {
if ( empty($template['options_site']) ) {
$services_templates_get_error = 'Parse services_templates_get API error: options_site is empty';
break;
Expand Down
9 changes: 9 additions & 0 deletions inc/cleantalk-integrations-by-hook.php
Original file line number Diff line number Diff line change
Expand Up @@ -433,6 +433,15 @@
'setting' => 'forms__contact_forms_test',
'ajax' => false
),
'WebMagicStudio' => array(
'hook' => array(
'admin_post_nopriv_wms_contact',
'admin_post_wms_contact',
),
'setting' => 'forms__general_contact_forms_test',
'priority' => 1,
'ajax' => false
),
'Newsletter' => array(
'hook' => 'newsletter_action',
'setting' => 'forms__contact_forms_test',
Expand Down
Loading
Loading