Spam protection, Honeypot, Anti-Spam by CleanTalk
by CleanTalk Inc · Security
Also makes 3 other plugins · 240.2K+ installs across the portfolio →
Top-rated antispam for contact forms, comments, WooCommerce, eCommerce, and login. No CAPTCHAs, no friction, just background anti spam protection.
96 health vs 64 average across 997 Security plugins
Directory ranking optimization
How it's scored →How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.
Excellent listing optimization
Well tuned across the board
Daily downloads
Since 2022-10-05 · 1,421 days · wp.org + Plugin Pulse archive
30-day downloads
Rolling 30-day volume · peaks are release surges
332.0K
now · peak 576.9K
Directory rank vs rivals
wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you
Rating trend
Star average over time · dips mark rough releases
Update activity
How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.
Release cadence
Actively maintainedHow often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.
28
releases in the last 12 months
1mo ago
latest release · v6.83.1
528
tagged releases on record
Recent releases
What its installed base runs
via wordpress.orgShare of active installs on each version of this plugin. Green is the current release; a big slice on older versions is a user base that has stopped updating.
Estimated active installs
The public count shows “200K+”. Our estimate pins where the real number sits.
Refined from the date this plugin crossed into its current band.
Install history · since 2015-03-10 · 1,498 observations
Estimated value
What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.
Est. annual revenue
Est. acquisition value
No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price. A declining trend compresses what a buyer would pay.
Details
Recent reviews
All reviews on wp.org ↗- ★★★★★ brielyn1441mo ago
CleanTalk is great!
Read on wp.org ↗ - ★★★★★ bingokid1mo ago
Plugin saved my site after it was flooded with spam orders. Support is super fast as well.
Read on wp.org ↗ - ★★★★★ souej1mo ago
CleanTalk ist ein effektives Plugin. Ich nutze es schon länger auf mehreren Websites und bin sehr begeistert! Schluss mit täglichen, nervigen Spam- oder Phishing-E-Mails. Ich bedanke mich bei den Entwicklern und empfehle CleanTalk gerne weiter.
Read on wp.org ↗ - ★★★★★ Jeannine2mo ago
Excellent support. The team investigated the issue thoroughly, kept me updated, and finally resolved the problem. I really appreciated the clear communication and the technical expertise. Thank you very much!
Read on wp.org ↗ - ★★★★★ masteringmatrix2mo ago
Satisfied with the plugin. No more unwanted posts in my blogs.
Read on wp.org ↗ - ★★★★★ sylvskin2mo ago
I LOVE CleanTalk. It just works! It’s quiet, simple to set up, and does its job without getting in the way. No coding, no complicated setup, just install it and let it work. I removed it for about six months because my hosting provider said their security would cover everything. It didn’t. Spam registrations and bot activity returned. As soon as I reinstalled CleanTalk, the problem disappeared. If you want effective anti-spam protection that’s easy to use and quietly gets on with the job, I highly recommend CleanTalk.
Read on wp.org ↗ - ★★★★★ bbdigital782mo ago
My clients were experiencing massive spam problems on their forms. Cleantalk fixed this quickly. I share a report weekly with them weekly showing all the submissions that were passed through and those that were blocked and we’ve been very pleased with the results. I recently had a support question, Almaz responded quickly and answered my question to my satisfaction.
Read on wp.org ↗ - ★★★★★ lorisawaya2mo ago
Dropping a message on my admin page that I can not close — !@#$ you. Immediately deleted the plug in.
Read on wp.org ↗
Latest updates
via wp.org changelogRecent releases and news for this plugin
- — Version 6.84 New. Integration. WooCommerce. Spam order details modal windows implemented. New. Integration. Catch fetch request. Iframe forms of sender.com protected. Fix. Settings. Improve alt storage. Fix. ContactEncoder. Addition 6.84
- — Version 6.83.1 Upd. Settings. Implement honey test. 6.83.1
- — Version 6.83 New. Settings. Getting apikey wizard. New. RateLimit. Enabled the RateLimit shared library New. Footer. New link on Website Feedback Plugin Upd. Contacts Encoder. Flow improvements. Upd. ContactEncoder. Improve shortcode 6.83
- — Version 6.82 New. Integration. Integration with Email Subscribers Fix. Integration. Editing the doBlock method New. Integration. Integration edits when on and off js Fix. Code. Editing the check_value parametere 6.82
- — Version 6.81 New. Code. Amelia integration Code. Links from backend Fix. Code. Improve statement. Fix. Code. Editing the array key transfer Fix. SFWUpdateLog. Transferring values to placeholders prepare() Fix. SFW. Mixing values in c 6.81
- — Version 6.80 Fix. catchJqueryAjax. Object as null comparison fixed. Fix. CatchXHR. Mailpoet integration added to provide the event_token. Upd. Bot Detector Service. Added alternative source URL. Upd. Bot Detector Service. Updates. Fi 6.80
Known vulnerabilities
via Wordfence Intelligence15 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.
- 2026-07-27 CVE-2026-65437 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 6.82 Patched in 6.83
- 2026-06-11 CVE-2026-8071 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 6.79 Patched in 6.79
- 2026-02-14 CVE-2026-1490 Reliance on Reverse DNS Resolution for a Security-Critical Action Affects <= 6.71 Patched in 6.72
- 2024-11-25 CVE-2024-10781 Improper Check or Handling of Exceptional Conditions Affects <= 6.44 Patched in 6.45
- 2022-10-03 CVE-2022-3302 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 5.185 Patched in 5.185.1
- Medium · 6.1 Spam protection, AntiSpam, FireWall by CleanTalk <= 5.173 - Reflected Cross-Site Scripting ↗2022-03-30 CVE-2022-28222 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 5.173 Patched in 5.174.1
- Medium · 6.1 Spam protection, AntiSpam, FireWall by CleanTalk <= 5.173 - Reflected Cross-Site Scripting ↗2022-03-30 CVE-2022-28221 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 5.173 Patched in 5.174.1
- High · 7.5 Spam protection, AntiSpam, FireWall by CleanTalk <= 5.153.3 - Unauthenticated Blind SQL Injection ↗2021-03-05 CVE-2021-24295 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 5.153.3 Patched in 5.153.4
- 2020-11-20 CVE-2021-24131 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 5.149 Patched in 5.149
- Medium · 6.1 Spam protection, AntiSpam, FireWall by CleanTalk <= 5.127.3 - Reflected Cross-Site Scripting ↗2019-11-12 CVE-2019-17515 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 5.127.3 Patched in 5.127.4
- Medium · 6.1 Spam protection, AntiSpam, FireWall by CleanTalk < 5.22 - Reflected Cross-Site Scripting ↗2015-08-25 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 5.22 Patched in 5.22
Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.
CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.
Behavioral tests
via WP HiveAutomated install-time checks, tested on PHP 8.1.12 · WP 7.0.1
Languages
via translate.wordpress.orgTranslated into 36 languages, 9 at 90% or more
Plus 12 more locales with partial translations.
Growth timeline
Install-tier crossings we have observed, and how long each tier took to outgrow
- 2022-11-19 100K+ → 200K+ up
Competes with
The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).
-
Kama SpamBlock 4K+ installs · 4.5★ · 4 shared tags A -
Honeypot Plus for Contact Form 7 800+ installs · 3.8★ · 4 shared tags B -
Gravity Forms Zero Spam 100K+ installs · 4.2★ · 3 shared tags A -
hCaptcha for WP 70K+ installs · 4.5★ · 3 shared tags A
-
Maspik – Multi-Layer Spam Protection 30K+ installs · 4.6★ · 3 shared tags A -
Friendly Captcha for WordPress 10K+ installs · 3.9★ · 3 shared tags B
Embed this report card
Drop a live Pulse card for Spam protection, Honeypot, Anti-Spam by CleanTalk into a readme, a review or a deck. It updates itself.
<iframe src="https://plugins.wpmayor.com/embed/cleantalk-spam-protect" width="480" height="300" style="border:0" loading="lazy" title="Spam protection, Honeypot, Anti-Spam by CleanTalk — Plugin Pulse"></iframe> Spam protection, Honeypot, Anti-Spam by CleanTalk: 200K+ active installs, 4.8★ (3,204 reviews). Plugin Pulse (WP Mayor), as of 2026-08-25. https://plugins.wpmayor.com/plugin/cleantalk-spam-protect