Synth Antispam – AI Comment Spam Protection
Download Synth Antispam – AI Comment Spam Protection 0.2.0Description
At a glance
Looking for Synth Antispam – AI Comment Spam Protection v0.2.0? It is available here as a free GPL download for WordPress — updated September 29, 2026 · requires WordPress 6.0+ & PHP 8.0+.
Spammers learned to write around keyword filters. Synth reads what a comment is actually trying to promote.
Keyword lists and blocklists miss polite, well-written spam: the “Great article, very helpful!” comment with a casino link in the author URL, the fake SEO agency, the crypto pitch dressed up as a question. Synth uses an AI model to understand the intent of new comments — so it catches spam that looks human, while legitimate comments continue through your normal WordPress moderation. No CAPTCHA, no puzzles, nothing extra for your visitors.
Synth is an AI spam classifier for WordPress comments. It analyzes what a comment is trying to promote instead of matching it against static keyword lists.
What it blocks
- SEO and link-building spam, including links hidden in the author URL field
- Casino, crypto, adult and pharma promotions
- Fake “great post!” comments written to carry a link
- Rewritten and misspelled spam that slips past keyword rules
- Pingback spam and trackback spam, including automated submissions through XML-RPC
- Spam submitted through the REST API
Why it’s better than a rule list
- Rewording doesn’t help the spammer. Rules match strings, so spammers change the string. The model reads the message — and the message is the thing being sold.
- Nothing to maintain. No keyword lists, blocklists or regex to update.
- Synth never automatically deletes comments. Spam goes to the Spam folder (or the moderation queue in strict mode) and can be restored in one click. Synth never moves a comment to Trash.
- You see why. A verdict column in the Comments list (and on the WooCommerce Products Reviews screen) shows the spam category and confidence for every checked comment.
- No CAPTCHA, no visitor friction. No puzzles or extra fields. Submitting a comment waits for the service for up to 2 seconds; the verdict follows in the background. No tracking scripts on your pages.
- Your decisions come first. Synth never touches a comment you or another moderation plugin already marked as spam or trash, never changes a comment whose status a moderator has already changed, and never publishes a comment your site held for review, so it runs fine alongside your existing setup. A held comment it finds to be spam still goes to the Spam folder (in strict mode it stays in the queue).
- Your site keeps accepting comments. If the service is unreachable, or your included checks run out, AI classification pauses and comments follow the fallback you chose: they continue through your normal WordPress moderation (default) or are held for review.
WooCommerce product reviews
If your shop runs WooCommerce, Synth Antispam checks product reviews the same way it checks comments. A product review is submitted through the same WordPress comment form, so reviews are covered as soon as a site key is set — there is nothing extra to switch on.
- A spam review goes to the Spam folder (or the moderation queue in strict mode) and can be restored in one click, exactly like a comment.
- The verdict column appears on the Products Reviews screen, where WooCommerce lists reviews.
- Reviewers who already have an approved review or comment on your site are trusted and skipped.
Synth looks for promotional and link spam in reviews. It does not judge whether a review is genuine, so it is not a filter for fake or invented reviews.
Contact Form 7
Synth Antispam checks Contact Form 7 submissions too (Settings Synth Antispam Contact Form 7). Spam is marked as spam by Contact Form 7 itself, so its email is not sent. Install Flamingo to keep a copy of every submission.
Start protecting comments in a few clicks
- Install and activate.
- Open Settings Synth Antispam and press Get a site key — no account to create, no API key to copy.
- Done. Every site starts with an included allowance of AI checks — see current plans.
Until a key is set, the plugin sends nothing except when you press Get a site key, and WordPress decides on every comment exactly as before.
Data minimization
Synth sends only the data needed to classify a comment or a form submission: the comment text, author name and URL, the email domain, and a per-site pseudonymous hash of the email. It does not receive the commenter’s full email address, IP address, raw User-Agent, cookies or your post content. Commenters who already have an approved comment are skipped entirely. What is sent, when, and how long it is kept is listed under “External services” below.
External services
This plugin needs the Synth Antispam service (wp-api.synth.locker, operated by LightApps OÜ, Estonia) to classify comments and, when Contact Form 7 checks are on, form submissions. Nothing is sent until a site key is set, except the request made when you press Get a site key.
Every setting and mode of the plugin works on every plan; only the number of AI checks depends on the plan.
Requests the plugin makes
Every request below carries the plugin version and WordPress’s own User-Agent header, which names your site address and WordPress version (not the commenter’s browser); all except Get a site key also carry your site key and, in a separate header, your site address.
- Submit a comment (or a WooCommerce product review, pingback or trackback) for a verdict — fields listed below. This request also carries your site key and your site address; the first such request is what ties the key to your site.
- Submit a form for a verdict — only while Contact Form 7 checks are on; the same fields (see
content.body), and the visitor waits for the verdict. - Collect the verdict a moment later — sends only the identifier the service issued for that comment.
- Report a moderator correction — off by default (
synth_wp_send_feedbackfilter returns false); when enabled, sends only the identifier and the moderator’s decision (spam / not spam). - Get a site key — only when you press the button; sends only the plugin version and the User-Agent header.
- Test connection — only when you press the button; sends one sample comment (“ping”, with no commenter details) and costs one check.
- Check the remaining allowance — only while an administrator has the settings screen open; sends the site key and site address. Costs no check; with a new key it may be the request that ties the key to your site.
- Site Health status — only while an administrator has Tools Site Health open, at most once every 15 minutes; sends a fixed test identifier and costs no check.
- Start a purchase — only when you press an upgrade button; sends Synth the site key, site address, selected option and the settings-page path to return to, then opens Stripe Checkout. Card data goes directly to Stripe and never reaches your site, this plugin or Synth.
Exactly what is sent, field by field. The complete list, matching the plugin’s request builder:
schema_version— request format version.plugin_version— installed plugin version.surface—wp_commentorwp_cf7.object_type— comment, review, pingback, trackback or form.content.body— the comment text; for a form, its subject and message.content.author_name— the name entered.content.author_url— the website entered.content.author_email_domain— only the email domain, e.g.gmail.com, never the address.content.author_id_hash— a per-site salted hash of the email; cannot be linked across sites.context.author_status—registeredoranonymous.context.is_reply— whether it is a reply.context.site_locale— your site language.context.client_ip_status— whether an IP was present, never the IP.context.has_user_agent— whether a User-Agent was present, never the string.
What is never sent: full email address, IP address, raw User-Agent, post title or body, HTTP referrer, cookies. From a Contact Form 7 form: no attachments, hidden or internal fields, list, checkbox or radio choices, or email fields other than the sender’s.
Retention: verdict records expire after 24 hours. Separately, the service keeps copies of each submitted request, its verdict and any later correction to train and improve its models. These copies are stored as sent, have no expiry and cannot currently be turned off. This applies to form submissions as well: the service keeps its copy of each submitted form message indefinitely, as sent. To have your site’s copies deleted, email [email protected] with your site address. Uninstalling deletes your site’s salt but not copies already taken. Held form submissions are kept on this site for 7 days, then deleted automatically; deleting the plugin removes them at once.
- Terms of Use: https://synth.locker/assets/legal/wordpress-terms-of-use.html
- Privacy Policy: https://synth.locker/assets/legal/wordpress-privacy-policy.html
- Pricing: https://wordpress.synth.locker/pricing
- Stripe: https://stripe.com/legal · https://stripe.com/privacy
Paste-ready paragraph for your privacy policy. The same list for site owners who write their policy by hand, minus the four fields that describe the request’s shape rather than the commenter or the submission (schema_version, plugin_version, surface and object_type). It is generated from the same manifest as the field list above, so it cannot fall behind it:
Synth Antispam sends each comment (and each WooCommerce product review, pingback or trackback) to the Synth Antispam classification service — an external processor — to obtain a spam verdict. What is sent: the comment body; the commenter’s display name; the commenter’s website URL; the domain part (not the full address) of the commenter’s email address; a one-way salted hash derived from that email address; whether the commenter is anonymous or a registered user of this site; whether the comment is a reply; the site’s language; whether an IP address was present at all, never the address itself; whether a User-Agent string was present at all, never the string itself. If Contact Form 7 checks are on, form submissions are sent the same way, the form’s subject and message standing in for the comment body. Comments from people who already have an approved comment on this site are not sent to the service at all. The commenter’s full email address, IP address and raw User-Agent string are never sent, in any case. Verdicts are retained by the service for 24 hours and then expire automatically. Separately from that, the service keeps its own copy of everything listed above, together with the verdict it produced and any correction a moderator of this site later makes to that verdict, and uses those copies to train and improve the Synth spam-classification models. Those copies are kept indefinitely and have no expiry date; the comment text and the commenter details above are kept as sent, not anonymised or aggregated. This applies to form submissions as well: the service keeps its copy of each submitted form message indefinitely, as sent. This applies to every site that uses the service: there is no setting that turns it off. To have this site’s stored copies deleted, write to [email protected]. Uninstalling this plugin deletes this site’s local secret value, after which any previously sent hash can no longer be linked back to an email address, by this site or by the service.
Every address that appears in the source
A search of this plugin’s files finds these addresses and no others:
wp-api.synth.locker— the Synth Antispam service above; changeable on the settings screen or inwp-config.php. The only address this plugin sends a request to.checkout.stripe.com— Stripe’s payment page. Nothing is sent there by the plugin; it only checks that the payment page it was handed really is Stripe’s before opening it in your browser.synth.locker,wordpress.synth.locker,stripe.com,wordpress.org,www.gnu.organdfsf.org— links (terms, privacy, pricing and plugin home pages, Stripe’s documents, the support forum in the translation template, the GPL licence). Nothing is sent to them.[email protected]— the email address for deletion requests.- Not addresses: the example
your-synth-endpoint.examplein the empty settings field,gmail.comin the field list above, the translation-template placeholder[email protected], and names that appear only inside code comments and are never contacted (wp-api-dev.synth.locker,evil.example,https://x,http://api,http://localhost).
Frequently asked questions
What is Synth Antispam – AI Comment Spam Protection?
Synth Antispam – AI Comment Spam Protection is a free WordPress plugin available under the GPL license. The current version is 0.2.0.
Is Synth Antispam – AI Comment Spam Protection free to download?
Yes — Synth Antispam – AI Comment Spam Protection 0.2.0 is a free GPL download with no hidden fees, no account needed, and no feature locked behind a paywall in this package.
How do I install Synth Antispam – AI Comment Spam Protection 0.2.0?
Download the ZIP file from this page, then in your WordPress dashboard go to Plugins → Add New → Upload Plugin, choose the file, click Install Now, then Activate. The plugin works immediately after activation — no license key or extra setup is required for the core features.
What are the requirements for Synth Antispam – AI Comment Spam Protection?
Synth Antispam – AI Comment Spam Protection 0.2.0 requires WordPress 6.0 or higher and PHP 8.0 or higher. Most modern WordPress hosts already meet these versions. Running older versions may cause features to break, so update WordPress and PHP first if your site is behind.
When was Synth Antispam – AI Comment Spam Protection last updated?
Version 0.2.0 was last updated on September 29, 2026. This page is refreshed automatically, so the download here always matches the newest version we have verified.
Is the Synth Antispam – AI Comment Spam Protection download safe?
The file is sourced directly from the official WordPress.org repository — the same file the developer published. It is served unmodified, so what you install here is byte-identical to the official release.
Technical details
| Version | 0.2.0 |
|---|---|
| Last updated | September 29, 2026 |
| Requires WordPress | 6.0 or higher |
| Requires PHP | 8.0 or higher |
| Author | Synth AI |
| Tags | ai, antispam, contact-form-7, spam-protection, woocommerce |
Download Synth Antispam – AI Comment Spam Protection
Download Synth Antispam – AI Comment Spam Protection WP PluginNote: if the download does not start, disable your ad blocker and try again.