Configuring form protection
Blocklist for Forms protects forms on a per-plugin basis: you turn protection on only for the form plugins you actually use. This keeps things fast and avoids interfering with plugins that aren’t part of your setup.
Enabling & disabling form compatibility
Section titled “Enabling & disabling form compatibility”- Go to Settings → Blocklist for Forms.
- You’ll see a checkbox for each supported form plugin, listed in alphabetical order.
- Tick a form plugin to enable protection for it; untick to disable.
- Save your changes.
Only the form plugins you enable are checked against your block lists. Any submission through an enabled form is inspected; forms from disabled plugins are left untouched.
Supported form plugins
Section titled “Supported form plugins”Blocklist for Forms works with the most popular WordPress form plugins, including Contact Form 7, Gravity Forms, WPForms, Fluent Forms and more. See the full list, with notes on how each is handled, in Supported form plugins.
What gets checked
Section titled “What gets checked”For most form plugins, Blocklist for Forms inspects the submitted field content against your blocked words and, where an email field is present, against your blocked emails and domains.
- Contact Form 7 already uses WordPress’s
disallowed_keyslist by default, so it benefits from disallowed-word checks out of the box. - WooCommerce checkout is protected primarily by email and domain blocking, and also checks order notes against your disallowed words.
