Skip to content

Configuring form protection

Blocklist for Forms protects forms on a per-plugin basis: you turn protection on only for the form plugins you actually use. This keeps things fast and avoids interfering with plugins that aren’t part of your setup.

  1. Go to Settings → Blocklist for Forms.
  2. You’ll see a checkbox for each supported form plugin, listed in alphabetical order.
  3. Tick a form plugin to enable protection for it; untick to disable.
  4. Save your changes.

Only the form plugins you enable are checked against your block lists. Any submission through an enabled form is inspected; forms from disabled plugins are left untouched.

Blocklist for Forms works with the most popular WordPress form plugins, including Contact Form 7, Gravity Forms, WPForms, Fluent Forms and more. See the full list, with notes on how each is handled, in Supported form plugins.

For most form plugins, Blocklist for Forms inspects the submitted field content against your blocked words and, where an email field is present, against your blocked emails and domains.

  • Contact Form 7 already uses WordPress’s disallowed_keys list by default, so it benefits from disallowed-word checks out of the box.
  • WooCommerce checkout is protected primarily by email and domain blocking, and also checks order notes against your disallowed words.