Download the PHP package attargah/anti-scam without Composer
On this page you can find all versions of the php package attargah/anti-scam. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.
Download attargah/anti-scam
More information about attargah/anti-scam
Files in attargah/anti-scam
Package anti-scam
Short Description A Filament plugin to protect frontend forms from spam/scam bots with IP blocking and a blacklist management panel.
License MIT
Homepage https://github.com/attargah/anti-scam
Informations about the package anti-scam
Anti-Scam Laravel Package
A comprehensive Laravel package that provides advanced protection against spam, scam bots, and malicious activities on your web forms. This package integrates seamlessly with Filament admin panel for easy management and monitoring.
Features
🛡️ Multi-Layer Protection
- Anti-Scam Protection: Detects and blocks scam bots using hidden form fields
- Anti-Spam Protection: Rate limiting with progressive ban duration
- IP Blocking: Temporary and permanent IP blocking system
- XSS Protection: Automatic input sanitization
📊 Admin Panel Integration
- Filament Resources: Manage blocked IPs, scam IPs, and logs
- Real-time Monitoring: Track blocked attempts and scam activities
- Log Management: Detailed logging with user agent, request details, and timestamps
🎯 Advanced Bot Detection
- Hidden Form Fields: Invisible honeypot fields to catch bots
- Hash-based Validation: Secure validation using Laravel's Hash facade
- Randomized Input Order: Prevents pattern-based bot detection
- Configurable Display: Hide fields using CSS or move them off-screen
Installation
You can install the package via Composer:
Publish Configuration, Migrations and Translations
Run Migrations
Configure the Package
Set your secret key in the config/anti-scam.php file:
Configuration
The package provides extensive configuration options in config/anti-scam.php:
Anti-Scam Configuration
Anti-Spam Configuration
Usage
1. Protect Your Forms
Use the @protect Blade directive in your forms:
2. Apply Middleware
Add the middleware to your routes or controllers:
You can also prevent XSS attacks using Validation.
💡 Bot Deception / Honeypot Success Message:
To trick scam bots into thinking their request was successful, you can place the following snippet before saving any data in your controller:This ensures that:
- Legitimate users are not affected (since they won't trigger the hidden field).
- Bots see a success message and believe their request went through.
- No actual data is saved for requests flagged as scam.
3. Filament Admin Panel
Register the plugin in your Filament panel:
Middleware Components
AntiScam Middleware
- Detects scam bots using hidden form fields
- Validates hash-based tokens
- Logs scam attempts and optionally bans IPs
AntiSpam Middleware
- Implements rate limiting with configurable thresholds
- Progressive ban duration (increases with repeated violations)
- Automatic permanent bans for persistent offenders
CheckBlockedIP Middleware
- Blocks requests from banned IP addresses
- Supports both temporary and permanent bans
- Returns 403 status for blocked requests
XSSProtection Middleware
- Sanitizes all input data
- Removes HTML tags and scripts
- Prevents XSS attacks
Database Tables
The package creates three main tables:
scam_ips: Stores detected scam IP addresses and related informationblocked_ips: Manages IP blocking with expiration timesblocked_ip_logs: Detailed logs of all blocking activities
Testing
Run the test suite:
The package includes comprehensive tests for all middleware components and functionality.
Security Considerations
- Secret Key: Always use a strong, unique secret key for the anti-scam protection
- Rate Limiting: Adjust spam protection settings based on your traffic patterns
- IP Blocking: Be cautious with permanent IP bans as they may affect legitimate users
- Logging: Regularly review logs to identify patterns and adjust protection levels
Contributing
Contributions are welcome! Please feel free to submit a Pull Request.
License
This package is open-sourced software licensed under the MIT license.
Support
If you encounter any issues or have questions, please open an issue on GitHub.
Changelog
Please see CHANGELOG for more information on what has changed recently.
Made with ❤️ by Attargah
All versions of anti-scam with dependencies
filament/filament Version ^4.0
filament/forms Version ^4.0
filament/tables Version ^4.0
spatie/laravel-package-tools Version ^1.15.0