Download the PHP package tmi/anti-spam without Composer

On this page you can find all versions of the php package tmi/anti-spam. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.

FAQ

After the download, you have to make one include require_once('vendor/autoload.php');. After that you have to import the classes with use statements.

Example:
If you use only one package a project is not needed. But if you use more then one package, without a project it is not possible to import the classes with use statements.

In general, it is recommended to use always a project to download your libraries. In an application normally there is more than one library needed.
Some PHP packages are not free to download and because of that hosted in private repositories. In this case some credentials are needed to access such packages. Please use the auth.json textarea to insert credentials, if a package is coming from a private repository. You can look here for more information.

  • Some hosting areas are not accessible by a terminal or SSH. Then it is not possible to use Composer.
  • To use Composer is sometimes complicated. Especially for beginners.
  • Composer needs much resources. Sometimes they are not available on a simple webspace.
  • If you are using private repositories you don't need to share your credentials. You can set up everything on our site and then you provide a simple download link to your team member.
  • Simplify your Composer build process. Use our own command line tool to download the vendor folder as binary. This makes your build process faster and you don't need to expose your credentials for private repositories.
Please rate this library. Is it a good library?

Informations about the package anti-spam

tmi/anti-spam

Framework-light, presentation-free anti-spam primitives for Symfony forms.

Layer 1 — honeypot stack (free, no CAPTCHA, no third party). Three cheap, JS-and-bot-resistant signals:

Layer 2 — Cloudflare Turnstile (optional, stronger). A decoupled siteverify wrapper with an injected hostname allow-list — catches what the honeypot can't and vice versa. Use both for defence-in-depth.

Carries no entities, templates, translations or routes — pure logic + one form-type extension + one Stimulus controller. Detachable by design.

Install

Register the bundle (Symfony Flex does this automatically):

Usage

1. Add the honeypot fields to a form

2. Wire the JS (Stimulus)

Copy assets/controllers/antispam_controller.js into your app's assets/controllers/ (or register the package's UX assets).

3. Check on submit

Pair it with a Symfony rate_limiter on the submit endpoint for layered defence.

4. (Optional) Cloudflare Turnstile

TurnstileVerifier is app-decoupled — it takes the allowed hostnames as a constructor argument rather than reading any app host registry, so subclass it (or wire it) to supply your own list. The HTTP client should be a scoped client pointed at https://challenges.cloudflare.com; the secret stays server-side.

Hostnames are normalized (lowercase + trailing .local strip for dev parity) before comparison. The widget JS + sitekey stay in your app.

License

MIT.


All versions of anti-spam with dependencies

PHP Build Version
Package Version
Requires php Version >=8.4
psr/log Version ^3.0
symfony/config Version ^7.3 || ^8.0
symfony/dependency-injection Version ^7.3 || ^8.0
symfony/form Version ^7.3 || ^8.0
symfony/http-client Version ^7.3 || ^8.0
symfony/http-client-contracts Version ^3.0
symfony/http-kernel Version ^7.3 || ^8.0
symfony/options-resolver Version ^7.3 || ^8.0
symfony/uid Version ^7.3 || ^8.0
Composer command for our command line client (download client) This client runs in each environment. You don't need a specific PHP version etc. The first 20 API calls are free. Standard composer command

The package tmi/anti-spam contains the following files

Loading the files please wait ...