• Resolved Drivingralle

    (@drivingralle)


    Hey!

    I looked into a client website and the log inside Brevo. There are a lot of spam sign ups that are eating email counts. And are allowing this plugin to be misused for DDOS or stalking attacks. By bombing people with double opt in emails.

    The only option to prevent that you offer is the use of Captchas that require external request. Because of GDPR this is not acceptable.

    A big step forward would be a honeypot as and widely, successful way to fight bots. Sadly the plugin does not provide hooks or filters to allow others to extent it. Therefore I suggest to add a honeypot to the plugin to prevent thousands of spam emails. Or some hooks and filters so others can provide it.

    Greetings
    derRALF

Viewing 8 replies - 1 through 8 (of 8 total)
  • Came here to say the same! @neeraj_slit @alexisbienayme

    I found this KB article:
    https://help.brevo.com/hc/en-us/articles/19591451188114-Protect-your-forms-from-bots-and-spam-signups

    But although you are mentioning different things to prevent spam registrations, you only provide a UI for external Captcha or the DOI itself. This is not sufficient.

    Why not adding an easy way to add a honeypot field or a math question in your plugin?

    All the best
    Torsten

    Plugin Support alexisbienayme

    (@alexisbienayme)

    Hello,

    I understand your concern. We offer protection for your form using Cloudflare Turnstile, as described in this article: https://help.brevo.com/hc/en-us/articles/360019551939-Add-a-CAPTCHA-to-your-subscription-form.

    The Brevo plugin on WordPress allows you to add this protection. Please feel free to use it to secure your form.

    As for now, it’s not possible to add a honeypot but I’ll pass it to our Product team for an improvement of our plugin.

    I remain at your disposal.

    Alexis

    Hi @alexisbienayme

    Cloudflare Turnstile is also an external request.

    This thread is about adding an antispam feature without external request, like honeypot or a math quiz. Or one of the other features mentioned here:
    https://help.brevo.com/hc/en-us/articles/19591451188114-Protect-your-forms-from-bots-and-spam-signups

    Cloudflare Turnstile and Google reCaptcha is what we want to avoid.

    All the best
    Torsten

    Plugin Support alexisbienayme

    (@alexisbienayme)

    Hello,

    I understand. For the moment, we only have these solutions.

    The alternative would be to use a plugin that allows the creation of registration forms on WordPress, and to connect it to Brevo using Zapier.

    Here’s the link: https://zapier.com/

    Brevo is available on Zapier, so you’ll need to make sure that the application used to create the forms is also available on Zapier.

    I’ve passed on your requirements to our product team with a view to improving our functionality.

    Alexis

    Thread Starter Drivingralle

    (@drivingralle)

    Hey!

    Sending the data through Zapier is on the same level not acceptable or even worse, as personal data are send.

    Looking forward to the improving of the plugin.

    Greetings
    derRALF

    Plugin Support alexisbienayme

    (@alexisbienayme)

    Hi,

    I understand.

    As a last resort, you can create a form using programming and use Brevo’s API to add the contacts. This way you can add a Recaptcha of your choice.

    Here’s the link for API : https://developers.brevo.com/

    Your feedback has been passed on to the Product team.

    Have a great day !

    Alexis

    Michael

    (@michael-luther)

    The same spam problem has existed for some time on one of my customer websites. Fortunately, another customer has not yet complained about it.

    Unfortunately, Brevo has not responded to my direct request to support about two months ago.

    As Brevo is, as far as I know, a French company (or have you sold your soul?), the interest in data protection should be a natural endeavor as they are based in Europe.

    In addition to the expected function and security of a plugin, data protection is equally important. Not every user, or perhaps even very few users, are programmers.

    I would very much welcome a timely and practicable solution.

    With best regards

    Michael

    torao9340

    (@torao9340)

    Yes, problem with spam is very visible and annoying. Captchas don’t work with the most popular cache plugins, there’s no way to protect yourself. Just annoying and dangerous.

Viewing 8 replies - 1 through 8 (of 8 total)
  • You must be logged in to reply to this topic.