Wellenbrecher · Version 1.0

Breaks the spam wave before it reaches the harbor.

Local-first anti-spam for comments, forms, registrations and WooCommerce. One plugin instead of three: the entire assessment runs on your own server, with no cloud, no DPA and no request limits.

Local-firstzero external requests by default
GDPRIP only as an HMAC, deletion deadlines
Fail-openprotection never costs real requests
Wellenbrecher · Overview
Spam wave broken42 blocks today · 0 false hitsScore 96
Quarantine · 3 requestswaiting for your reviewreview
Observation mode2 days left, then liveactive
Features

One plugin that breaks the whole spam wave

Every channel, one explainable engine, GDPR from day one – and none of it costs you real requests.

Every channel, one plugin

Comments, trackbacks, registrations (WordPress, Multisite, WooCommerce), product reviews and the fleet's Leadlotse forms – one shield instead of three separate tools.

Explainable score engine

Every submission gets a traceable score with three zones: pass, quarantine or block. Each rule can be switched off or weighted individually.

Observation mode

For the first 7 days everything is only logged, nothing is blocked. You first see what would happen, then switch it live at your own pace.

Invisible & accessible

No captcha, no puzzles, no cookies. An accessible honeypot, a time trap and behavioral signals work unnoticed in the background.

Quarantine with restore

Bring back wrongly caught Leadlotse requests with a single click – the lead is created normally, including double opt-in and CRM handover.

Block log & stats

Every decision lands in the block log with its reason, plus daily stats. Even accidentally rejected requests stay visible – no invisible false positives.

Protects the fleet natively

If Leadlotse is active, its forms run through automatically. Newsletter sign-ups for Kurato are protected from bot subscriptions before an entry even exists.

WooCommerce integrated

Product reviews run through the same engine automatically. Verified buyers get a trust bonus and are held up less often.

Fail-open by design

If Wellenbrecher throws an internal error, the content passes through – into normal moderation if needed, never into a silent block. Anti-spam must not cost you real requests.

Score engine

Not just spam yes or no – but why

Instead of a black box, Wellenbrecher builds a score for every submission from many individual signals. Three zones decide what happens – transparent and traceable.

Pass

Legitimate requests pass unhindered. Logged-in users, verified buyers and senders with a clean history even get a trust bonus.

Quarantine

Edge cases land in the review pool instead of the void. You review them at your leisure and restore genuine requests with a single click.

Block

Clear spam is rejected before it reaches the database – with a full reason in the block log, never invisible.

You set the thresholds yourself with sliders. Weak signals like headers or origin never reach quarantine on their own – only strong rules like a filled-in honeypot come close by themselves.

Channels

One shield for every entrance

Wherever spam tries to get in, Wellenbrecher stands in front of it. Every channel runs through the same engine, without you maintaining three plugins.

  • Comments and trackbacks, including optional XML-RPC shutdown
  • Registrations: WordPress, Multisite and WooCommerce
  • WooCommerce product reviews, with a trust bonus for verified buyers
  • Leadlotse forms with quarantine and one-click restore
  • Kurato newsletter sign-ups automatically, before a bot subscription is created
Wellenbrecher · Quarantine
Leadlotse · contact requestheld back as an edge caserestore
Block log · 7 days0 questionable out of 42 blocksreviewed
WooCommerce reviewverified buyer · bonusTrust
Privacy

Local-first: your server, your data

In its delivery state, not a byte leaves your website. The entire assessment happens on your server – the only outgoing call is the update check against hafenstudios.com, at most every 12 hours and without any visitor data.

  • In the log, the IP is never in plain text, only as a non-reversible check value (HMAC) under a weekly rotating key
  • Only the domain of email addresses is stored
  • Automatic deletion deadlines: blocked or flagged entries after 7 days, quarantine after 30 days (adjustable)
  • Privacy policy snippet for the WordPress privacy assistant
  • Wired into WordPress data export and erasure
  • No DPA, no third-country transfer, no request limits – explicitly usable commercially too
# The only external request
GET https://hafenstudios.com/updates/wellenbrecher.json

# At most every 12 hours · plain update check
# No visitor data, no content, no tracking
On the horizon

Wellenbrecher Pro

The Wellenbrecher core stays free and fully functional forever. For everyone who wants to go even deeper, there is an optional paid add-on.

Available now

Wellenbrecher Pro: a learning Bayes filter, escalating proof-of-work, GeoIP and an AI second opinion. Pro from 19 euros/year, fleet up to 10 sites 69 euros/year.

Get Pro Compare all prices
FAQ

Frequently asked questions

I use a page cache or a CDN. Is there anything to watch out for?

Wellenbrecher bakes nothing dynamic into cached pages. The form token is loaded on demand via a small REST endpoint (/wellenbrecher/v1/token) that sets no-cache headers. Exclude this route from caching in your full-page cache or CDN. A missing token is only a scoring signal and never a reason to block on its own.

My theme renders the comment field itself. Does protection still work?

Yes. If your theme renders the comment field without the standard hook, only the honeypot and field-swap signals are dropped. All other rules – headers, content, repeat offenders, token – apply unchanged.

Can I disable XML-RPC comments and pingbacks?

Yes. In the settings you can remove the XML-RPC methods for comments and pingbacks. The xmlrpc.php file itself stays reachable so apps and services that need it keep working.

Does Wellenbrecher work without JavaScript?

Yes. A missing token or missing JavaScript is always only a scoring signal, never a reason to block on its own. No-JS visitors and legitimate REST clients are left alone; the content, header and repeat-offender rules work entirely without JavaScript.

Is Wellenbrecher free?

Yes. Wellenbrecher is open source under GPLv2, with no request limits and explicitly usable commercially. The local-first core stays free forever. Wellenbrecher Pro with a learning Bayes filter, proof-of-work, GeoIP and an AI second opinion is coming as an optional paid add-on.

Is Wellenbrecher a security plugin?

No, and that's intentional. Wellenbrecher protects against spam, not against attacks. It ships no login brute-force protection, no firewall and no .htaccess changes, so it doesn't get in the way of security plugins like Wordfence.

Ready to break the spam wave?

Download Wellenbrecher and switch it live at your own pace – or ask us if you need help setting it up.