SpamGuard Download 0.3.3

5.0
Dutch eric redegeld 2 weeks ago

I’ve been working on a new OSSN component called SpamGuard and I’d like to share the current version with the community for testing and feedback.

SpamGuard is intended as a privacy-first anti-spam layer for OSSN. It does not automatically ban users or delete content. Instead, it combines several signals and gives administrators a clearer picture of suspicious registrations and promotional activity.

Current features include:

registration monitoring;
HMAC-based IP hashing by default;
optional raw IP storage;
detection of multiple registrations from the same IP hash;
registration bursts by e-mail domain;
historical e-mail-domain review using existing OSSN users;
signup honeypot;
signup speed detection;
NORMAL / WATCH / REVIEW registration status;
external-link analysis in wall posts;
promoted-domain detection;
domain drill-down to the users who posted it;
direct Profile / Message actions;
Blog URL analyzer;
direct links back to detected wall posts and Blog content;
configurable retention period;
trusted-domain allowlist;
English and Dutch language files.

Important before testing: SpamGuard makes changes to the OSSN database.

It creates and maintains its own tables:

ossn_spamguard_events
ossn_spamguard_content
ossn_spamguard_domains

It may also add new columns to its own SpamGuard tables during upgrades.

SpamGuard does not modify the structure of ossn_users, but it does read existing user data such as e-mail domain and account creation time for historical registration analysis.

Because this is still under active development, I strongly recommend testing it first on a development or staging installation and making a database backup before installing or upgrading.

A few important design choices:

SpamGuard does not consider one signal proof of abuse.
For example, multiple accounts on the same IP can also happen at schools, offices, mobile providers, VPNs or shared households.

The default IP mode is therefore Hash only. This allows SpamGuard to detect that registrations came from the same IP without retaining the actual IP address.

Raw IP storage is available, but only as an explicit administrator choice.

SpamGuard also works alongside CAPTCHA rather than replacing it. The idea is to add extra layers such as:

CAPTCHA

  • honeypot
  • registration timing
  • e-mail-domain bursts
  • IP hash
  • promoted-domain analysis

The current version is SpamGuard 0.4.3.

I would especially appreciate feedback on OSSN compatibility across different installations, Blog integration, scoring thresholds, privacy defaults, administrator workflow, false positives, and ideas for other useful signals.

This is still under active development, so feedback, testing and code review are very welcome.

Comments
Dutch Eric redegeld Replied 6 days ago

uploaded the adjusted version

Dutch Eric redegeld Replied 6 days ago

Thanks, you were right.

We moved SpamGuard::ensureSchema() out of the normal OSSN init and into enable.php, so the schema check now only runs when the component is enabled instead of on every page/request.

After the change we tested the site with repeated curl TTFB checks. The test site is now stable at around 0.26–0.31 seconds TTFB, without spikes.

Thanks for pointing this out.

Dutch Eric redegeld Replied 7 days ago

Aaaarrrrg yess
Thanks good feedback.
Thought about this component?

Indonesian Arsalan Shah Replied 1 week ago

There is problem i see

SpamGuard::ensureSchema(); this run every time OSSN loads or every page loads, you should add this in enable.php file so when component is enabled it checks. This will slow down the website.

Example enable.php

require_once ossn_route()->com . 'SpamGuard/classes/SpamGuard.php';
SpamGuard::ensureSchema();

Indonesian Arsalan Shah Replied 1 week ago

Nice will test soon!

Component

Developer: eric
License GPL v2
Type: Site admin
Requires OSSN Version : 8.9
Latest Version: 0.3.3
Last Updated 6 days ago
Repository Url View Repository

Versions