eric redegeld
2 weeks ago
I’ve been working on a new OSSN component called SpamGuard and I’d like to share the current version with the community for testing and feedback.
SpamGuard is intended as a privacy-first anti-spam layer for OSSN. It does not automatically ban users or delete content. Instead, it combines several signals and gives administrators a clearer picture of suspicious registrations and promotional activity.
Current features include:
registration monitoring;
HMAC-based IP hashing by default;
optional raw IP storage;
detection of multiple registrations from the same IP hash;
registration bursts by e-mail domain;
historical e-mail-domain review using existing OSSN users;
signup honeypot;
signup speed detection;
NORMAL / WATCH / REVIEW registration status;
external-link analysis in wall posts;
promoted-domain detection;
domain drill-down to the users who posted it;
direct Profile / Message actions;
Blog URL analyzer;
direct links back to detected wall posts and Blog content;
configurable retention period;
trusted-domain allowlist;
English and Dutch language files.
Important before testing: SpamGuard makes changes to the OSSN database.
It creates and maintains its own tables:
ossn_spamguard_events
ossn_spamguard_content
ossn_spamguard_domains
It may also add new columns to its own SpamGuard tables during upgrades.
SpamGuard does not modify the structure of ossn_users, but it does read existing user data such as e-mail domain and account creation time for historical registration analysis.
Because this is still under active development, I strongly recommend testing it first on a development or staging installation and making a database backup before installing or upgrading.
A few important design choices:
SpamGuard does not consider one signal proof of abuse.
For example, multiple accounts on the same IP can also happen at schools, offices, mobile providers, VPNs or shared households.
The default IP mode is therefore Hash only. This allows SpamGuard to detect that registrations came from the same IP without retaining the actual IP address.
Raw IP storage is available, but only as an explicit administrator choice.
SpamGuard also works alongside CAPTCHA rather than replacing it. The idea is to add extra layers such as:
CAPTCHA
The current version is SpamGuard 0.4.3.
I would especially appreciate feedback on OSSN compatibility across different installations, Blog integration, scoring thresholds, privacy defaults, administrator workflow, false positives, and ideas for other useful signals.
This is still under active development, so feedback, testing and code review are very welcome.
Eric redegeld
Replied 6 days ago
uploaded the adjusted version
Eric redegeld
Replied 6 days ago
Thanks, you were right.
We moved SpamGuard::ensureSchema() out of the normal OSSN init and into enable.php, so the schema check now only runs when the component is enabled instead of on every page/request.
After the change we tested the site with repeated curl TTFB checks. The test site is now stable at around 0.26–0.31 seconds TTFB, without spikes.
Thanks for pointing this out.
Eric redegeld
Replied 7 days ago
Aaaarrrrg yess
Thanks good feedback.
Thought about this component?
Arsalan Shah
Replied 1 week ago
There is problem i see
SpamGuard::ensureSchema(); this run every time OSSN loads or every page loads, you should add this in enable.php file so when component is enabled it checks. This will slow down the website.
Example enable.php
require_once ossn_route()->com . 'SpamGuard/classes/SpamGuard.php';
SpamGuard::ensureSchema();
Arsalan Shah
Replied 1 week ago
Nice will test soon!