bhadaway / stop-spammers

Stop Spammers has been forked into a new project called Dam Spam.
https://github.com/bhadaway/dam-spam
35 stars 13 forks source link

Just when I thought I FOUND the Best Spam Plugin it BLOCKED Me! #189

Closed NotAgainx2 closed 6 months ago

NotAgainx2 commented 6 months ago

Just when I thought I FOUND the Best Spam Plugin it BLOCKED Me!

WOW! I just installed Anti-Spam: Spam Protection and after logging OUT of the WordPress ADMIN I want to see if the settings for Anti-Spam had changed. Instead After login successfully with my credentials when I got to my 2 FACTOR authenticator to supply my code I was told I had the wrong code even though I had my smart phone in front of me with the correct code still good for another 20 seconds. I tested this out on the 2nd site I had just installed the Anti-Spam plugin and the 2 FACTOR Authenticator told me I had the wrong code again. So I had to FTP and disable the Anti-Spam plugin in order to gain access which I was able to do on both sites. CONCLUSION the Anti-Spam plugin does NOT work with 2 FACTOR Authenticator. The Plugin really looked impressive and I hoped it would be a winner but sadly it FAILED. If you have a FIX for this issue I’ll be willing to try the Anti-Spam plugin again.

Thank you JP

bhadaway commented 6 months ago

Hi JP,

Glad you were able to regain access, and yes, there is currently a known conflict with one of the settings and 2FA.

Stop Spammers > Protections Options > Toggle off "Check Credentials on All Login Attempts" > Save

Thanks

NotAgainx2 commented 6 months ago

Hello Bhad, Thank you for the TIP. I've reinstalled and tested the Spam Blocked plugin it's working and using your guidance I've been able to login with 2 Factor Authentication with no issues. Many Thanks JP

bhadaway commented 6 months ago

You're welcome.

NotAgainx2 commented 6 months ago

Sorry, I need to post more here, I was using Stop Spammers, with Toggle off "Check Credentials on All Login Attempts" but when another developer of mine was trying to access our Wordpress Admin he was denied access even with the right credentials the only way to gain access was to turn OFF Stop Spammers. Even 2 Factor Authentication was turned off and he had no access. So something is interfering with Wordfence or Wordpress login. Not sure why this is happening, however, I wanted to share this info, as I'd LOVE to use "Stop Spammers" once this is all fixed. Thank you JP

bhadaway commented 6 months ago

I don't think anything needs to be fixed in this case. You'll still need to often whitelist people you invite to use your admin. The easiest way to do this is:

Stop Spammers > Allow Lists > Add the Developer's Email > Save

PS: Just to manage your expectations a bit in the future, Stop Spammers is a fairly aggressive plugin. It's really not a "set and forget" type thing. Using a plugin like this doesn't just work all on its own. It's a tool and you're the gatekeeper. You'll always need to let good people in and make adjustments when the bad ones get in. I'm not describing Stop Spammers, but security in nature.