Skip to main content

Form Shield Overview

Form Shield protects your WordPress forms from spam, bots, and phishing using AI-powered analysis — no CAPTCHAs or honeypots required.

How It Works

Form Submission → WordPress Plugin → Behavioral Scoring → TrolleyShield API → AI Analysis → Allow/Flag/Block
  1. User submits a form on your WordPress site (Gravity Forms)
  2. Behavioral scoring — the plugin tracks mouse movement, typing speed, time-on-page, and other signals to generate a human-likeness score (0-100)
  3. Data sent to TrolleyShield — form content, behavioral score, IP address, and user agent are sent to the API
  4. AI analysis — TrolleyShield AI classifies the submission as legitimate, spam, bot, phishing, or suspicious
  5. Action taken — the submission is allowed, flagged for review, or blocked based on the classification

Features

  • No CAPTCHAs — invisible protection that doesn't hurt user experience
  • Behavioral analysis — detects bots via mouse/keyboard patterns, not challenges
  • AI classification — understands context, not just keywords
  • Configurable actions — choose to allow, flag, or block each intent type
  • Usage dashboard — see how many submissions were analyzed and their classifications
  • IP intelligence — VPN, proxy, Tor, and hosting provider detection (Growth tier+)
  • Data export — bulk CSV export of filtered submissions, plus branded single-submission PDF reports

Manually Overriding the Action

Owners and admins can change the action on any submission from the submission detail view. Open a submission, find Recommended Action, and click Edit to choose Allow, Flag, or Block. The AI's detected intent stays unchanged — only the action is overridden, and the submission is marked with an Edited badge.

Changing the action to Allow will fire a Google Ads offline conversion when the submission has a Google Ads click ID (gclid, gbraid, or wbraid) and a conversion action is configured for the account. A manual override bypasses the usual AI thresholds, and you'll be asked to confirm before a conversion is fired. A conversion is only created once per submission, so re-editing won't fire a duplicate.

Supported Platforms

  • Custom Forms — build forms in TrolleyShield and embed on any website (learn more)
  • WordPress with Gravity Forms — via the Form Shield WordPress plugin
  • Any platform — via the API for custom integrations

Requirements

  • A TrolleyShield account on Forms tier or above
  • For WordPress: Gravity Forms installed + the Form Shield plugin
  • For Custom Forms: no external requirements

Next Steps