Skip to main content
Drupal is a registered trademark of Dries Buytaert
Release: OpenID Connect / OAuth client 3.0.0-alpha9 New alpha version released for module openid_connect (3.0.0-alpha9). Usage Milestone: Google Analytics Module google_analytics crossed 1,000 active installs. Release: Timelinr 1.0.1 Minor update available for module timelinr (1.0.1). Release: GraphQL Compose Codegen 1.1.2 Minor update available for module graphql_compose_codegen (1.1.2). Release: Mapy.com 1.1.3 Minor update available for module mapycom (1.1.3). Release: Ckeditor5 entity browser 3.0.3 Minor update available for module ckeditor5_entity_browser (3.0.3). Release: Ckeditor5 entity browser 3.0.1 Minor update available for module ckeditor5_entity_browser (3.0.1). Release: Ckeditor5 entity browser 3.0.2 Minor update available for module ckeditor5_entity_browser (3.0.2). Release: Teamleader Integration 4.0.2 Minor update available for module teamleader (4.0.2). Module Revived: Entityqueue Buttons 1.1.2 Module entityqueue_buttons updated after 8 months of inactivity (1.1.2).

Protected Forms

1,682 sites Security covered Drupal 8–11
View on drupal.org

Protected Forms is a spam protection module that rejects submissions containing specific language patterns or characters. It can protect various form types, including nodes, comments, webforms, and user profiles, and allows administrators to configure bypass permissions for specific roles.

Successor of Protected Permissions module. See #3281497: Protected Submissions has been renamed as Protected Forms

Description

Protected Forms is a light-weight, non-intrusive spam protection module that enables rejection of node, comment, webform, user profile, contact form, private message and revision log submissions which contain undesired language characters or preset patterns.

How it works

If a user attempts to add a content with a trigger pattern in the name, subject or any other textarea or textfield type fields, then the submission is rejected giving a preset error message.

Admins can configure any role's permission to Bypass Protected Forms validation.

The statistics for rejected submissions can be tracked on the Status Report page.

The rejected submissions can be viewed on the Recent log messages page.

Installation

Download and place the recommended version of the module in your website's modules directory, go to the Extend page (/admin/modules) and enable the Protected Forms module.

Alternatively, just run on CLI:

composer require drupal/protected_forms
drush -y en protected_forms

Configuration

Go to the Protected Forms configuration page on /admin/config/content/protected_forms, set the allowed language scripts, reject message text and the trigger patterns for rejection.

If you want to protect form submissions from only anonymous users, then make sure to go to Permissions page (/admin/people/permissions#module-protected_forms) and put a check mark for authenticated user role next to the Bypass Protected Forms validation option.

Troubleshooting

Report all issues on https://www.drupal.org/project/issues/search/protected_forms.

Alternative modules

Depends on

Dependencies of the latest stable release

No dependencies recorded for this project.

Required by

Tracked projects that depend on this one

No tracked projects depend on this one yet.

Activity

Tracked releases
6
Tracked since
Dec 2024
Latest release
1 year ago
Releases (12 mo)
0 ▼ from 6
Maintenance
Dormant

Release Timeline

Releases

Version Type Core Release date
2.0.10 Stable 8–11 Dec 24, 2024
2.0.9 Stable 8–11 Dec 16, 2024
2.0.8 Stable 8–11 Dec 10, 2024
2.0.7 Stable 8–11 Dec 9, 2024
2.0.6 Stable 8–11 Dec 9, 2024
2.0.5 Stable 8–11 Dec 9, 2024