{"id":382452,"date":"2026-10-07T21:08:18","date_gmt":"2026-10-07T21:08:18","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/volance-detection\/"},"modified":"2026-10-07T21:07:54","modified_gmt":"2026-10-07T21:07:54","slug":"volance-detection","status":"publish","type":"plugin","link":"https:\/\/ky.wordpress.org\/plugins\/volance-detection\/","author":23581497,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"0.1.0","stable_tag":"0.1.0","tested":"7.1.3","requires":"6.0","requires_php":"8.0","requires_plugins":null,"header_name":"Volance Detection","header_author":"Oops Games LLC","header_description":"Observe-only: relays consented form-submission signals to Volance and logs the human-likeness score in wp-admin. Never blocks; fails open.","assets_banners_color":"cdcecf","last_updated":"2026-10-07 21:07:54","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/github.com\/oops-games-llc\/volance-wordpress","header_author_uri":"https:\/\/volance.com","rating":0,"author_block_rating":0,"active_installs":0,"downloads":41,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"0.1.0":{"tag":"0.1.0","author":"thisissohard002","date":"2026-10-07 21:07:54","revision":3733338}},"upgrade_notice":{"0.1.0":"<p>First release.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3733336,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3733336,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256},"icon.svg":{"filename":"icon.svg","revision":3733336,"resolution":false,"location":"assets","locale":false}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3733336,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3733336,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250},"banner.svg":{"filename":"banner.svg","revision":3733336,"resolution":false,"location":"assets","locale":false}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["0.1.0"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3733336,"resolution":"1","location":"assets","locale":"","width":1280,"height":900},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3733336,"resolution":"2","location":"assets","locale":"","width":1280,"height":900}},"screenshots":{"1":"Settings: connect your keys, choose forms and consent.","2":"Activity log: scores, verdicts and \"No browser evidence\" entries."}},"plugin_section":[],"plugin_tags":[15643,22770,92828,599],"plugin_category":[54],"plugin_contributors":[284894],"plugin_business_model":[],"class_list":["post-382452","plugin","type-plugin","status-publish","hentry","plugin_tags-agents","plugin_tags-bot-detection","plugin_tags-form-security","plugin_tags-spam","plugin_category-security-and-spam-protection","plugin_contributors-thisissohard002","plugin_committers-thisissohard002"],"banners":{"banner":"https:\/\/ps.w.org\/volance-detection\/assets\/banner-772x250.png?rev=3733336","banner_2x":"https:\/\/ps.w.org\/volance-detection\/assets\/banner-1544x500.png?rev=3733336","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":"https:\/\/ps.w.org\/volance-detection\/assets\/icon.svg?rev=3733336","icon":"https:\/\/ps.w.org\/volance-detection\/assets\/icon.svg?rev=3733336","icon_2x":false,"generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/volance-detection\/assets\/screenshot-1.png?rev=3733336","caption":"Settings: connect your keys, choose forms and consent."},{"src":"https:\/\/ps.w.org\/volance-detection\/assets\/screenshot-2.png?rev=3733336","caption":"Activity log: scores, verdicts and \"No browser evidence\" entries."}],"raw_content":"<!--section=description-->\n<p>Volance Detection connects your site to the Volance service. When a visitor allows it, a small script records how they interact with the page, and your server passes that to Volance when they submit a login, registration or comment form. Volance returns an estimated human-likeness score, and the plugin shows it in your WordPress admin.<\/p>\n\n<p>This plugin is <strong>observe-only<\/strong>. It never blocks a submission, never redirects and never changes what a visitor sees. If Volance is slow, down or over quota, your forms work exactly as before.<\/p>\n\n<ul>\n<li>Nothing is collected, and the Volance script is not even downloaded, until the visitor clicks Allow. A visitor who declines, or whose browser sends Global Privacy Control, is not observed.<\/li>\n<li>A score is an <strong>estimate<\/strong>. It is not proof that someone is human or a bot.<\/li>\n<li>Your secret key stays on your server. It is never printed on a page or sent to a browser.<\/li>\n<li>Fingerprinting is never used. If your Volance workspace has the fingerprint tier switched on, the plugin collects and sends nothing until you switch it off.<\/li>\n<li>The activity log keeps the score, verdict, form, time and request ID for 30 days. It stores no IP address, browser details or form content.<\/li>\n<\/ul>\n\n<p>You need a Volance account. Create one at https:\/\/app.volance.com.<\/p>\n\n<h3>External services<\/h3>\n\n<p>This plugin connects to the Volance service, operated by Oops Games LLC, to estimate whether a form submission came from a human, an agent or a bot.<\/p>\n\n<p><strong>1. Volance script (visitor's browser).<\/strong> After a visitor clicks Allow, their browser downloads and runs https:\/\/app.volance.com\/trace.js. It makes no network requests of its own. Downloading it reveals the visitor's IP address and browser details to Volance's servers, as any web request does.<\/p>\n\n<p><strong>2. Volance scoring API (your server).<\/strong> When a visitor who allowed detection submits an observed form, your server sends Volance a request to https:\/\/app.volance.com\/api\/trace\/session and then https:\/\/app.volance.com\/api\/trace\/score, authenticated with your workspace keys. The request contains:<\/p>\n\n<ul>\n<li>interaction timing, pointer movement, wheel and scroll timing, key press timing (never which keys) and coarse browser and device descriptors recorded by the script;<\/li>\n<li>the visitor's IP address, which Volance stores only as a one-way hash;<\/li>\n<li>the visitor's User-Agent, Accept-Language, Sec-CH-UA and Sec-Fetch-Site \/ Sec-Fetch-Mode request headers.<\/li>\n<\/ul>\n\n<p>It never contains typed characters, form values, clipboard contents, page text, page URLs or cookies. Without a visitor's consent, nothing is sent.<\/p>\n\n<p><strong>3. Volance account calls (administrators).<\/strong> The Test connection button and the plan and usage line on the settings page call https:\/\/app.volance.com\/api\/trace\/config, \/session and \/usage from your server with your keys. A scheduled task also checks your workspace settings twice a day.<\/p>\n\n<p>Volance Terms: https:\/\/volance.com\/terms\nVolance Privacy Policy: https:\/\/volance.com\/privacy<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin to <code>\/wp-content\/plugins\/volance-detection<\/code>, or install it from the Plugins screen.<\/li>\n<li>Activate it.<\/li>\n<li>Go to <strong>Settings \u2192 Volance Detection<\/strong>. Paste your public key (<code>pk_...<\/code>) and secret key (<code>sk_...<\/code>) from the Volance portal and click <strong>Test connection<\/strong>.<\/li>\n<li>Choose the forms to observe and how consent is asked, then tick <strong>Turn on<\/strong>.<\/li>\n<\/ol>\n\n<p>If you prefer, define <code>VOLANCE_DETECTION_SECRET_KEY<\/code> in <code>wp-config.php<\/code> instead of saving the secret key in the database.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20this%20plugin%20block%20bots%3F\"><h3>Does this plugin block bots?<\/h3><\/dt>\n<dd><p>No. It scores and logs. Blocking is up to you.<\/p><\/dd>\n<dt id=\"what%20exactly%20is%20sent%20to%20volance%3F\"><h3>What exactly is sent to Volance?<\/h3><\/dt>\n<dd><p>Only for a visitor who allowed detection and then submitted an observed form: interaction timing, pointer movement, wheel and scroll timing, key press timing (never which keys), coarse browser and device details, the visitor's IP address, and the visitor's User-Agent, Accept-Language, Sec-CH-UA and Sec-Fetch headers. Volance stores the IP address only as a one-way hash. See the External services section.<\/p><\/dd>\n<dt id=\"what%20is%20never%20collected%3F\"><h3>What is never collected?<\/h3><\/dt>\n<dd><p>The characters a visitor types, form values, clipboard contents and page text. The plugin also does not send page URLs or cookies. The plugin and the Volance service both reject content-bearing fields.<\/p><\/dd>\n<dt id=\"how%20do%20i%20ask%20visitors%20for%20consent%3F\"><h3>How do I ask visitors for consent?<\/h3><\/dt>\n<dd><p>Use the built-in Allow \/ Decline notice, or choose \"Use my own consent tool\" and call <code>window.volanceDetection.setConsent(true)<\/code> when a visitor agrees (and <code>false<\/code> if they decline or withdraw). You can also dispatch a <code>volance-detection:consent<\/code> event on <code>document<\/code> with <code>{ detail: { granted: true } }<\/code>.<\/p><\/dd>\n<dt id=\"how%20long%20is%20data%20kept%3F\"><h3>How long is data kept?<\/h3><\/dt>\n<dd><p>This plugin's log is deleted after 30 days. Volance deletes raw scores and sessions after 30 days; see its privacy policy.<\/p><\/dd>\n<dt id=\"i%20use%20a%20proxy%20or%20cdn.%20will%20the%20visitor%20ip%20be%20right%3F\"><h3>I use a proxy or CDN. Will the visitor IP be right?<\/h3><\/dt>\n<dd><p>By default the plugin sends <code>REMOTE_ADDR<\/code>. If your site sits behind a trusted proxy, return the real address from the <code>volance_detection_visitor_ip<\/code> filter.<\/p><\/dd>\n<dt id=\"will%20it%20slow%20my%20forms%20down%3F\"><h3>Will it slow my forms down?<\/h3><\/dt>\n<dd><p>Scoring runs after the response has been sent on servers that support it (PHP-FPM and LiteSpeed). On other servers a submission can wait for up to a few seconds if Volance is slow; there is a 3 second limit per call and no retries.<\/p><\/dd>\n<dt id=\"what%20happens%20when%20i%20uninstall%3F\"><h3>What happens when I uninstall?<\/h3><\/dt>\n<dd><p>The plugin removes its settings, log table and scheduled task. Data already stored by Volance is managed in the Volance portal.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>0.1.0<\/h4>\n\n<ul>\n<li>First release: settings, consent notice, observe-only scoring of login, registration and comment forms, activity log, plan and usage line.<\/li>\n<\/ul>","raw_excerpt":"Estimates whether a login, registration or comment submission came from a human, an agent or a bot, using the Volance service. Observe-only.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ky.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/382452","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ky.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/ky.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/ky.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=382452"}],"author":[{"embeddable":true,"href":"https:\/\/ky.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/thisissohard002"}],"wp:attachment":[{"href":"https:\/\/ky.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=382452"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/ky.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=382452"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/ky.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=382452"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/ky.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=382452"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/ky.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=382452"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/ky.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=382452"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}