Gravity Forms Spam Hexer vs. Gravity Forms Zero Spam: Which Anti-Spam Plugin Is Better?
Spam protection used to be fairly straightforward.
A bot would find your contact form, ignore everything happening in the browser, and submit 400 entries offering cryptocurrency investments, SEO services, counterfeit medication, or “urgent business partnerships” from people who appeared unfamiliar with the concept of punctuation.
You installed a honeypot, added reCAPTCHA, blocked a few suspicious domains, and moved on.
That is no longer enough for many websites.
Modern spam bots can execute JavaScript, operate through headless browsers, rotate IP addresses, and generate messages that sound almost human. A roofing company might receive a polished inquiry about “strategic backlink collaboration.” A plumber might get a detailed request that begins like a service call and ends with an offer to redesign the company’s website. A law firm may receive dozens of messages that sound plausible until someone realizes the sender submitted the same “unique legal situation” to 600 attorneys.
Two free plugins are now competing to solve this problem for Gravity Forms users:
- Gravity Forms Zero Spam, developed by GravityKit
- Gravity Forms Spam Hexer, developed by Gravity Wiz
Both plugins operate invisibly. Both can use artificial intelligence to examine the actual meaning of a submission. Neither requires visitors to identify traffic lights, motorcycles, crosswalks, or whatever other blurry object CAPTCHA has decided constitutes proof of humanity this week.
However, the two plugins take significantly different approaches.
A Note About Gravity Wiz and GravityKit
Before comparing the two products, it is worth noting that we use products from both Gravity Wiz and GravityKit, and we trust both companies.
Gravity Wiz has spent years building specialized extensions for Gravity Forms. We already use its products, including Spellbook, and consider the Gravity Wiz team to be genuine Gravity Forms experts. Spam Hexer may be new, but it comes from developers with a long track record of understanding how Gravity Forms works in real-world environments.
The same is true of GravityKit. We also use GravityKit products and trust the company’s work. Gravity Forms Zero Spam is not coming from an unknown developer that released a plugin last week and may disappear six months from now. GravityKit has an established presence in the Gravity Forms ecosystem and extensive experience building and maintaining Gravity Forms products.
In other words, this is not a comparison between one trusted developer and one questionable alternative. Both companies are credible, experienced, and actively invested in the Gravity Forms community.
They also compete with each other, which is good for Gravity Forms users. The competition encourages both teams to improve their products, add better controls, and rethink how WordPress forms should handle increasingly sophisticated spam.
The decision should therefore come down to how each plugin works, which controls it provides, and which approach is the better fit for a particular website—not whether one developer can be trusted.
The Biggest Difference: Tokens vs. Proof of Work
Before either plugin asks AI to judge the content, it first tries to determine whether the submission came through a legitimate browser session.
This is where their strategies begin to diverge.
How Gravity Forms Zero Spam Works
Gravity Forms Zero Spam uses a signed, time-limited token.
When someone loads a protected Gravity Form, Zero Spam generates a token and uses JavaScript to place it in the form. When the form is submitted, the server checks whether that token is valid.
A basic spam bot that sends information directly to the form-processing endpoint never properly loads the page. It therefore never receives a valid token.
The submission is marked as spam.
This approach has several advantages:
- It is lightweight.
- It works invisibly.
- It does not require cookies.
- It does not force visitors through a visual challenge.
- It stops many low-effort automated submissions.
The weakness is that a more sophisticated bot can load the page, execute JavaScript, obtain the token, and submit the form in a way that looks much more like a real visitor.
The token proves that the browser followed the expected process. It does not necessarily prove that the browser belongs to an actual person.
How Spam Hexer Works
Spam Hexer uses a computational proof-of-work challenge.
When the form loads, the visitor’s browser receives a unique SHA-256 puzzle. The browser solves that puzzle in the background and submits the answer with the form.
Normally, this occurs while the person is reading the page or filling out the fields. Most legitimate visitors will never notice it.
Spam Hexer offers different difficulty levels:
- Light
- Standard
- Strict
A higher difficulty requires more computation.
The goal is not to create an unsolvable challenge. Modern bots running real browsers can still complete it. The goal is to impose a cost on every automated submission.
A real homeowner requesting an air-conditioner repair solves the challenge once. A spam operation attempting to submit 500,000 messages must solve it 500,000 times.
That additional work consumes processor time, electricity, server capacity, and money.
Spam Hexer also uses unique values to prevent a bot from solving one challenge and replaying the same answer across thousands of submissions.
The difference can be summarized simply:
Zero Spam asks: Did this submission receive a valid token from the form?
Spam Hexer asks: Did this browser complete the unique computational work required for this submission?
Spam Hexer’s proof-of-work approach places more friction on large-scale automated operations. Zero Spam’s token system is lighter and less likely to create noticeable delays on old or underpowered devices.
How Gravity Forms Zero Spam Uses AI
Zero Spam’s AI system performs two particularly useful jobs.
AI Can Catch Content-Based Spam
A submission may pass the token check but still be obvious spam when someone reads it.
For example, a plumber might receive:
Hello, I am interested in emergency drain cleaning. We also help plumbing companies rank number one on Google with guaranteed backlinks.
Technically, the visitor loaded the page and submitted the form correctly. The message is still a sales pitch disguised as a customer inquiry.
Zero Spam can send the submission to an AI model and ask whether it is relevant and legitimate.
A roofing company could provide instructions such as:
Legitimate inquiries usually involve roof leaks, storm damage, inspections, insurance estimates, replacements, repairs, commercial roofing, or scheduling. Messages primarily offering marketing, website design, staffing, investment, or unrelated business services should be treated as spam.
That context helps the model understand what the business actually does.
AI Can Rescue Legitimate Submissions
This may be Zero Spam’s most important advantage.
Sometimes a legitimate visitor fails the token check because of a technical problem. Caching, JavaScript optimization, an old browser tab, an aggressive firewall, or another compatibility issue could interfere with the token.
Zero Spam can ask AI to review the rejected message.
Suppose a homeowner submits:
Our furnace stopped working this morning. The thermostat is on, but the system is blowing cold air. We have two young children in the house. Can someone come out today?
Even if the token check failed, AI can recognize that this sounds like a genuine HVAC service request and restore it.
For a small business, that matters.
A spam entry is annoying. A lost emergency-service call, roof replacement lead, or legal consultation can cost hundreds or thousands of dollars.
Zero Spam’s AI Controls
Zero Spam gives developers several useful controls:
- Global AI instructions
- Form-specific instructions
- Separate confidence levels for catching spam and rescuing entries
- Hourly AI limits
- Field exclusions
- Email-address masking
- Entry notes explaining the AI decision
Field exclusions are especially important.
A law firm might want the model to review the general description of a legal issue without sending a Social Security number, date of birth, home address, or uploaded document to an outside AI provider.
An HVAC company might allow AI to examine the service-request message while excluding payment information, access instructions, or other sensitive fields.
Hourly limits can also prevent an attack from generating an unexpectedly large API bill.
How Spam Hexer Uses AI
Spam Hexer applies AI after a submission successfully passes the proof-of-work challenge.
The model receives information about:
- The website
- The form
- The form fields
- The submitted values
- Custom business context
- The selected confidence threshold
It then classifies the submission and provides a reason for its decision.
A law firm might add context such as:
Legitimate inquiries may involve divorce, custody, criminal defense, estate planning, probate, business disputes, personal injury, or requests to schedule a consultation. Messages offering marketing, guest posts, loans, software development, or unrelated services should be treated as spam.
A roofer could explain:
Legitimate messages may involve leaks, missing shingles, storm damage, hail inspections, insurance claims, roof replacement, commercial roofing, gutters, or requests for an estimate.
Spam Hexer lets the site owner choose what happens when a submission fails proof of work or is classified as spam by AI.
The plugin can:
- Save the entry and mark it as spam
- Silently reject it
- Display a validation error
These actions can be configured separately.
For example, a developer might silently reject submissions that fail proof of work but save AI-classified spam for later review.
That flexibility is useful, although silently rejecting entries should be approached carefully during initial testing. A false positive that is saved as spam can be recovered. A silently discarded $15,000 roof-replacement lead cannot.
Unlike Zero Spam, Spam Hexer’s documented workflow does not use AI to rescue submissions that fail the proof-of-work test. AI classification begins after valid proof of work has been supplied.
Spam Hexer’s OpenRouter Support
One of Spam Hexer’s most interesting features is its direct support for OpenRouter.
OpenRouter is not an AI model. It is a platform that gives developers access to models from numerous AI companies through one API and one billing account.
Depending on current availability, this may include models from:
- OpenAI
- Anthropic
- Meta
- Mistral
- DeepSeek
- Other providers
Instead of configuring a separate account and API key for each company, a developer can use OpenRouter and choose among many available models.
This can be helpful for spam classification because you probably do not need the most expensive, advanced reasoning model in existence to determine that this message is unrelated to plumbing:
Dear business owner, we can increase your domain authority with 5,000 permanent links.
A fast, inexpensive model may be completely adequate.
OpenRouter also offers centralized spending limits, model restrictions, routing controls, and Zero Data Retention options for compatible providers.
OpenRouter vs. OpenAI, Google, or Anthropic Directly
Using OpenRouter adds flexibility, but it also introduces another company into the data-processing chain.
OpenRouter May Be Better When You Want:
- Access to many models through one API
- The ability to change models easily
- Centralized usage and spending controls
- Automatic provider routing
- Zero Data Retention enforcement
- Easy testing of cheaper classification models
- A backup when one provider is unavailable
A Direct Provider May Be Better When You Want:
- A direct relationship with OpenAI, Google, or Anthropic
- One fewer service processing the submission
- Provider-specific billing and support
- Simpler privacy documentation
- No OpenRouter platform fee
- Existing enterprise terms with a particular provider
OpenRouter is not automatically more private or less private. The answer depends on the selected model, provider, endpoint, account settings, and data-retention configuration.
Developers should review those settings before sending customer messages through any AI service.
What Could AI Spam Classification Cost?
For most small-business websites, the actual AI cost should be minimal.
Assume each spam review uses roughly:
- 1,000 input tokens
- 50 output tokens
That would include the instructions, form context, submitted message, classification, confidence score, and explanation.
Actual usage will vary, but this gives us a reasonable example.
Suppose a local HVAC contractor receives 500 form submissions per month. Using an inexpensive model, the monthly classification cost may be only a few cents.
A busier plumbing franchise receiving 5,000 monthly submissions might spend a few dollars.
A high-traffic legal directory processing 25,000 inquiries and spam attempts could spend more, particularly if it chooses a more expensive model.
As an illustration, a low-cost model might place approximate OpenRouter expenses in ranges such as:
- 1,000 classifications: Less than $1
- 5,000 classifications: A few dollars
- 25,000 classifications: Roughly $10–$15
A more capable and expensive model might increase those totals to:
- 1,000 classifications: Around $2
- 5,000 classifications: Around $10
- 25,000 classifications: Around $50
These are examples, not guaranteed prices. AI pricing changes, and the length of each submission affects token usage. OpenRouter also applies its platform fee to paid usage.
For most small businesses, however, the cost of AI classification is unlikely to be the deciding factor.
The larger financial risk is a false positive.
A plumber may spend 20 cents reviewing hundreds of messages but lose a $2,500 sewer-line replacement because one legitimate inquiry disappeared. A roofer might save $4 in API costs while missing a full roof-replacement lead. A lawyer may lose a valuable case consultation because an unusual message was silently rejected.
That is why new configurations should initially save questionable entries as spam instead of permanently discarding them.
Other Advantages of Gravity Forms Zero Spam
Zero Spam currently offers several operational features beyond its basic token system:
- AI-based spam detection
- AI-based rescue of token failures
- Email-address and domain rejection rules
- Wildcard and regular-expression rules
- Scheduled spam reports
- Field-level AI exclusions
- Hourly AI limits
- Save and Continue protection
- Integration with Shield Security’s silentCAPTCHA
- Configurable ordering of spam checks
It is also the more established option, with a larger production history.
For developers who prioritize conservative filtering and false-positive recovery, Zero Spam presents a strong case.
Other Advantages of Spam Hexer
Spam Hexer offers much more visibility into what is happening.
Its reporting can include:
- Proof-of-work successes and failures
- Puzzle-solving times
- AI request counts
- AI response times
- Estimated AI costs
- Classification confidence
- Spam reason codes
- Difficulty levels
- Entry-level analysis
It also integrates with Gravity Forms logging and developer tools.
This makes Spam Hexer particularly attractive for developers who want to investigate patterns, compare configurations, and understand why entries are being blocked.
It can also protect standard WordPress comments, extending its usefulness beyond Gravity Forms.
Should You Run Both?
Running both plugins’ full AI systems on the same form is probably unnecessary.
Doing so could create:
- Duplicate AI requests
- Additional API costs
- Longer processing times
- Conflicting classifications
- More complicated troubleshooting
- Confusion about which plugin marked an entry as spam
It would be better to test the plugins separately on selected forms.
During testing:
- Save suspicious submissions instead of silently rejecting them.
- Review spam entries regularly.
- Track false positives.
- Watch submission latency.
- Monitor API usage and cost.
- Compare the types of spam each plugin catches.
- Test forms from mobile devices and different browsers.
Which Plugin Should You Choose?
Choose Gravity Forms Zero Spam when:
- Protecting real leads from false positives is your highest priority.
- You want AI to rescue legitimate token failures.
- You need field-level privacy controls.
- You want hourly AI limits.
- You need email-domain blocking rules.
- You use Shield Security.
- You prefer a mature, conservative solution.
Choose Spam Hexer when:
- You prefer proof-of-work protection.
- Your spam bots already execute ordinary JavaScript.
- You want detailed reporting and diagnostics.
- You want direct OpenRouter support.
- You want broader model selection.
- You need WordPress comment protection.
- You already use Spellbook.
- You trust Gravity Wiz’s Gravity Forms expertise.
The Bottom Line
Gravity Forms Zero Spam and Spam Hexer are not simply two plugins doing the same thing with different logos.
Zero Spam focuses on lightweight token validation, flexible filtering controls, and AI-powered false-positive rescue.
Spam Hexer focuses on proof of work, detailed observability, configurable enforcement, and broader access to AI models through OpenRouter.
Zero Spam currently looks like the safer choice for businesses where every legitimate inquiry matters and false-positive recovery is essential.
Spam Hexer may be the more technically interesting choice for developers dealing with persistent automated attacks, especially when detailed analytics and model flexibility are important.
For many developers, the best answer will be determined through controlled testing rather than a feature checklist.
Just do not begin that test by silently deleting everything the AI dislikes. Even artificial intelligence has bad days, and your next “suspicious submission” may be a homeowner with a leaking roof, a broken furnace, and a willingness to pay someone immediately.
