Spam comments on a WordPress site: how to stop them

Any WordPress site that accepts comments will attract spam. Automated bots find the comment form and submit comments stuffed with links to pharmacy, gambling and similar sites, hoping the links get published and help those sites rank in search results. It is not a hack: nobody has logged in to your site or changed its files. The comment form is simply being used for something it was never meant for.

Why it is worth dealing with

  • Published spam damages the site. Visitors see it, and a page full of links to dubious sites makes a site look neglected to people and search engines alike.
  • Unpublished spam still sits in your database. Comments in the moderation queue or the spam folder are not visible to visitors, but they are still stored and they keep piling up.
  • Our malware scanner checks databases as well as files. A stored comment containing spam links can be flagged as malicious content, even though it poses no risk to the server. That is often how these come to light.

If your site does not need comments, turn them off

Many business and club websites never use comments at all. If that is you, switching them off removes the problem completely. It takes two steps, because the first only affects posts published from now on.

  1. In the WordPress dashboard go to Settings > Discussion. Under Default post settings, untick Allow people to submit comments on new posts and Allow link notifications from other blogs (pingbacks and trackbacks) on new posts, then save.
  2. For posts that already exist, go to Posts > All Posts and tick the box at the top of the list to select every post. Choose Edit from the Bulk actions menu and click Apply, set Comments to Do not allow, and click Update. The list shows one page of posts at a time, so either repeat this for each page or raise Number of items per page under Screen Options first. Then do the same under Pages.

If you do want comments, moderate them

All of these are in Settings > Discussion:

  • Before a comment appears: tick Comment must be manually approved, so nothing is published until you approve it. If that is too much work, Comment author must have a previously approved comment is a lighter option: first-time commenters are held, people you have approved before are not.
  • Comment Moderation: set the number of links allowed before a comment is held to 1. That holds any comment containing a link, and the commenter's website address counts as one. Genuine comments rarely need a link; spam almost always has one.
  • Other comment settings: tick Automatically close comments on old posts and choose a number of days. Most genuine discussion happens soon after a post is published, so this costs very little.

Add a spam filter

Moderation stops spam being published, but you still have to wade through it. A spam filter plugin sorts it for you. Akismet, from Automattic, the company behind WordPress.com, is the best known. It does nothing until you enter an API key from akismet.com, so activating the plugin on its own is not enough.

Clearing out what is already there

Go to Comments in the dashboard and look at the Pending and Spam tabs. Anything that is clearly spam can be marked as spam, and on the Spam tab the Empty Spam button deletes the lot permanently. Check the Approved tab too, in case spam has already been published.

Keep it in proportion

Comment spam is a nuisance rather than a break-in: it does not give anyone access to your site. Real compromises most often come through out-of-date plugins, and that is where security effort is best spent. For what genuinely protects a WordPress site, see Securing a WordPress site: what actually matters.

  • 0 Users Found This Useful
Was this answer helpful?

Related Articles

Recognising a phishing email that claims to be from us

Hosting customers are a standard target for phishing, because an attacker who gets your control...

My website has been hacked: the first things to do

Work in this order. The instinct is to delete the bad files and carry on, which is exactly how...

File and folder permissions, and why 777 is never the answer

Every file and folder has permissions controlling who may read, write and run it. When something...

Turning on two-factor authentication

Two-factor authentication means that knowing your password is not enough to get in. It is the...

Why we block IP addresses, and how to get unblocked

Our servers block addresses automatically when they behave like an attack. This is not a...