Any WordPress site that accepts comments will attract spam. Automated bots find the comment form and submit comments stuffed with links to pharmacy, gambling and similar sites, hoping the links get published and help those sites rank in search results. It is not a hack: nobody has logged in to your site or changed its files. The comment form is simply being used for something it was never meant for.
Why it is worth dealing with
- Published spam damages the site. Visitors see it, and a page full of links to dubious sites makes a site look neglected to people and search engines alike.
- Unpublished spam still sits in your database. Comments in the moderation queue or the spam folder are not visible to visitors, but they are still stored and they keep piling up.
- Our malware scanner checks databases as well as files. A stored comment containing spam links can be flagged as malicious content, even though it poses no risk to the server. That is often how these come to light.
If your site does not need comments, turn them off
Many business and club websites never use comments at all. If that is you, switching them off removes the problem completely. It takes two steps, because the first only affects posts published from now on.
- In the WordPress dashboard go to Settings > Discussion. Under Default post settings, untick Allow people to submit comments on new posts and Allow link notifications from other blogs (pingbacks and trackbacks) on new posts, then save.
- For posts that already exist, go to Posts > All Posts and tick the box at the top of the list to select every post. Choose Edit from the Bulk actions menu and click Apply, set Comments to Do not allow, and click Update. The list shows one page of posts at a time, so either repeat this for each page or raise Number of items per page under Screen Options first. Then do the same under Pages.
If you do want comments, moderate them
All of these are in Settings > Discussion:
- Before a comment appears: tick Comment must be manually approved, so nothing is published until you approve it. If that is too much work, Comment author must have a previously approved comment is a lighter option: first-time commenters are held, people you have approved before are not.
- Comment Moderation: set the number of links allowed before a comment is held to 1. That holds any comment containing a link, and the commenter's website address counts as one. Genuine comments rarely need a link; spam almost always has one.
- Other comment settings: tick Automatically close comments on old posts and choose a number of days. Most genuine discussion happens soon after a post is published, so this costs very little.
Add a spam filter
Moderation stops spam being published, but you still have to wade through it. A spam filter plugin sorts it for you. Akismet, from Automattic, the company behind WordPress.com, is the best known. It does nothing until you enter an API key from akismet.com, so activating the plugin on its own is not enough.
Clearing out what is already there
Go to Comments in the dashboard and look at the Pending and Spam tabs. Anything that is clearly spam can be marked as spam, and on the Spam tab the Empty Spam button deletes the lot permanently. Check the Approved tab too, in case spam has already been published.
Keep it in proportion
Comment spam is a nuisance rather than a break-in: it does not give anyone access to your site. Real compromises most often come through out-of-date plugins, and that is where security effort is best spent. For what genuinely protects a WordPress site, see Securing a WordPress site: what actually matters.