Block Comment Spam Bots
Professional spammers use programs to automate their spamming. The ‘Block Comment Spam Bots’ (BCSB) plugin efficiently blocks their process. No more comment spam! As no legitimate user will use the professional spammer’s automated process which relies on cURL and WGET commands, real users will never notice the BCSB plugin at work. There are no CAPTCHAS for your visitors to interact with. No silly questions. Just the comment form as designed in any theme. On the admin side, there are no blacklists, special keys (like Askimet), overloaded spam queues, or overworked databases that store spam comments until you manually delete them. Install the plugin and that’s it. Invisible, to you and your visitors. The only change you will notice is in your admin area. The list of comments now has a green check next to them. That way you know that comment was made on your website by a real person and was not bypassed by hacking spammers connecting directly to your server. All that remains is comments made by real people, and while real people can spam, it takes them time and effort. The amount of spam from real people is a lot more manageable than the tsunami from automated spammers, saving you time to concentrate on the important things in life, like your readers, and making connections. We’ve tested it on multiple websites and it wipes out automated spam completely. If it doesn’t on your site, please let us know. ** Geeky Stuff ** …in case you are interested in how it works… tl;dr – This provides a total and easy solution to comment spam from spam bots. Comments are processed by the WordPress wp-post-comments.php file. Automated spammers (‘spam bots’) can provide (‘post’) data directly to that page, bypassing any comment processing, by using CURL/WGET commands. Bypassing the comment form by posting directly (via CURL or WGET commands), is quite easy. Just send the post ID number, and the bot’s fake name and email, and the spammy content. Boom! Comment spam is on your site! The result is comment spam – and that is not always caught by other comment spam checkers. Even if it is caught by programs such as Akismet, processing that spam takes some server resources, including writing to the database. This plugin uses several techniques to ‘sense’ a spambot. There are hidden fields that are changed after a delay. There is a delay in displaying the submit button. And it blocks direct access to the WordPress post/processing functions. The techniques, also used in our standalone “FormSpemmerTrap” (FST) program, and our other anti-spam plugins (like FormSpammerTrap for Comments), are very effective. They use a bit of JavaScript to block spambots – since automated processes via CURL/WGET/etc cannot process JS code. It’s simple: you install this plugin, activate it, and bot comments will stop. Immediately. And it doesn’t add any visual impediments to your comments. No reCaptcha things (which many see as a pain). No silly questions (‘what is 2+8’) on the form. Your comment form does not change. Regular users will not notice a difference. But you will. No more spam comments for you! This is the best solution to block comment spam. We’ve tested it on a site that had 20-40 spam comments a day. With this plugin enabled, the spam comment stopped. Immediately. And there have been none since installing this plugin. ** Not one. Zero.** The Admin, Comments list page is modified to show a column with a green checkmark icon if the comment was entered by a real person and not a bot. This is an assurance that the comment was not entered via an automated CURL/WGET to the wp-comments-post.php file. A comment that is on the list that does not show the checkmark was done by a bot. But you won’t see those blocked comments with this plugin enabled. They never get into your database. You can hover over the checkmark icon to see the GUID value indicating a person entered the comment. The plugins ‘Settings’ screen has no settings. You don’t even need to look at the Settings screen. If you do, you’ll see information about the plugin. And there is a CURL command you can use to test the effectiveness of blocking (or not blocking) direct access to the wp-comments-post.php file. The plugin also adds the hidden GUID field to the comment form after a delay to help block bots that are using the comment form to submit. If the hidden field is not submitted then a bot tried to bypass the comment form. And a short delay happens before the comment submit button is displayed – another bot protection.
Top keywords
- comment21×2.68%
- spam18×2.29%
- comments11×1.40%
- comment spam7×0.89%
- form7×0.89%
- automated6×0.76%
- bot6×0.76%
- comment form6×0.76%
- curl6×0.76%
- real6×0.76%
- there6×0.76%
- wget5×0.64%
Simple CAPTCHA with Cloudflare Turnstile
Easily add Cloudflare Turnstile to all your WordPress website forms to protect them from spam! A user-friendly, privacy-preserving reCAPTCHA alternative. 100% free! Supported Forms You can currently enable Turnstile on the following forms: WordPress Login Form Registration Form Password Reset Form Comments Form WooCommerce Checkout Pay For Order Account Details Form Login Form Registration Form Password Reset Form Form Plugins WPForms Fluent Forms Contact Form 7 Gravity Forms Formidable Forms Forminator Forms Jetpack Forms Kadence Forms SureForms Other Integrations Elementor Pro Forms Easy Digital Downloads Forms Paid Memberships Pro Forms Mailchimp for WordPress Forms MailPoet Forms BuddyPress Registration Form bbPress Create Topic & Reply Forms MemberPress Forms Ultimate Member Forms WP-Members Forms WP User Frontend Forms WP User Manager Forms wpDiscuz Comments Form CheckoutWC & Flux Checkout Sunshine Photo Cart This plugin is also compatible with WordPress Multisite, and most two-factor authentication (2FA) plugins. Other Features The plugin includes several other features and options: Theme: Select the default theme for Turnstile. Language: Set the default language for Turnstile. Appearance Mode: Choose if Turnstile is always displayed, or only when an interaction is required. Disable Submit Button: Disable the submit button on forms until the Turnstile challenge is completed. Custom Error Message: Set your own custom error message for failed submissions. Whitelist: Prevent Turnstile from showing for logged in users, or certain IP addresses (wildcards are not supported). Resource Hint (Preconnect): Option to enable resource hint preconnect for improved performance. Failsafe Mode: Option to enable failsafe mode. When Cloudflare is down, this mode will either allow submissions, or fallback to reCAPTCHA. Debug Logging: Enable debug logging of Turnstile form submission events to help with troubleshooting. Getting Started It’s super quick and easy to get started with Cloudflare Turnstile! Simply generate a “site key” and “secret key” in your Cloudflare account, and add these in the plugin settings page. Select which forms Turnstile should be added to and click save. Finally, click the “TEST API RESPONSE” button to make sure the Turnstile API response is working OK. A new Cloudflare Turnstile challenge will then be displayed on your selected forms to protect them from spam! For more detailed instructions, please see our setup guide. What is Cloudflare Turnstile? Cloudflare Turnstile delivers frustration-free, CAPTCHA-free web experiences to website visitors. Turnstile is an anti-spam filter that stops abuse and confirms visitors are real without the data privacy concerns or awful UX that CAPTCHA thrusts on users. Learn more here: https://www.cloudflare.com/en-gb/products/turnstile/ Is it free to use? Yes, this plugin is completely free with no paid version, and does not include any additional data tracking. Cloudflare Turnstile is also a completely free service. Plugin Languages Currently available in 14 languages. Thank you to all the contributers! If you would like to help contribute translations, please click here. Other Information For help & suggestions, please create a support topic. Follow the developer @ElliotSowersby on Twitter. View on GitHub Support The Plugin If you would like to support the continued development and support of this plugin, you can make a donation. Trademark Notice Cloudflare, the Cloudflare logo, and Cloudflare Workers are trademarks and/or registered trademarks of Cloudflare, Inc. in the United States and other jurisdictions. This plugin is not affiliated with, endorsed, or sponsored by Cloudflare, Inc.