Comment Blacklist Updater
Updates the “Comment Blacklist” in Settings / Discussion with a list terms from a remote or local source. By default it get’s the data from Github (“wordpress-comment-blacklist“) by Grant Hutchinson) but you can also get them from any URL or from a local blacklist.txt file. This plugin is an enhanced version of the plugin Comment Blacklist Manager. We decided to create this enhanced version of the plugin, because we wanted to be able to add blacklists without using filters and directly from the WordPress administration. You can still use a filter to modify the blacklist sources if that is more convienient for you. And we also wanted to have more information about the plugin in SETTINGS / DISCUSSION; for example when the blacklist was updated and when it will be updated next time, when the blacklist sources were updated, etc. You can configure three sources for your blacklists: Default blacklist (which can be disabled): wordpress-comment-blacklist by Grant Hutchinson). Please keep in mind that if there is no other blacklist source defined, this will be used as default, even if it\’s not selected. Blacklist from remote URL: You paste the URL to the blacklist and if the file exists and can be accesed (must return code 200) it will be used as a blacklist source. If you want to include a local blacklist for the site, you can upload a blacklist.txt file to the UPLOADS folder and it will also be taken into account. The blacklist.txt file has to be in the root of the UPLOADS folder; it will not be recognized if it\’s for example in /uploads/2025/12/ and the file has to be accesible via http/https (if the access to the file is protected it can\’t be used). And you can use the filter cblm_sources to replace all the blacklists or to add more. If you replace all blacklists with the filter, the settings done in the WordPress administration will be ignored. We decided to keep the same filter as used by “Comment Blacklist Manager” to make it easy to switch between both plugins. Please note: After the September 2023 update only users with administrator privileges can use this plugin. If you’re not an admin you will get following error: “You do not have sufficient permissions to access this page”. What can I do with this plugin? The plugin updates the “Comment Blacklist” in Settings / Discussion with a list terms from a remote or local source. By default it get’s the data from Github (“wordpress-comment-blacklist by Grant Hutchinson) but you can also get them from any URL or from a local blacklist.txt file. Why do I want to update the “Comment Blacklist” in Settings / Discussion? If you want to reduce spam received in your comment forms but also in your contact forms (for example when using Contact Form 7), using blacklisted terms can help. Contact Form 7 encourages to use: Akismet, reCaptcha and the comment blacklist to reduce contact form spam. Contact Form 7 supports spam-filtering with Akismet. Intelligent reCAPTCHA blocks annoying spambots. Plus, using comment blacklist, you can block messages containing specified keywords or those sent from specified IP addresses. The best way to reduce the contact form 7 spam is to use a very extensive term database which is updated regulary with new spam terms. And this plugin does exactly this: Updating the blacklist regularly. Why are you using the “Comment Blacklist for WordPress” from Grant Hutchinson as default source for the blacklist? Since 2011 Grant Hutchinson has been identifying and compiling over 34,000 phrases, patterns, and keywords commonly used by spammers and comment bots in usernames, email addresses, link text, and URIs. His blacklist is very extensive and that’s why we love it. As with all compilations, this blacklist is a work in progress and it is updated more or less every month. And each of these updates will be included automatically with the update process that runs every 24 hours. Sometimes simple is better. If you know another source that is as extensive as this one, drop us a message and we will check if it’s interesting to add it also as a default. System requirements PHP version 5.6 or greater. Comment Blacklist Updater Plugin in your Language! This first release is avaliable in English and Spanish. In the “languages” folder we have included the necessary files to translate this plugin. If you would like the plugin in your language and you’re good at translating, please drop us a line at Contact us. Further Reading You can access the description of the plugin in Spanish at: Actualizador lista negra de comentarios | WordPress Plugin. Contact For further information please send us an email.
Top keywords
- blacklist26×3.28%
- comment11×1.39%
- comment blacklist9×1.13%
- contact8×1.01%
- file7×0.88%
- default6×0.76%
- source6×0.76%
- contact form5×0.63%
- form5×0.63%
- grant5×0.63%
- grant hutchinson5×0.63%
- hutchinson5×0.63%
Blacklist Manager – WooCommerce Anti-Fraud, Blacklist & Checkout Verification
Blacklist Manager is a WooCommerce blacklist, anti-fraud, and spam prevention plugin for stores that need to block fake orders, suspicious customers, spam registrations, and unwanted form submissions. The free plugin is a complete local protection toolkit, not a Premium trial. Use blacklist rules for phone numbers, email addresses, IP addresses, and email domains at WooCommerce checkout, registration, comments, product reviews, REST API orders, and supported WordPress forms. The plugin works with WooCommerce Classic Checkout, WooCommerce Checkout Blocks, Contact Form 7, Gravity Forms, and WPForms. What the free plugin includes Manage local email, phone, IP address, and email-domain entries through Suspects and Blocklist workflows. Stop matching identities at WooCommerce checkout and protect registration, comments, product reviews, supported forms, and WooCommerce REST API orders. Require built-in checkout email verification for the policies you configure. Core owns and runs email verification; phone OTP and Twilio/TextMagic SMS transport belong to Blacklist Manager Premium. Configure free customer notices and admin alerts, then review dashboard blacklist and detection statistics. Documentation | Support | Demo Key Features WooCommerce checkout protection: Block or review orders using phone, email, IP address, and email domain rules. Suspect and blocked lists: Review risky identities before moving confirmed abuse to the blocklist. Fast blacklist management: Add entries from the dashboard or directly from the WooCommerce order screen. Registration protection: Stop signups that match blocked emails, IP addresses, or email domains. Comment and review blocking: Prevent comments and product reviews from blacklisted emails. Form spam protection: Check Contact Form 7, Gravity Forms, and WPForms submissions against blacklist data. Checkout email verification: Require a Core-owned email verification code before allowing checkout to continue. WooCommerce REST API protection: Block blacklisted identities from creating orders through external apps or integrations. Custom notices and alerts: Customize customer-facing block messages and admin email alerts. Dashboard stats: Review blacklist entries and detection attempts from the admin area. Checkout Compatibility Blacklist Manager supports WooCommerce Classic Checkout, WooCommerce Checkout Blocks, and many third-party checkout plugins that use standard WooCommerce checkout and order creation flows. Global Blacklist Decisions Blacklist Manager can optionally connect your store to Global Blacklist Decisions, a separate broader-risk service that checks order identities such as email, phone, IP address, address, and email domain against network data. It is not required for local Core protection and is not a prerequisite for Premium. Learn more about Global Blacklist Decisions Premium Features Consider Blacklist Manager Premium when recurring abuse makes manual blacklist maintenance too time-consuming, when checkout or payment patterns need automatic action, when repeat attackers change individual identity fields, or when your team needs deeper investigation and audit tools. Premium is the advanced local/store extension. It adds: Risk scoring for blacklist, identity, IP, address, payment, device, and order pattern signals. Automation rules to auto-suspect, auto-block, or auto-review orders. Payment intelligence for Stripe, PayPal, Mollie, Braintree, WooPayments, AVS, card country, and payer mismatch signals. Device identity checks to link repeat abuse across emails, phones, IPs, addresses, and accounts. Advanced blocking for customer name, address, device, disposable email, disposable phone, country, VPN, and proxy signals. Activity logs, import/export, cleanup tools, permissions, multi-store sync, CAPTCHA, IP intelligence, geocoding, and email validation integrations. Phone OTP runtime and Twilio/TextMagic SMS transports; Core continues to own checkout email verification. Explore Premium Supported Plugins and Integrations Supported plugins WooCommerce Contact Form 7 Gravity Forms WPForms Premium integrations WooCommerce Stripe Gateway, Payment Plugins for Stripe WooCommerce, WooCommerce PayPal Payments, Payment Plugins for PayPal WooCommerce, Braintree for WooCommerce, Mollie Payments for WooCommerce, and WooPayments. Cloudflare, reCAPTCHA v3/v2, hCaptcha, IP-api, BigDataCloud, ZeroBounce, NumCheckr, Google Maps, Twilio, and TextMagic. Use Cases Block fake WooCommerce orders before payment review. Prevent repeat abuse from known phone numbers, email addresses, IP addresses, and domains. Reduce spam registrations, comments, product reviews, and form submissions. Require Core email verification during checkout without installing Premium. Add Premium phone OTP when a store also needs SMS-based phone ownership checks. Review suspicious customers before moving them to the blocklist. Use Global Blacklist Decisions as an additional fraud signal.