WordPress Comments and Spam: Settings, Plugins and Privacy

By: Irina Shvaya | October 1, 2026
This guide is part of our WordPress resource hub: costs and hosting, the block editor, plugins, SEO and speed, security, maintenance, WooCommerce, development, comparisons and migrations.

Comments can build community on a blog, but on many business sites they mostly attract spam. WordPress gives you a full set of built-in controls under Settings, Discussion: you can moderate everything, hold comments with links, block words or IP addresses, close comments on older posts or turn them off entirely. Add a spam filter and most of the junk never reaches your inbox.

Spam does not stop at comments, though. Contact forms, registration forms, WooCommerce reviews and checkout pages all receive automated submissions. The same principles apply: layer your defenses, keep humans in the loop for anything public, and be clear with visitors about what data you collect.

This guide covers the core comment settings, anti-spam plugins and their pricing models as of October 2026, how to disable comments cleanly, how to handle form spam, and the privacy points to cover. Plugins are described neutrally, not ranked.

Key Takeaways

  • WordPress's Discussion settings already include moderation rules, a link threshold (two links by default), keyword and IP lists and automatic closing of old posts.
  • Akismet (5+ million active installs) is free for personal sites on a name-your-price basis; commercial sites need a paid plan, from $9.95 a month billed yearly as of October 2026.
  • Alternatives range from local, free filters such as Antispam Bee to honeypot plugins and cloud services such as CleanTalk.
  • If you do not want comments, close them in Discussion settings and on existing posts, or use a plugin to remove them sitewide.
  • Comments involve personal data, including IP addresses, so your privacy policy should explain what you collect and which services check it.

The Discussion settings you should know

Go to Settings, Discussion. The official documentation explains each option. The ones that matter most for spam and moderation:

Default post settings

  • Allow people to submit comments on new posts: on by default in new installs. Unchecking it affects new posts only; existing posts keep their own setting.
  • Allow link notifications from other blogs (pingbacks and trackbacks) on new posts: a common source of spam. Many sites turn this off.

Other comment settings

  • Comment author must fill out name and email: a small barrier for bots; the details are not verified.
  • Users must be registered and logged in to comment: strongly reduces spam, at the cost of fewer casual comments.
  • Automatically close comments on old posts: you set how many days old a post must be. older posts can keep attracting spam for years, and closing them keeps approved comments visible.
  • Show comments cookies opt-in checkbox: on by default; visitors choose whether WordPress remembers their name, email and website.

Before a comment appears

  • Comment must be manually approved: every comment waits for review.
  • Comment author must have a previously approved comment: on by default; first-time commenters wait in the queue.

Comment moderation and disallowed keys

  • Link threshold: WordPress holds a comment if it contains a set number of links. The default is two.
  • Moderation list: comments containing listed words, names, URLs, emails or IP addresses are held. The list matches inside words, so "press" matches "WordPress".
  • Disallowed Comment Keys: comments matching these entries are not held for review. In current WordPress code they go straight to the trash (or to spam if the trash is disabled). Use it sparingly, because legitimate comments can be caught.

A moderation workflow that scales

A simple routine keeps comments useful without eating hours:

  1. Keep "previously approved comment" on so regulars post instantly and newcomers are reviewed.
  2. Run a spam filter so obvious junk never reaches the queue.
  3. Review the Pending queue on a schedule, not on every email notification.
  4. Check the Spam folder occasionally for false positives, especially after changing filters.
  5. Share moderation with Editors so it is not a single person's job; in core, the Editor role includes the capability to moderate comments.

WooCommerce product reviews are stored as comments too, so the same settings and filters apply to them.

Anti-spam plugins and how they work

Anti-spam tools use a few different approaches:

  • Cloud filtering: the comment or form submission is sent to an external service that scores it against data from many sites (Akismet, CleanTalk).
  • Local filtering: rules and checks run on your own server, with no external call (Antispam Bee).
  • Honeypots: hidden fields that humans never see but bots fill in (WP Armour).
  • Challenges: CAPTCHA-style checks such as Google reCAPTCHA or Cloudflare Turnstile.

The table lists well-known options in no particular order. Install bands come from WordPress.org and pricing from vendor pages and plugin listings, checked on October 1, 2026.

PluginApproachWordPress.org installsPricing model (as of October 2026)
Akismet Anti-spamCloud filtering by Automattic for comments and supported forms5+ millionPersonal sites: name your price; Pro $9.95/month billed yearly (1 site, 500 spam checks a month); Business $49.95/month billed yearly
Antispam BeeLocal filtering, no external service700,000+Free for private and commercial use
WP Armour (Honeypot Anti Spam)Honeypot fields, no external API calls400,000+Free; paid Extended version with a yearly license
Anti-Spam by CleanTalkCloud service covering comments, forms, registrations and orders200,000+Free trial, then a paid subscription (listed at $12 per year in its plugin description)
Simple CAPTCHA with Cloudflare TurnstileAdds Cloudflare Turnstile challenges to forms200,000+Free plugin; uses Cloudflare's Turnstile service
Advanced Google reCAPTCHAAdds Google reCAPTCHA to login, comment and other forms200,000+Free plugin; uses Google's reCAPTCHA service

Akismet's pricing page describes the Personal tier as for "personal sites and blogs" and Pro as for "professional or commercial sites and blogs". If your site sells products or services, plan for a paid tier.

Whichever you choose, check it with the same criteria as any plugin: maintenance, security history, performance and what data it sends where. Our plugin evaluation checklist covers those steps. Avoid running several spam filters on the same form; overlapping checks make false positives harder to diagnose.

How to turn comments off

Many business sites do not need comments at all. To turn them off with core settings:

  1. In Settings, Discussion, uncheck "Allow people to submit comments on new posts" and the pingback and trackback option.
  2. For existing posts, go to Posts, select all, choose Edit under Bulk actions and set Comments to "Do not allow".
  3. Repeat for pages and any other content types that support comments.
  4. Remove or hide comment blocks from your theme templates if your theme still shows an empty comments area.

If you want comments removed everywhere in one step, the Disable Comments plugin (1+ million active installs) can switch them off sitewide or per post type. Its documentation notes that because WooCommerce reviews are stored as comments, disabling comments on products turns reviews off too. As of October 1, 2026, its listing shows it tested up to WordPress 7.0.6, one release series behind the current 7.1.2, so check for updates.

Turning comments off does not delete existing ones. Decide whether to keep them visible, close them or remove them.

Form spam is the bigger problem

On many business sites, contact and quote forms are a bigger spam target than comments, especially once comments are off. Useful layers:

  • Honeypot fields built into many form plugins, or added by a plugin like WP Armour.
  • A challenge such as Cloudflare Turnstile or reCAPTCHA on high-value forms. Check that it offers an accessible path for people using assistive technology.
  • A filter like Akismet or CleanTalk, which many form plugins can call.
  • Server-side rules: rate limiting and blocking known bad sources at your host or firewall.
  • Content rules: reject submissions with links in the name field or repeated sales pitches.

Some spam is not from bots but from people pitching services by hand, which no filter catches perfectly. Our article on Cloudflare CAPTCHA in site security covers the challenge layer, and our custom forms and workflow plugins post covers custom filtering rules.

Privacy considerations for comments

Comments are personal data. WordPress's suggested privacy policy text says that when visitors comment, the site collects "the data shown in the comments form, and also the visitor's IP address and browser user agent string to help spam detection". It also notes that "An anonymized string created from your email address (also called a hash) may be provided to the Gravatar service", and that comments and their metadata "are retained indefinitely" by default.

Practical steps:

  • Use Settings, Privacy to create a privacy policy page and review the suggested text for comments, Gravatar and any spam service.
  • Disclose cloud spam services. WordPress's suggested text includes "Visitor comments may be checked through an automated spam detection service."
  • Keep the comment cookie opt-in checkbox enabled.
  • Turn off avatars (Settings, Discussion, Avatars) if you do not want commenter email hashes sent to Gravatar.
  • Use Tools, Export Personal Data and Erase Personal Data to handle requests; WordPress's comment data is included in both.

This is general information; privacy laws differ by location, so check your obligations with a qualified advisor.

Spam, SEO and security

Spam comments with links can harm how your pages are perceived and lead visitors to bad sites. WordPress adds rel="nofollow ugc" to links in comments, but unmoderated spam still looks careless. Compromised sites are sometimes injected with spam content, which is a different problem from comment spam; our article on pharma hack SEO spam explains the warning signs. For broader protection see the WordPress security plugins guide.

Conclusion

Start with WordPress's own Discussion settings, add one spam filter that fits your budget and privacy stance, and protect forms with layered defenses. If comments add nothing for your audience, turn them off cleanly. Update your privacy policy to match what you actually collect. If you would like help hardening forms and comments as part of regular upkeep, eSEOspace offers website maintenance services, and our WordPress hub has more guides.

Frequently asked questions

Is Akismet free?

For personal sites and blogs, Akismet uses a name-your-price model. Commercial sites need a paid plan; as of October 2026, Pro is $9.95 a month billed yearly for one site and Business is $49.95 a month billed yearly.

Are there free anti-spam plugins for business sites?

Yes. Antispam Bee states it is free for both private and commercial projects and runs without an external service. Honeypot plugins such as WP Armour also have free versions.

How do I stop spam without a plugin?

Use Discussion settings: require a previously approved comment, keep the link threshold low, close comments on older posts, turn off pingbacks and trackbacks, or require users to log in. These reduce spam significantly but rarely eliminate it.

Does disabling comments affect WooCommerce reviews?

It can. WooCommerce stores product reviews as comments, so disabling comments on the product type turns reviews off as well.

Do I need to mention comments in my privacy policy?

WordPress's suggested privacy text covers comments because they collect personal data, including IP addresses, and may involve Gravatar and spam detection services. Review it and adapt it to your site.

Put this into action with eSEOspace

We help businesses grow with website design that actually performs. Explore the services behind this guide:

Book a free strategy call →

Get a FREE Audit

We'll perform a comprehensive SEO, AEO, GEO & CRO audit of your website — completely free — and show you exactly how to outrank your competitors.

Don't have a site yet? Get in touch →

Get a FREE GEO/AEO/SEO Audit

We'll analyze your site's SEO, GEO, AEO & CRO — completely free — and show you exactly how to get found across Google and AI answers.

Don't have a site yet? Get in touch →

You Might Also like to Read