Dealing with WordPress spam: comments, forms and registrations
How to reduce spam across your WordPress site using comment moderation settings, form protection, anti-spam tools, registration controls and general hardening measures.
Spam is one of the most persistent annoyances of running a WordPress site. Bots and human spammers target every form they can find, including comment forms, contact forms, registration pages and login screens.
Beyond being a nuisance, spam can cause real problems. Comment spam often contains links to phishing or malware sites that can harm your visitors and damage your site's reputation with search engines. Large volumes of bot traffic use up server resources (sometimes enough to cause 502, 503 or 504 errors), and fake user registrations clutter your database. Dealing with it early saves a lot of clean-up later.
The sections below cover each place spam typically appears.
Comment spam
WordPress has built-in moderation settings that are worth setting up before reaching for anything else. They're all under Settings → Discussion.1
- Comment must be manually approved stops any comment appearing on your site until you approve it. Spam still arrives in your moderation queue, but visitors never see it.
- Automatically close comments on posts older than a number of days stops comments on old posts. Most genuine discussion happens soon after a post is published, while spam targets old posts indefinitely.
- Allow link notifications from other blogs (pingbacks and trackbacks) on new posts can be unticked. These were designed to tell you when another site links to your content, but they're widely abused for spam. The setting only affects new posts, so existing posts keep their current setting unless you change them individually or with bulk edit.
- Comment author must fill out name and email adds a small hurdle, though it won't stop determined bots on its own.
If you don't want comments at all, you can turn them off for new posts in the same screen.
For stronger automated filtering, an anti-spam plugin can check comments against known spam patterns and sources. Use one anti-spam tool at a time. Running several can cause conflicts where genuine comments get caught or spam slips through.
Contact form spam
If your site has a contact form, it's almost certainly receiving spam. Most form plugins have a honeypot option, which adds a hidden field that people can't see but bots fill in, so the form can quietly reject those submissions.
Honeypots catch simple bots, but more sophisticated ones get past them. For stronger protection, add a CAPTCHA such as Cloudflare Turnstile or Google reCAPTCHA to your forms. Most well-maintained form plugins support these, either built in or through an add-on. Test the form after adding one, and bear in mind some CAPTCHAs are harder for people using assistive technology.
If you notice repeated spam from the same IP addresses, blocking them through your host's firewall or your security plugin can help. Keep a note of what you block, so you can undo it if a real visitor gets caught.
If the problem is the opposite (genuine form messages not arriving), see our guide to fixing WordPress email delivery.
Registration and login abuse
If you don't need people to register on your site, the simplest fix is to untick Anyone can register under Settings → General.2 WooCommerce stores have their own account settings, covered in our WooCommerce fraud prevention guide.
If you do allow registrations (for memberships, a shop or a community area), WordPress's own security guidance recommends:3
- Adding a CAPTCHA to the login and registration forms
- Limiting repeated login attempts, ideally at your host, CDN or firewall rather than inside WordPress, since that stops the traffic before it uses your server's resources
- Using strong, unique passwords and two-factor authentication for administrator accounts
General hardening
Keeping WordPress, plugins and themes updated is one of the simplest and most effective defences, since outdated software is a common way in for attackers. WordPress installs minor maintenance and security releases automatically by default,4 and you can turn on automatic updates for individual plugins from the Plugins screen. Our guide to handling a plugin security vulnerability explains how to judge how urgent an update is. Take a backup before major updates, and test on a staging copy if you can.
XML-RPC is an older way for other apps to talk to WordPress, and the xmlrpc.php file is a frequent target for login attacks. WordPress's guidance is to disable it if you don't use it, and to restrict and rate-limit it if you do.3 Some tools still rely on it, including Jetpack and some mobile apps, so check before switching it off. Many security plugins and hosts have an option to disable it. If you do it through .htaccess instead, download a copy of the file first, since a broken rule can cause a 500 internal server error.
A web application firewall (WAF), provided by your host, a service like Cloudflare or a security plugin, filters malicious traffic before it reaches your site. WordPress's guidance prefers blocking at this level where possible.3
Finally, review your user accounts from time to time. Remove accounts that are no longer needed, and check nobody has more access than they need. Take a backup before deleting users, since WordPress asks what to do with a deleted user's content and the wrong choice can remove posts.
Need help dealing with spam?
If spam volume is overwhelming and these measures aren't bringing it under control, my freelance WordPress development and emergency WordPress support can help with a full review of your settings and a clean-up. Your hosting provider may also be able to block abusive traffic at server level.
options-discussion.php, WordPress source code on GitHub. ↩
options-general.php, WordPress source code on GitHub. ↩
Brute force attacks, WordPress Advanced Administration Handbook. ↩ ↩ ↩