WordPress OSINT, maintenance or security needs? Reach out!
TLDWP

Plugin: block-comment-spam-bots (Used by 280 domains)

Block Comment Spam Bots

πŸ‘€ Rick Hellewell πŸ“¦ v2.62 πŸ”— Plugin Homepage

Professional spammers use programs to automate their spamming. The β€˜Block Comment Spam Bots’ (BCSB) plugin efficiently blocks their process. No more comment spam!

As no legitimate user will use the professional spammer’s automated process which relies on cURL and WGET commands, real users will never notice the BCSB plugin at work. There are no CAPTCHAS for your visitors to interact with. No silly questions. Just the comment form as designed in any theme.

On the admin side, there are no blacklists, special keys (like Askimet), overloaded spam queues, or overworked databases that store spam comments until you manually delete them.

Install the plugin and that’s it. Invisible, to you and your visitors. The only change you will notice is in your admin area. The list of comments now has a green check next to them. That way you know that comment was made on your website by a real person and was not bypassed by hacking spammers connecting directly to your server.

All that remains is comments made by real people, and while real people can spam, it takes them time and effort. The amount of spam from real people is a lot more manageable than the tsunami from automated spammers, saving you time to concentrate on the important things in life, like your readers, and making connections.

We’ve tested it on multiple websites and it wipes out automated spam completely. If it doesn’t on your site, please let us know.

** Geeky Stuff **
…in case you are interested in how it works…

tl;dr – This provides a total and easy solution to comment spam from spam bots.

Comments are processed by the WordPress wp-post-comments.php file. Automated spammers (β€˜spam bots’) can provide (β€˜post’) data directly to that page, bypassing any comment processing, by using CURL/WGET commands.

Bypassing the comment form by posting directly (via CURL or WGET commands), is quite easy. Just send the post ID number, and the bot’s fake name and email, and the spammy content. Boom! Comment spam is on your site!

The result is comment spam – and that is not always caught by other comment spam checkers. Even if it is caught by programs such as Akismet, processing that spam takes some server resources, including writing to the database.

This plugin uses several techniques to β€˜sense’ a spambot. There are hidden fields that are changed after a delay. There is a delay in displaying the submit button. And it blocks direct access to the WordPress post/processing functions.

The techniques, also used in our standalone β€œFormSpemmerTrap” (FST) program, and our other anti-spam plugins (like FormSpammerTrap for Comments), are very effective. They use a bit of JavaScript to block spambots – since automated processes via CURL/WGET/etc cannot process JS code.

It’s simple: you install this plugin, activate it, and bot comments will stop. Immediately.

And it doesn’t add any visual impediments to your comments. No reCaptcha things (which many see as a pain). No silly questions (β€˜what is 2+8’) on the form. Your comment form does not change. Regular users will not notice a difference. But you will. No more spam comments for you!

This is the best solution to block comment spam. We’ve tested it on a site that had 20-40 spam comments a day. With this plugin enabled, the spam comment stopped. Immediately. And there have been none since installing this plugin. ** Not one. Zero.**

The Admin, Comments list page is modified to show a column with a green checkmark icon if the comment was entered by a real person and not a bot. This is an assurance that the comment was not entered via an automated CURL/WGET to the wp-comments-post.php file. A comment that is on the list that does not show the checkmark was done by a bot. But you won’t see those blocked comments with this plugin enabled. They never get into your database. You can hover over the checkmark icon to see the GUID value indicating a person entered the comment.

The plugins β€˜Settings’ screen has no settings. You don’t even need to look at the Settings screen. If you do, you’ll see information about the plugin. And there is a CURL command you can use to test the effectiveness of blocking (or not blocking) direct access to the wp-comments-post.php file.

The plugin also adds the hidden GUID field to the comment form after a delay to help block bots that are using the comment form to submit. If the hidden field is not submitted then a bot tried to bypass the comment form. And a short delay happens before the comment submit button is displayed – another bot protection.

DomainExposuresHeadersLast Checked
t*e*r*s*s*o*l*n*.org βœ… F 2026-04-28 07:35:50
c*r*s*r*s*e*l.com (WP 6.9.4) βœ… D 2026-04-27 23:51:20
k*i*.org βœ… F 2026-04-27 23:04:09
t*e*i*b*r*p*e*s.com βœ… F 2026-04-27 20:53:40
p*i*i*s*b*e*i*g.com βœ… F 2026-04-27 17:47:44
f*e*-*i*n*b*r*.de βœ… F 2026-04-27 17:12:51
d*m*x*a*i*.com (WP 6.9.4) βœ… F 2026-04-27 10:21:15
m*e*o*b*l*.com (WP 6.9.4) βœ… C 2026-04-27 10:08:49
g*a*d*i*e*s*c*e*.com (WP 6.9.4) βœ… F 2026-04-27 01:21:36
t*e*i*l*n*h*r*e*r.com (WP 6.9.4) πŸ”“ F 2026-04-26 23:38:04
a*o*9.com (WP 6.9.4) βœ… F 2026-04-26 19:26:27
m*c*a*l*a*d*n*i*e.com (WP 6.9.4) βœ… F 2026-04-26 15:43:44
x*a*m*-*i*i.gr βœ… D 2026-04-26 10:20:55
s*r*p*o*k*a*.com βœ… F 2026-04-26 07:33:41
o*e*a*i*n*m*t*o*.co.uk βœ… F 2026-04-26 05:52:20
w*e*r*c*e*.com (WP 5.8.13) ⚠️ F 2026-04-26 05:48:26
l*n*m*k*r.com (WP 6.9.4) βœ… F 2026-04-25 20:11:46
d*m*n*i*n*a.com (WP 6.6.2) βœ… F 2026-04-25 12:38:15
t*e*s*g*o*p.com (WP 6.9.4) βœ… F 2026-04-25 10:53:01
a*m*n.fr (WP 6.9) βœ… F 2026-04-25 10:39:33
t*e*o*i*i*a*g*a*d.com βœ… F 2026-04-25 07:31:40
m*r*s*p*l*a*c*.com (WP 6.9.4) βœ… F 2026-04-24 15:42:37
t*s*e*f*r*i*a*.com (WP 6.9.4) βœ… F 2026-04-24 13:44:10
c*s*l*r*y.org βœ… F 2026-04-24 08:58:05
a*h*i*k*n*a*.com βœ… F 2026-04-24 02:55:46
h*t*l*a*e*w*r*m*r*n*.com (WP 6.9.4) βœ… F 2026-04-23 21:04:23
h*t*l*a*u*a*g*a*d.com (WP 6.9.4) βœ… F 2026-04-23 15:48:35
e*l*e*t*o*m*l.com βœ… F 2026-04-23 13:57:44
m*k*v*n*s.com (WP 6.9.1) βœ… B 2026-04-23 12:55:11
c*a*i*m*g*a.com (WP 6.9.4) βœ… F 2026-04-23 01:27:50
h*n*y*u*n*v*s*t*.com βœ… F 2026-04-22 16:11:08
s*u*i*4*3*a*r.com βœ… D 2026-04-21 23:54:09
c*b*t*u*o*e*v*c*.com (WP 6.9.4) βœ… F 2026-04-21 18:52:47
s*o*y*p*i*z.com (WP 6.9.4) βœ… F 2026-04-21 01:23:38
s*o*a*u*u.com (WP 6.9.4) βœ… F 2026-04-20 16:21:06
r*d*a*a*d*l*a*.com (WP 6.9.4) βœ… F 2026-04-20 04:19:45
r*d*r*n*a*c*r*.com βœ… F 2026-04-20 02:44:54
m*l*n*e*e*d.com (WP 6.9.4) βœ… F 2026-04-20 01:27:24
b*r*b*r*-*n*i*e.com (WP 6.9.4) βœ… F 2026-04-19 19:46:45
m*d*e*e*t.se βœ… F 2026-04-19 16:05:59
f*d*i*e.com (WP 6.9) βœ… F 2026-04-19 08:18:52
g*o*p*r*.pro βœ… F 2026-04-19 04:11:54
v*c*o*y*h*c*.com βœ… F 2026-04-18 21:12:53
s*n*o*e*.com βœ… F 2026-04-18 21:01:01
m*d*e*e*t.com βœ… F 2026-04-18 18:54:16
f*t*u*u*e*i*.com (WP 6.9.4) βœ… C 2026-04-18 17:57:01
k*v*n*o*d*h*t*s.com (WP 6.9.4) βœ… F 2026-04-18 13:33:52
o*k*e*d*e*c*n*e*.org (WP 6.8.5) πŸ”“ D 2026-04-18 11:39:47
h*s*u*a*a*e*y.com (WP 6.9.4) βœ… D 2026-04-18 08:13:11
h*r*r*m*l*f*.com (WP 6.9.4) βœ… F 2026-04-18 05:15:33
s*h*r*o*j*c*s.com (WP 6.9.4) βœ… F 2026-04-17 23:59:21
j*h*n*e*s*.wpengine.com βœ… F 2026-04-17 14:05:37
h*m*t*e*p*l*b.com βœ… F 2026-04-17 13:43:04
t*e*n*w*t*-*n.com βœ… F 2026-04-17 11:58:24
d*a*e*i*a*d*i*a*e*.com.br (WP 6.9.4) βœ… F 2026-04-17 11:38:51
t*e*d*n*n*w*.com (WP 6.9) πŸ”“ D 2026-04-17 07:03:27
t*a*m*m*m*.com (WP 6.9.4) βœ… F 2026-04-16 08:25:42
h*m*o*r*.com βœ… F 2026-04-16 07:40:50
k*r*a*a*j*w*l*e*s.com (WP 6.9.4) βœ… F 2026-04-15 18:34:38
s*a*k*-*l*i*g.com βœ… F 2026-04-15 17:25:42
k*r*n*m*n*k*o*a.com (WP 6.9.4) βœ… F 2026-04-15 14:49:23
m*s*e*d*n*a*.com (WP 6.9.4) βœ… F 2026-04-15 11:04:02
o*o*e*o*c.com (WP 6.9.4) βœ… F 2026-04-15 07:33:43
r*c*i*d.com (WP 6.6.1) βœ… F 2026-04-15 07:14:06
r*c*p*c*r*o.com (WP 6.9.4) βœ… B 2026-04-15 03:35:37
t*x*c*e*t*m*s*c.com (WP 6.9.4) βœ… F 2026-04-15 02:30:26
e*a*k*l*a*a.com (WP 6.9.4) βœ… F 2026-04-14 22:29:47
t*u*i*g*u*.com (WP 6.9.4) βœ… F 2026-04-14 20:09:05
b*o*m*b*l*o*n*.com βœ… F 2026-04-14 11:59:08
b*o*m*b*l*o*.com βœ… F 2026-04-14 11:59:08
r*a*m*l*i*l*x.com (WP 6.9.4) βœ… F 2026-04-14 11:02:48
m*r*d*n*w*l*n*s*.com βœ… F 2026-04-14 09:07:14
a*e*i*a*i*d*s*r*a*s*p*.com (WP 6.7.5) βœ… F 2026-04-13 23:46:14
r*v*r*p*i*.com (WP 6.9.4) βœ… F 2026-04-13 19:47:50
r*v*e*u.com (WP 6.9.4) βœ… F 2026-04-13 19:47:50
t*p*o*y*a*r*c*p*s.com (WP 6.2.9) ⚠️ F 2026-04-13 18:05:56
k*b*r*t*g*l.com (WP 6.9.4) βœ… F 2026-04-13 16:33:53
t*n*a*c.org (WP 6.9.4) βœ… F 2026-04-13 08:33:39
t*n*t*u*n*x*a*.com (WP 6.9.4) βœ… F 2026-04-13 08:00:52
m*r*-*-*a*s*l.com (WP 6.8.5) πŸ“‘ D 2026-04-12 21:00:11
h*l*b*o*.com βœ… D 2026-04-12 19:34:49
r*j*h*g*b*r.com (WP 6.5.8) βœ… F 2026-04-12 15:49:12
j*l*a*a*d*r*y*.com (WP 6.7.1) βœ… F 2026-04-12 09:02:51
t*d*y*e*t*n*.com βœ… F 2026-04-12 08:24:25
a*p*o*.com (WP 6.9.4) βœ… D 2026-04-12 03:30:59
j*d*t*f*h*m*n*.com (WP 6.9.4) βœ… F 2026-04-12 02:19:36
m*n*-*-*a*o*a*s*.com βœ… A 2026-04-12 00:07:54
g*m*a*i*y.com βœ… F 2026-04-11 15:44:40
a*l*v*p*l*a*c*s.com (WP 6.9.4) βœ… F 2026-04-11 10:52:00
p*o*r*m*.uebertangel.org (WP 6.9.4) βœ… D 2026-04-11 01:42:24
s*a*t*r*n*a*.com (WP 6.9.4) βœ… F 2026-04-11 01:12:33
e*w*o*d*m*s.com βœ… F 2026-04-10 19:12:56
k*r*t*n*h*o*a*k*.org βœ… F 2026-04-10 01:38:43
t*r*e*i*t*g*h*r*e*.com (WP 6.9.4) βœ… B 2026-04-10 01:13:52
j*h*n*e*s.com βœ… F 2026-04-09 23:17:26
e*f*r*i*u*r.cat βœ… F 2026-04-09 09:18:43
c*a*i*g*a*t*.com (WP 6.9.4) βœ… F 2026-04-08 21:16:06
t*n*a*c.com (WP 6.9.4) βœ… F 2026-04-08 16:28:26
g*h*p*y*i*e.com (WP 6.9.4) βœ… F 2026-04-08 13:42:05
c*u*d*v*l*e*r*h*t*c*s.com (WP 6.8.5) βœ… F 2026-04-08 05:10:35

Top 50 Plugins

Plugin Count
elementor 2,610,282
contact-form-7 2,337,644
elementor-pro 1,466,093
woocommerce 1,223,104
revslider 876,684
js_composer 572,075
jetpack 492,222
wp-rocket 416,628
essential-addons-for-elementor-lite 395,134
header-footer-elementor 338,692
gutenberg-core 324,845
elementskit-lite 318,307
instagram-feed 298,589
gravityforms 297,893
google-analytics-for-wordpress 296,326
google-site-kit 287,278
complianz-gdpr 285,637
cookie-law-info 281,352
sitepress-multilingual-cms 248,177
wpforms-lite 238,039
bluehost-wordpress-plugin 233,662
astra-sites 230,472
litespeed-cache 208,332
gtranslate 174,637
coblocks 166,711
cookie-notice 164,421
gutenberg 161,748
the-events-calendar 144,897
popup-maker 136,627
premium-addons-for-elementor 127,956
astra-addon 127,895
bb-plugin 127,337
mailchimp-for-wp 124,297
LayerSlider 123,244
wp-smushit 121,831
tablepress 117,305
creame-whatsapp-me 113,186
custom-fonts 111,825
pro-elements 109,681
duracelltomi-google-tag-manager 108,630
click-to-chat-for-whatsapp 107,419
woocommerce-gateway-stripe 107,358
cleantalk-spam-protect 105,299
akismet 103,125
smart-slider-3 102,017
honeypot 100,700
megamenu 100,333
pixelyoursite 99,994
fusion-builder 99,480
formidable 95,673

Top 50 Themes

Theme Count
hello-elementor 839,023
astra 689,331
Divi 688,815
pub 216,748
generatepress 157,433
flatsome 156,461
Avada 150,237
h4 132,621
oceanwp 115,095
kadence 102,323
enfold 87,699
salient 84,687
bb-theme 81,307
twentytwentyfour 78,539
blocksy 76,160
twentytwentyfive 74,865
cocoon-master 72,462
betheme 69,466
twentyseventeen 67,865
woodmart 57,177
dt-the7 57,157
neve 50,179
twentytwentyone 43,364
bridge 42,676
Avada-Child-Theme 39,119
swell 38,644
twentytwenty 37,532
gox 36,812
lightning 36,811
twentytwentythree 35,835
bricks 30,482
Impreza 30,440
Newspaper 28,223
twentytwentytwo 27,764
epik-redesign 23,800
extendable 22,930
pro 22,929
storefront 22,793
uncode 22,342
twentysixteen 21,929
yith-wonder 21,662
sydney 20,796
themify-ultra 20,173
Total 18,592
twentyfifteen 18,182
porto 17,103
hestia 16,520
thrive-theme 15,743
yootheme 15,443
twentynineteen 15,189