Comment spam and trackback floods aren't just a moderation headache — they consume real server resources and can slow your site down as effectively as a traffic spike.
Comment spam is automated software submitting comments to your WordPress site with links back to other websites — usually gambling, pharmaceutical, or adult sites trying to build search engine links. The bots don't read your content; they just look for the WordPress comment form and submit to it repeatedly.
Trackback and pingback spam is a related problem. WordPress's trackback and pingback system was designed to notify other WordPress sites when you link to them. By 2012 it had been comprehensively abused — bots send fake trackback requests to thousands of sites simultaneously, generating server load with no legitimate content behind it.
Every comment submission — even one that WordPress catches in moderation — triggers a full PHP process: WordPress loads, the comment is processed, Akismet (if enabled) makes an API call, and the result is written to the database. A moderate spam flood, say a few hundred submissions per hour, can keep PHP workers constantly busy.
Trackback requests are particularly wasteful because WordPress processes them in full before determining they're spam. At volume — and coordinated trackback floods can generate thousands of requests per minute — they can bring a site on shared hosting to its knees.
Akismet is the WordPress spam filtering service that comes bundled with every WordPress install. It checks comment and trackback submissions against a continuously updated database of known spam patterns. For most sites, it catches the overwhelming majority of spam before it reaches your moderation queue.
Akismet is free for personal sites. For business sites it requires a paid subscription — a reasonable cost given what it prevents. It needs an API key to function; if you installed WordPress and skipped the Akismet setup, go back and do it.
The limitation is that Akismet still processes the submission in PHP before making its determination. It reduces moderation work but doesn't reduce server load from the initial requests.
For most small business WordPress sites, trackbacks and pingbacks provide no value. They were designed for a blogging ecosystem that communicated via these mechanisms — a relatively small niche today. Disabling them entirely removes a substantial spam attack surface:
CAPTCHA challenges (asking users to identify text or images) add friction that automated bots can't pass. The downside is that they add friction for real users too. By 2012, most CAPTCHAs were solvable by commercial CAPTCHA-solving services anyway.
Honeypot fields are a more elegant solution: add a form field that's hidden from human users via CSS, but visible to bots that read raw HTML. Bots fill in all fields; if the honeypot field has content, the submission is rejected. Several plugins implement this approach and it's effective against less sophisticated bots.
Requiring users to register before commenting eliminates spam bots entirely — they won't create accounts. The tradeoff is a significant reduction in genuine comment engagement, since most readers won't bother registering just to leave a comment. For sites where comments aren't central to the value, this is often the right call.
Most comment spam problems come down to the same issue as most WordPress performance problems: requests that shouldn't be consuming server resources are consuming them. Addressing it at the source rather than processing it through PHP is always the more efficient approach.
Australian WordPress hosting from $5/month
Your own containerised environment on Australian NVMe servers. Simple, fast, and genuinely cheap.