All posts
September 2012·5 min read

Why WordPress comment spam is more than just annoying

Comment spam and trackback floods aren't just a moderation headache — they consume real server resources and can slow your site down as effectively as a traffic spike.

What comment spam actually is

Comment spam is automated software submitting comments to your WordPress site with links back to other websites — usually gambling, pharmaceutical, or adult sites trying to build search engine links. The bots don't read your content; they just look for the WordPress comment form and submit to it repeatedly.

Trackback and pingback spam is a related problem. WordPress's trackback and pingback system was designed to notify other WordPress sites when you link to them. By 2012 it had been comprehensively abused — bots send fake trackback requests to thousands of sites simultaneously, generating server load with no legitimate content behind it.

The server load problem

Every comment submission — even one that WordPress catches in moderation — triggers a full PHP process: WordPress loads, the comment is processed, Akismet (if enabled) makes an API call, and the result is written to the database. A moderate spam flood, say a few hundred submissions per hour, can keep PHP workers constantly busy.

Trackback requests are particularly wasteful because WordPress processes them in full before determining they're spam. At volume — and coordinated trackback floods can generate thousands of requests per minute — they can bring a site on shared hosting to its knees.

Akismet: the baseline defence

Akismet is the WordPress spam filtering service that comes bundled with every WordPress install. It checks comment and trackback submissions against a continuously updated database of known spam patterns. For most sites, it catches the overwhelming majority of spam before it reaches your moderation queue.

Akismet is free for personal sites. For business sites it requires a paid subscription — a reasonable cost given what it prevents. It needs an API key to function; if you installed WordPress and skipped the Akismet setup, go back and do it.

The limitation is that Akismet still processes the submission in PHP before making its determination. It reduces moderation work but doesn't reduce server load from the initial requests.

Disabling trackbacks and pingbacks

For most small business WordPress sites, trackbacks and pingbacks provide no value. They were designed for a blogging ecosystem that communicated via these mechanisms — a relatively small niche today. Disabling them entirely removes a substantial spam attack surface:

  • Go to Settings → Discussion in your WordPress admin
  • Uncheck "Allow link notifications from other blogs (pingbacks and trackbacks) on new articles"
  • To disable on existing posts, use the Bulk Edit function in Posts to update all at once

Adding a CAPTCHA or honeypot

CAPTCHA challenges (asking users to identify text or images) add friction that automated bots can't pass. The downside is that they add friction for real users too. By 2012, most CAPTCHAs were solvable by commercial CAPTCHA-solving services anyway.

Honeypot fields are a more elegant solution: add a form field that's hidden from human users via CSS, but visible to bots that read raw HTML. Bots fill in all fields; if the honeypot field has content, the submission is rejected. Several plugins implement this approach and it's effective against less sophisticated bots.

Requiring registration to comment

Requiring users to register before commenting eliminates spam bots entirely — they won't create accounts. The tradeoff is a significant reduction in genuine comment engagement, since most readers won't bother registering just to leave a comment. For sites where comments aren't central to the value, this is often the right call.


Most comment spam problems come down to the same issue as most WordPress performance problems: requests that shouldn't be consuming server resources are consuming them. Addressing it at the source rather than processing it through PHP is always the more efficient approach.

Australian WordPress hosting from $5/month

Your own containerised environment on Australian NVMe servers. Simple, fast, and genuinely cheap.