Top 10 Ways to Stop Spam on WordPress Comments and Forms

by Francis Rozange | Oct 1, 2026 | WordPress

In the autumn of 2020, dozens of WooCommerce stores received failed orders in the name of “bbbbb bbbbb”, all with the same British address. This was not ordinary spam: on vulnerable stores, each fake order opened a customer account, which the bot then used to look for vulnerabilities in the site’s other plugins.

Spam on WordPress is no longer about comments selling miracle pills. It is bots filling in contact forms, creating accounts, testing credit cards at checkout or signing strangers up to your newsletters. And every countermeasure has a cost that is not measured only in dollars.

A cloud filter is accurate, but it sends your visitors’ content to a third party. A visual challenge stops bots, but it gets in the way of people with disabilities. A local rule sends nothing, but lets more through. This comparison judges ten solutions on those three criteria: accuracy, privacy and accessibility.

How we ranked them

We mixed services and techniques, because good protection stacks several layers: local rules, an invisible trap field, an online content filter, a challenge for sensitive forms, and WordPress’s own settings.

For each solution, we looked at what it protects (comments, forms, registrations, orders), what leaves your site and to whom, what a visitor who cannot see or does not use a mouse experiences, and its price in October 2026. We do not repeat the accuracy rates vendors advertise, since they publish no method.

1. Akismet: the default filter, paid for commercial sites

What it does

Akismet, from Automattic, ships with every WordPress install and has more than five million active installs. It sends each comment, and through its integrations each form submission, to Akismet’s online service, which answers spam or not. Since 2022, a script also observes typing rhythm and mouse movement, without recording the typed content.

Strengths

It protects WooCommerce product reviews with no setup, and integrates with Jetpack, Contact Form 7, Gravity Forms, GiveWP and Elementor Pro forms. Blatant spam is discarded outright, and each comment keeps a history of its status changes.

Limits

Akismet is free only for personal, non-commercial sites. Ads, affiliate links, donations, an online store or simply promoting a business require a subscription, on pain of suspension without notice. It does not protect against fraudulent orders, as its own documentation points out, nor does it cover WordPress’s native registrations.

Its accuracy also depends on the integration. In July 2026, Akismet described how GiveWP’s multi-step donation forms generated an abnormal rate of false positives: the plugin queried the service at every step, which looked like repeated submissions. GiveWP fixed the problem in version 4.16.0.

Price and audience

The Pro plan, for a commercial site, costs $119.40 per year for 500 checks a month, at the time of writing. Akismet suits blogs and business sites that accept sending form content to a US provider, under a data processing agreement.

2. Antispam Bee: everything local, for comments

What it does

Antispam Bee, developed by a German-speaking collective and installed on more than 700,000 sites, filters comments on your own server with rules: trust for previously approved commenters, a typing-time check, language or country filters, regular expressions, a local spam database and a trap field.

Strengths

It is completely free, with no ads or paid version, and its main rules contact no external service. As with any comment, WordPress keeps the full IP address in its database, and Antispam Bee uses it for its local spam database without sending it anywhere. For a European blog that does not want to sign any processing agreement for its comments, it is the simplest solution.

What still leaves the site

Three optional checks call out: the country filter sends the anonymized IP address to a geolocation service, the language filter sends the comment text to the collective’s API, and trust based on avatars queries Gravatar. It is up to you to turn them on knowingly.

Limits and audience

Version 2 protects neither forms nor registrations, and it does not work with external comment systems such as Disqus. A rewritten version 3 has been in public beta since summer 2026, not for production use. Antispam Bee suits blogs that mainly need to protect their comments.

3. CleanTalk: an online filter for every form

What it does

CleanTalk, installed on more than 200,000 sites, is an online service with no CAPTCHA. The plugin is free, but it requires a paid key. It protects comments, most form plugins on the market, registrations, fake WooCommerce orders and newsletter sign-ups, and checks for disposable email addresses along the way.

Strengths

A single layer covers almost everything, invisibly for the visitor, and the price stays very low. Logs for the past week can be viewed in the service’s dashboard.

Limits

No CAPTCHA does not mean no transfer: submissions go to CleanTalk’s servers, except for fields you exclude. Above all, the plugin itself was once a way in. In late 2024, two serious flaws let an anonymous visitor install and activate any plugin on affected sites. They were fixed in versions 6.44 and 6.45, without the changelog flagging a security fix.

An anti-spam plugin opens endpoints that the service calls back remotely: update it like a security tool. Our comparison of WordPress security plugins helps you round out this protection.

Price and audience

Twelve dollars a year for one site, with no limit on calls. For a site that combines several form plugins and WooCommerce registrations, and accepts an online provider, it is the simplest layer.

A nearly invisible glass trap door on a dark floor, with a small mechanical insect caught inside

4. Cloudflare Turnstile: the free, invisible challenge

What it does

Turnstile replaces the CAPTCHA with invisible JavaScript tests that run in the browser. It works on any site, without routing traffic through Cloudflare. On WordPress, the most used plugin is Simple CAPTCHA with Cloudflare Turnstile, published by an independent developer rather than by Cloudflare, and installed on more than 200,000 sites.

Strengths

The service is free, with unlimited challenges. The plugin covers login, registration, comments, WooCommerce checkout, classic or block-based, and a long list of forms. According to Cloudflare, Turnstile accesses neither user input nor form entries, and it meets level AA of the WCAG 2.2 accessibility guidelines.

Limits

The token must be verified server-side: Cloudflare points out that the widget alone protects nothing. Cloudflare processes the IP address, the TLS fingerprint and the browser’s user agent, and declares itself a controller for the signals used to improve its product. Finally, it is a dependency: during Cloudflare’s outage on November 18, 2025, Turnstile stopped loading. The plugin offers a failsafe mode that either lets submissions through or falls back to reCAPTCHA.

Server-side verification

Each Turnstile token is valid for only five minutes and can be used only once: a second use is rejected by Cloudflare’s verification API. That check, done by your server, is what protects the form. A plugin or theme that displays the widget without verifying the token gives the illusion of protection without providing any. Test it by submitting the form with the script blocked: the submission should fail.

Price and audience

Free up to 20 widgets. Turnstile suits most sites that want an almost invisible challenge on login, registration and checkout.

5. hCaptcha: the CAPTCHA under a processing agreement

What it does

hCaptcha, from Intuition Machines, offers visual challenges and, on paid plans, a passive mode. Its WordPress plugin, with more than 80,000 installs, covers more than sixty integrations, adds its own trap field and a minimum submission time, and includes a migration wizard from reCAPTCHA or Turnstile.

Strengths

hCaptcha acts as a processor for the integrator, with a data processing agreement built into its terms, and stores its analytics data in the European Union by default. Stripe cites it among the CAPTCHA protections of its recommended integrations.

Limits

Some visitors see visual challenges. To avoid them, a person with a disability has to sign up on hCaptcha’s portal and regularly renew an accessibility cookie. A text challenge is available in the widget menu when the site enables it. Data collection includes mouse movements, scrolling and keypress events.

Price and audience

The basic plan is free up to 10,000 requests a month across all of an organization’s accounts; the Pro plan, with passive mode and 100,000 evaluations a month included, costs $99 per month billed yearly. To replace reCAPTCHA with a provider acting as a processor, it is the most direct option.

6. Google reCAPTCHA v3: accurate, but data-hungry

What it does

reCAPTCHA v3 gives each visit a score from 0 to 1, with no visible challenge. Google publishes no official plugin, but many plugins and most form builders integrate it. Since April 2026, reCAPTCHA has been part of a suite called Google Cloud Fraud Defense.

What changed in 2026

Since April 2, 2026, Google has acted as a processor: the site is the sole controller of the data, and Google commits not to use it for personalized advertising. Old “classic” keys can no longer be created, and the free tier is limited to 10,000 assessments a month across all the sites of an organization.

The privacy trade-off

The script and data still go through Google’s infrastructure, with a cookie and transfers outside Europe. And Google itself recommends loading reCAPTCHA in the background on every page, not just on forms, to give it more context. For a European site, the question of consent to trackers therefore arises in full.

Accessibility and audience

Version 2’s visual challenges come with audio challenges that work with the main screen readers. On the security side, researchers at ETH Zurich showed in 2024 that AI models passed all the reCAPTCHA v2 image captchas they tested, needing about as many challenges as a human. reCAPTCHA keeps its place on high-traffic sites already on Google Cloud that need risk scores.

7. Honeypot fields: the invisible, local layer

What they do

A honeypot is a hidden field that humans never fill in. A bot that fills it in is rejected. The W3C lists it among the alternatives to CAPTCHA worth considering, because it asks nothing of the visitor.

Strengths

WP Armour, with more than 400,000 installs and a perfect rating, injects a field through JavaScript whose name changes from one site to the next. Its free version covers comments, registration and most form builders, with no external calls at all. Many solutions in this comparison, and most form plugins, already include one.

Hiding the field properly

How the field is hidden matters. Antispam Bee’s FAQ advises against display: none, which some bots know how to spot and skip. The W3C cites Hilton’s loyalty site, where the field carries a label saying it is for robots only: a person who reaches it with a screen reader understands that it should be left empty. A maintained plugin handles these details for you, which is one more reason not to hand-roll your own.

Limits and audience

A honeypot stops neither humans paid to spam nor bots that actually render the page. It must also be hidden from assistive technologies, or clearly labeled as in the example the W3C cites, or it will trap a screen reader user. Despite those limits, it is the first layer to add to any site, since it costs nothing in privacy. WP Armour’s paid extension, which covers WooCommerce, starts at $19.99 per year.

8. Discussion settings: close what you do not use

What to know

By default, WordPress opens comments and pingbacks on every new post. If your site gets no useful comments, the best protection is to close them. Under Settings, then Discussion, uncheck link notifications and permission to comment on new posts, or automatically close comments on older posts.

The settings that filter

WordPress already holds for moderation any comment containing two or more links, and blocks a second comment from the same address within fifteen seconds. Words in the Disallowed Comment Keys list send the comment to the Trash, not to immediate deletion as the documentation suggests.

Turning comments off entirely

The Disable Comments plugin, with more than a million installs, removes the comments interface and feeds, and closes access through XML-RPC and the REST API. Two precautions: on a WooCommerce product, reviews are comments, and since WordPress 6.9, block-editor Notes are too. The plugin can keep the latter working.

On the command line, wp comment list --status=spam --fields=ID,comment_date,comment_author shows what your filters have held back, and wp option update default_comment_status closed closes comments on future posts. Glancing at the spam folder after each form plugin update also helps you catch false positives, like GiveWP’s.

9. Registration spam

Why it matters

Fake accounts are not just clutter. An account, even a subscriber one, is a foot in the door to exploit a flaw reserved for logged-in users. And a registration form that sends an email to any address can be used to flood third-party inboxes: in 2024, Microsoft described a criminal group that signed its victims up en masse to mailing lists, before contacting them while posing as IT support.

How to protect yourself

If you do not need public registration, leave “Anyone can register” unchecked in the general settings, and keep the default role at subscriber. If you do need it, put a challenge or a honeypot on the registration form: Turnstile, hCaptcha, WP Armour and CleanTalk all cover it. Akismet, for its part, does not check native registrations. These settings complement the WordPress security hardening measures.

The real case: “bbbbb bbbbb”, the bot that opened WooCommerce accounts

One of the best-documented stories of spam targeting WordPress stores dates from 2020. It ties together two problems in this comparison, registrations and orders, and it is still not entirely closed in 2026.

An order that was not an order

In late October 2020, merchants reported failed orders with fake payment details, all in the name of “bbbbb bbbbb”, with the same UK address and the same email domain. According to WP Tavern, the WooCommerce team discovered the problem after several dozen reports, and the first recorded case came nine days before the fix.

The parameter that ignored the settings

WooCommerce found the cause: a parameter sent to checkout let the bot create a customer account even when the merchant had disabled account creation. The Checkout block in the WooCommerce Blocks 3.7.0 feature plugin had the same flaw. The bot placed an order, got an account, then used it to probe for vulnerabilities in the site’s other plugins.

On the WooCommerce support forum, quoted by WP Tavern, a user reported that at the moment of one of these orders, their firewall blocked two attempts against a recently patched wishlist plugin, which they did not even have installed. An engineer summed up what his logs showed: either the script fails and leaves nuisance orders, or it succeeds and points the site to a scam address.

A fix that did not stop the orders

On November 4, 2020, a developer published a small plugin blocking the bot’s known names and domains. On November 5, WooCommerce 4.6.2 fixed the flaw: account creation now respected the setting. But the team warned that the fix would not stop the bot from creating orders, and recommended deleting the accounts already created.

In January 2021, a GitHub thread gathered merchants still affected on up-to-date sites. WooCommerce published a second advisory and pointed to anti-spam and anti-fraud extensions. In February, a contributor closed the thread: bot protection is outside the scope of core, and signature blocking is a cat-and-mouse game.

What has not changed in 2026

Nearly six years later, WooCommerce still ships neither a CAPTCHA nor a honeypot. A request to verify new accounts’ email addresses, opened in 2024, is still pending. The email confirmation added in WooCommerce 11.0 in 2026 is there to link orders placed without an account, not to block unverified accounts. And a request for a CAPTCHA API in core was filed in September 2026.

The lessons still hold. A setting is only as good as the code that enforces it, hence the importance of updates. A spam order can be reconnaissance, not just noise. Signature blocking only holds as long as the bot keeps the same name and domain, while behavior-based protections do not depend on them. And choosing that protection is still up to the merchant.

10. WooCommerce: fake accounts and card testing

Settings to check

In WooCommerce, then Settings, then Accounts & Privacy, keep guest checkout enabled, only offer account creation after checkout if you need it, and turn on deletion of inactive accounts. For reviews, you can restrict them to verified owners.

Card testing

Bots testing stolen cards also go straight for the store’s API, as the late-2024 wave showed. WooCommerce offers rate limiting, off by default, to turn on in the advanced settings. Its documentation also recommends a CAPTCHA at checkout, an anti-fraud extension and avoiding pay-what-you-want products with no minimum. Our comparison of WooCommerce payment gateways tells the story of the late-2024 attack wave against the store API.

The gateway’s role

Stripe advises validating the CAPTCHA server-side on every request that validates a card, and recommends limiting customer creation per IP address. A well-configured gateway, active rate limiting and a challenge at checkout make the strongest combination.

How to choose

  • European blog with no online provider: Antispam Bee and a honeypot, with tightened discussion settings.
  • Business site with forms: a honeypot, then Akismet or CleanTalk depending on your form plugins.
  • WooCommerce store: rate limiting, Turnstile or hCaptcha at checkout and registration, and a gateway with anti-fraud tools.
  • Membership or course site: a challenge on registration and regular cleanup of inactive accounts.
  • Site with accessibility obligations: favor solutions with no visual challenge, as our guide to WordPress accessibility fixes explains.

Summary table

Solution Type What goes to a third party Price (Oct. 2026)
Akismet Online filter Content, IP, browser Free (personal), $119.40 per year (commercial)
Antispam Bee Local rules Nothing by default Free
CleanTalk Online filter Submissions, except excluded fields $12 per year
Turnstile Invisible challenge IP, TLS fingerprint, user agent Free
hCaptcha Challenge, paid passive mode IP, browser, gestures Free up to 10,000 requests a month, Pro $99 per month
reCAPTCHA v3 Invisible score Browsing signals, cookie Free up to 10,000 assessments a month
Honeypot Local technique Nothing Free
Discussion settings Configuration Nothing Free
Registrations Configuration and challenge Depends on the challenge Free
WooCommerce Settings, rate limiting, challenge Depends on gateway and challenge Free to paid

Frequently asked questions

Is Akismet free for a business site?

No. The free key is reserved for personal, non-commercial sites. Ads, affiliate links, donations, online sales or promoting a business require a paid plan. Qualified nonprofits can, however, get a free license, capped at 60,000 calls a month.

Do I need consent for reCAPTCHA or Turnstile?

The question falls under the ePrivacy Directive, which covers any access to the visitor’s device, not just cookies. To our knowledge, no authority has ruled specifically on these tools. reCAPTCHA, loaded on every page as Google recommends, is the most exposed. Our guide to GDPR and consent on WordPress details the analysis.

Is a honeypot enough?

On a small blog, often. On a targeted site, no: bots that render the page get around it. Combine it with a content filter or a challenge on sensitive forms.

How do I protect WooCommerce checkout?

Turn on rate limiting for the store API, add a challenge verified server-side, disable account creation at checkout if you do not need it, and choose a gateway with anti-fraud tools.

Does disabling comments break editor Notes?

Block-editor Notes, introduced with WordPress 6.9, are stored as comments. A plugin that disables all comments can block them: check that it keeps them working: Disable Comments can, provided you allow that comment type in its settings.

Conclusion

No solution wins on every count. Online filters draw on a worldwide spam database, but they pass on your visitors’ content. Challenges stop bots, at the price of a third-party script and sometimes a barrier for people with disabilities. Local rules and honeypots pass on nothing, but let more through.

The right answer is layering: close what you do not use, add a honeypot everywhere, then a filter or a challenge where the stakes justify it. And the story of “bbbbb bbbbb” is a reminder: spam can be reconnaissance, and protection gets updated like the rest of the site.

Sources


LaFactory designs, builds and maintains WordPress and WooCommerce sites, form protection included, and develops its own plugins. Talk to us about your WordPress project.

Francis Rozange

Former section editor at Libération, he runs LaFactory, an international web agency since 1996.

Cart