On Comment Spam

Howdy, folks. I’m sure you’ve noticed that there has been a bit more comment spam over the last few months. It annoys me as much as you, possibly more, because there have been cases where spam comments have embedded viruses, implemented code that allows hijacking of the blog code, etc. What to do about it, though?

Akismet is one of the primary apps blogs use to catch spam. It’s been running around 97% effective since a big update earlier in the year, which means either a) it’s not as effective as it was, or b) comment spammers are finding ways to circumvent Akismet. So, I have to manually remove them. The other big app is Bad Behavior. Between the two, they are catching well over 7000 spam comments/trackbacks/pingbacks a week. Usually more.

I do have a few other minor apps that do other things, but, sadly, none can catch everything. There are a few measures I can take, but would prefer not to. I can ramp Bad Behavior up to strict, but that might catch legit comments.

I can require registration using a few different methods. Internal WordPress. A different plugin I use that already allows users to comment using their existing faceboook, twitter, etc, accounts, but this would force registration, rather than anonymous. If spam comments increase (I’m deleting 10 or less a day), I may implement Disqus. Which might allow other features, such as threaded comments (the theme I use will not allow it without major rewrite, and I like the way it works otherwise)

I could add another comment spam plugin, though, really, Akismet is the best. This is probably what I’ll look at first.

I could use some sort of captch. People tend to hate them, but I have a deactivated one that is easy to use. Rather not go back to it.

What are your thoughts?

Save $10 on purchases of $49.99 & up on our Fruit Bouquets at 1800flowers.com. Promo Code: FRUIT49
If you liked my post, feel free to subscribe to my rss feeds.

Both comments and trackbacks are currently closed

9 Responses to “On Comment Spam”

  1. John says:

    At least the spam is complimentary
    It can offset what Jeffery and I post

  2. Better_Be_Gumballs says:

    ROFL – John posts a rather truthful comment, followed by a spambot.

    Teach, this is your site and we’ll deal with whatever you choose.

    Captcha will at least allow non-wordpress or non-discus people the ability to comment.

    The wordpress or discus might allow us to maintain our credentials without having to enter them in with every page refresh.

    If you’re taking a poll,
    1) increase your spam plugins and see how that goes for a week or two
    2) Captcha
    3) WordPress or other login type method.

    Did not realize that you were getting flooded with that much spam. While you are only currently removing about 10 a day, once the spammers realize that your site allows some through, they will increase their focus. Or, that 10 a day might increase anyway.

    While you put alot of appreciated effort in to your site already, I hate to think you have to double your time\energy to just fight spam.

  3. Dana says:

    I’m not a big fan of the separate commenting window that you use.

    I use Akismet on my site, and it works very well for me. Alas! I have to pay a company called We Watch Your Website to protect mine from hackers, but it protects from not just harmful code in the comments, but from other attack methods.

  4. I’m going to check out some other plugins tomorrow. Interesting thing about Disqus is it still lets thru spam.

    Dana, if you click on the post header or the link at the bottom it will give you regular comments, versus the pop-up box.

  5. The Neon Madman says:

    Teach:

    Yes, I’ve been seeing the spam leak in, I usually just ignore it in the comments (it’s ridiculously easy to spot). Same thing for the trolls.

    It’s your party, so you get to set the rules. A captcha isn’t too bad to deal with. I refuse to use facebook/twitter, so for me a social media filter is out, but I don’t comment all that much to start with.

    BTW, I like the blog – it’s been a daily read for a long time. Keep on truckin’, Cap’n.

  6. Kevin says:

    Opinions:

    I like Disquss ok. Threaded comments are the major plus.

    Captcha is not a problem to me.

    I wouldn’t use Facebook, Twitter, or G+ to login.

  7. Thanks for the input, Neon, and the kind words.

    I’m seriously considering Disqus, mostly because of the threaded comments. I love them, but the script in the code of the blog will no longer allow it to work after a WordPress update. I have a plugin to allow it, but they won’t actually nest, nor will the internal WP feature work. Even shows “reply to” in the individual posts for comments, just won’t nest.

  8. Better_Be_Gumballs says:

    Hey Neon, do you also peruse the comments section?

    Teach, Does the “bad behavior” plugin allow you to see what is blocked? So, if upping it to “restrictive” blocks a legitimate email, could you retrieve it?
    If someone thought that they had been blocked, could they send ya a tweet?

    Or,
    There’s always the “going full moderation” mode as well.

    • For the most part, BB disappears most stuff. I can go in to Akismet and find legit comments treated as spam. Most of those get put in moderation que. Kinda like how anything with 5 or more links.

      People can email, definitely.

      I just installed another plugin, we’ll see how that works.

Pirate's Cove