The Elementor Website Builder has it all: drag and drop page builder, pixel perfect design, mobile responsive editing,…
About Cookies for Comments
This plugin adds a stylesheet or image to your blog's html source code, which drops a cookie when loaded by a browser. If a user leaves a comment without having the cookie, the comment is marked as spam. The plugin can also check the speed at which a user enters a comment to determine if it is likely from a spam bot. For added security, you can block spam attempts at the server level by adding certain lines to your .htaccess file.Frequently asked questions
What does this plugin do?
This plugin adds a stylesheet or image to your blog's html source code. When a browser loads that stylesheet or image a cookie is dropped. If that user then leaves a comment the cookie is checked. If it doesn't exist the comment is marked as spam.
Can the plugin check how long it took a user to enter a comment?
Yes, the plugin can check how long it took a user to enter a comment. If it's too fast, it's probably a spam bot.
How can I block spam attempts before they reach WordPress?
For the adventurous, you can add the provided lines to your .htaccess file. Replace the Xs with the cookie that was set in your browser after viewing your blog. Make sure the lines go above the standard WordPress rules.
How can I block spam signups in WordPress MU?
If you use WordPress MU, replace wp-comments-post.php above with wp-signup.php to block spam signups.
Changelog
0.5.5
- Sanitize the cookie key before setting it. Props Matt Cutts and @planetzuda
0.5.4
- Added a rejection message for when people trip over the cookie protection.
- Plugin requires WordPress 3.1+ now.
0.5.2
- Use an image to deliver cookie as well as stylesheet.
- Don’t load WordPress to set the cookie. Makes pageload much faster!
- Added “time to post comment” to comment notification emails.
- Support for SSL sites.
- If user is logged in don’t check for cookie.
- Speed spammer checks to stop smarter bots and human spammers.
0.5.1
- Generate cfc_key all the time if it’s missing, not just on serving the css html
- Added MU signup form mod_rewrite rules to docs and admin page
- Added Settings page link to plugins page.
- Add explanation text to css file.
- Add docs on how to use CFC to protect the MU signup form
- Show htaccess rules on admin page.
- Don’t let wp-super-cache cache this page.
- Store cfc_key in sitemeta for WordPress MU sites
- Added mod_rewrite rules to block spam comments before they get to WordPress