What checks a comment goes through in jekcms, how the spam score is calculated, which comments are published, which go to moderation and who gets notified. The flow from submission to publication, step by step.
A comment form looks like a text box and a button. The real work starts after the button is pressed. An open comment form soon becomes a target for bots, and without protection the moderation queue fills up with gambling, pharmacy and crypto links. This post follows a comment in jekcms from the moment it is submitted to the moment it is published.
Checks at Submission
Before a comment is written to the database it goes through these checks in order:
- Rate limit: At most 3 comments per minute are accepted from one IP address. Above that there are hourly and daily caps per IP and an hourly cap for the whole site.
- Honeypot and timing: The form has a hidden field people never see; if a bot fills it, the comment is not saved. Comments sent too soon after the form was opened are also treated as suspicious.
- CSRF token: Confirms the form was submitted from the site's own page.
- reCAPTCHA: If enabled for comments in the settings, Google's verification service is asked.
- Field checks: The name must be 2 to 100 characters, the email must be valid and the comment must be 3 to 5000 characters.
- Post status: If comments are closed site-wide or on that post, or sign-in is required, the submission is refused.
Bots get no hints. A request caught by the honeypot or over the cap still sees "Thank you for your comment", but nothing is written to the database.
The Spam Score
A comment that passes these checks goes to the spam filter. The filter does not make a single yes or no call; it adds points for each suspicious sign and records the reason. The main signs are:
- A blacklisted IP address or email (enough points for outright rejection)
- More links than allowed (the default limit is 2)
- Words used in pharmacy, gambling, adult and crypto scam spam
- A link inside the name, or a name or email username made of random characters
- All caps, repeated characters or words, script or iframe tags in the comment
- Shortened links (bit.ly, tinyurl and similar)
- An empty user agent or one belonging to a known bot client
- Three or more spam attempts from the same IP in the last 24 hours
A second layer runs on top of these. It checks whether the comment's alphabet matches the site language, whether the same text was sent under different names, whether it uses stock spam lines such as "impressed with your writing skills", whether it mixes look-alike letters from other alphabets, and whether it uses a disposable email address. There is also a Bayes model that learns from the administrator's decisions: when you mark a comment as spam or approve it in the panel, the model updates. StopForumSpam and Akismet reputation checks can be turned on as well.
Deciding by Score
The total score decides what happens to the comment:
if ($score >= 100) {
$action = 'reject'; // silently rejected
} elseif ($score >= $autoSpamThreshold * 10) {
$action = 'spam'; // set aside as spam
} elseif ($score >= 20) {
$action = 'pending'; // goes to moderation
}
// otherwise: the site's default comment status
The automatic spam threshold and the link limit can be changed on the Spam Protection screen in the panel. Rejected or spam comments are not written to the comments table, only to the spam log, so the table does not swell even when a site is under attack. For comments that are saved with a score above zero, the score and the reasons are stored with the comment, so the moderation screen shows why a comment ended up in the queue.
Moderation
The Comments screen in the panel has pending, approved, spam and trash tabs. You can approve, mark as spam or delete comments one at a time or in bulk. Because spam and approve decisions train the Bayes model, the filter gets better over time at recognising the kind of spam your site attracts. The Spam Protection screen also has a button to rescan pending comments with the current rules.
Whether comments are published straight away or held for moderation by default is set under Settings > Discussion. On the same screen you can turn comments off entirely or limit commenting to signed-in users.
Notifications
There are two kinds of notification, and both are off by default:
- New comment notice to the administrator: The commenter's name, email, text and a link to the moderation screen go to the admin email address.
- Reply notice: When an approved comment gets a reply, the person replied to and the authors of the comments above it get an email. Every email has an unsubscribe link, and anyone who uses it is not emailed again.
When the administrator replies to a comment from the panel, they do not get a "new comment" email about their own reply; only the reply notice runs.
Comments in Themes
The comment list and form appear on the theme's post page. For signed-in users the form takes the name and email from the session. It also works with JavaScript turned off: after submitting, the visitor returns to the post, and if something is wrong they are sent back to the form. An approved comment updates the post's comment count and clears the page cache, so it shows up straight away.