Flávio Bolsonaro participará da convenção do PL na Paraíba, confirma vereador Fábio Lopes

Evento será realizado no dia 2 de agosto, em João Pessoa, e marcará a oficialização da candidatura de Efraim Filho ao Governo da Paraíba, além de reunir lideranças do Partido Liberal (PL).

O Partido Liberal (PL) realizará, no próximo dia 2 de agosto, em João Pessoa, a convenção estadual que oficializará a chapa majoritária da legenda para as eleições de 2026.

O evento contará com a presença do senador Flávio Bolsonaro (PL-RJ), apontado pelo partido como pré-candidato à Presidência da República.


Durante a convenção, será oficializada a candidatura do senador Efraim Filho (PL) ao Governo da Paraíba. Também estarão presentes lideranças da legenda, entre elas o deputado federal Cabo Gilberto Silva, líder da oposição na Câmara dos Deputados, o pré-candidato ao Senado Marcelo Queiroga e o vereador de João Pessoa Fábio Lopes, além de filiados, apoiadores e militantes.


A realização do evento foi divulgada pelo vereador Fábio Lopes por meio de um vídeo publicado nas redes sociais. Na gravação, ele convida apoiadores e simpatizantes do ex-presidente Jair Bolsonaro para participarem da convenção e reforçarem o projeto político do partido na Paraíba.


Segundo Fábio Lopes, o encontro será um momento de mobilização da militância e de demonstração de apoio às pré-candidaturas da legenda para as eleições de 2026.

🗞️ Redação do papo informativo

CLIQUE AQUI E SIGA NOSSO CANAL NO WHATSAPP E FIQUE BEM INFORMADO

PF prepara esquema especial de segurança para candidatos à Presidência nas eleições de 2026

Partidos poderão solicitar proteção após as convenções; operação terá centenas de agentes mobilizados e investimento estimado em R$ 95 milhões.

A partir de 20 de julho, os candidatos à Presidência da República nas eleições de 2026 poderão contar com escolta e proteção especial da Polícia Federal durante a campanha eleitoral. De acordo com a corporação, cerca de R$ 95 milhões serão destinados à estrutura de segurança, que terá capacidade para atender simultaneamente até dez candidatos em diferentes regiões do país.


A solicitação do serviço deverá ser feita oficialmente pelos partidos políticos e a proteção poderá ser iniciada após a definição dos nomes nas convenções partidárias. No caso do presidente Luiz Inácio Lula da Silva, que deve disputar a reeleição, a segurança seguirá um modelo integrado, com participação da Polícia Federal e do Gabinete de Segurança Institucional (GSI).


Estrutura de segurança


Para garantir o acompanhamento dos candidatos, a PF prevê o deslocamento de até 458 servidores especializados. Os agentes passaram por treinamentos realizados entre 2025 e 2026, com capacitações em áreas como direção defensiva, primeiros socorros, salvamento aquático e uso de drones.


Toda a operação será coordenada a partir de Brasília pela Sala Nacional de Comando e Controle, que terá acesso às agendas dos candidatos e acompanhará as movimentações das equipes de segurança em tempo real, permitindo respostas rápidas durante os compromissos de campanha.

🗞️ Redação do papo informativo

Eleições: convenções partidárias começam nesta segunda; veja o que muda

Legenda têm até 5 de agosto para definir candidatos, formalizar coligações e registrar as chapas junto ao Tribunal Superior Eleitoral (TSE).

O período de convenções partidárias para as eleições de 2026 começa nesta segunda-feira (20). A etapa é considerada uma das mais importantes do calendário eleitoral, pois é nesse momento que os partidos oficializam os candidatos que disputarão os cargos em eleição.

As convenções poderão ser realizadas até o dia 5 de agosto. Após a definição dos nomes, os partidos devem encaminhar ao Tribunal Superior Eleitoral (TSE) o registro das candidaturas e os respectivos números por meio do Módulo Externo do Sistema de Candidaturas (CANDex), disponível pela internet.

Durante as convenções, além da escolha dos candidatos, também são definidas as coligações partidárias e confirmados os números de urna. As legendas podem manter o número utilizado na eleição anterior, e os candidatos que concorrerem ao mesmo cargo também têm o direito de permanecer com o número já utilizado anteriormente.



Nas eleições de 2026, os brasileiros escolherão presidente e vice-presidente da República, governadores e vice-governadores, dois senadores por estado, deputados federais e deputados estaduais — ou distritais, no caso do Distrito Federal.

As convenções estaduais serão responsáveis pela escolha dos candidatos aos governos estaduais, Senado, Câmara dos Deputados e Assembleias Legislativas. Já as convenções nacionais definirão as candidaturas à Presidência da República e eventuais coligações em âmbito nacional.

Partidos que já anunciaram datas para as convenções nacionais

PDT – 20 de julho

PL – 25 de julho

PSD – 26 de julho

MDB – 27 de julho

Novo – 27 de julho

PCdoB – 30 de julho

PSTU – 31 de julho

PV – 31 de julho

Missão – 1º de agosto

PCO – 1º de agosto

PSB – 2 de agosto

PT – 2 de agosto

🗞️ Redação do papo informativo

CLIQUE AQUI E SIGA NOSSO CANAL NO WHATSAPP E FIQUE BEM INFORMADO

Moraes nega autorização para Javier Milei visitar Bolsonaro em casa

Decisão do ministro mantém restrição de visitas ao ex-presidente por 30 dias; apenas advogados e médicos estão autorizados a entrar na residência.

O ministro Alexandre de Moraes, do Supremo Tribunal Federal (STF), negou neste sábado (18) o pedido para que o presidente da Argentina, Javier Milei, visitasse o ex-presidente Jair Bolsonaro em sua residência, em Brasília.

A solicitação havia sido apresentada pela defesa de Bolsonaro, que pretendia realizar o encontro no próximo dia 25 de julho, durante a passagem de Milei pelo Brasil para participar da convenção nacional do Partido Liberal (PL).

Na decisão, Moraes afirmou que o pedido ficou prejudicado em razão da determinação expedida na sexta-feira (17), que suspendeu por 30 dias todas as visitas ao ex-presidente, permitindo apenas a entrada de advogados e médicos.



A restrição foi imposta após a divulgação, nas redes sociais, de uma carta atribuída a Bolsonaro e publicada pelo senador Flávio Bolsonaro. Para o ministro, o episódio representou descumprimento da medida cautelar que proíbe o ex-presidente de acessar ou utilizar redes sociais.

A defesa argumentou que Bolsonaro não tinha conhecimento de que a carta seria publicada pelo filho, mas a justificativa foi rejeitada por Moraes. O ministro também manteve a proibição de visitas do senador Flávio Bolsonaro ao pai pelo período de 90 dias.

Bolsonaro cumpre prisão domiciliar em Brasília, após ter sido condenado pelo Supremo Tribunal Federal por liderar uma tentativa de golpe de Estado. Inicialmente em regime fechado, o ex-presidente passou ao regime domiciliar por razões humanitárias, em razão de seu estado de saúde, após uma internação hospitalar.

🗞️ Redação do papo informativo

CLIQUE AQUI E SIGA NOSSO CANAL NO WHATSAPP E FIQUE BEM INFORMADO

Paraguaia é presa em Campina Grande suspeita de integrar logística do tráfico entre Paraíba e RN

Suspeita, apontada como integrante de uma facção criminosa do Rio Grande do Norte, foi detida durante ação da Polícia Militar; drogas, arma de fogo e uma segunda mulher com mandado de prisão também foram encontradas.

Uma mulher de nacionalidade paraguaia foi presa na última sexta-feira (17), em Campina Grande, suspeita de atuar na logística do tráfico de drogas entre os estados da Paraíba e do Rio Grande do Norte. A ação foi realizada pela Polícia Militar da Paraíba (PMPB).

Durante a operação, os policiais apreenderam uma arma de fogo e porções de maconha, crack e cocaína no imóvel onde a suspeita estava.

Segundo as investigações, a mulher seria integrante de uma facção criminosa com atuação no Rio Grande do Norte e teria a função de fazer a ligação entre traficantes dos dois estados, além de prestar apoio logístico aos integrantes do grupo criminoso.



A prisão foi resultado de um trabalho de inteligência desenvolvido pelo Departamento de Inteligência (DEINTEL) da Polícia Militar, que repassou as informações à equipe da Força Tática do 2º Batalhão para o cumprimento da ação.

No mesmo local, uma segunda mulher também foi presa. De acordo com a PM, ela possuía um mandado de prisão temporária expedido pelo Tribunal de Justiça do Rio Grande do Norte.

As duas suspeitas foram encaminhadas à delegacia, juntamente com o material apreendido, para os procedimentos cabíveis.

🗞️ Redação do papo informativo

CLIQUE AQUI E SIGA NOSSO CANAL NO WHATSAPP E FIQUE BEM INFORMADO

Gutenberg Times: #WCUS Schedule, iframed Post Editor, WooCommerce 11.0 and so much more — Weekend Edition 369

Hi there!

What a week! WordPress 7.1 Beta 1 (and Beta 2) arrived with a huge array of updates. We’ll unpack them together over the next four weeks, right up to the final release on August 19, 2026.

One thing shouldn’t wait, though: the security release WordPress 7.0.2. Go update your production sites now — this newsletter will still be here when you’re back. 😉

In this edition, you’ll also find the first speaker lineup for WordCamp US, a fourth page-builder migration story, WooCommerce 11.0 on the horizon, and plenty of block development goodness: from iframed editors to on-brand maintenance pages.

Grab your favorite Saturday beverage and dig in.

Yours, 💕
Birgit


WordCamp US 2026: Four Tracks, Three Workshops, 33 Speakers

First speaker spotlight WordCamp US>

The first wave of WCUS 2026 speakers is live — and it reads like a who’s-who of WordPress in practice.

WordCamp US just published its opening lineup for August 16–19 in Phoenix: 34 confirmed speakers so far, including K Adam White, Brian Coords, Jamie Marsland, Kathy Zant, Miriam Schwab, and Robert Abela, all experienced developers, educators, security specialists, community builders.

The program runs four tracks.

  • AI in Action leads with sessions on agentic workflows, AI search, and guardrails for AI-assisted development.
  • Honing Your Skills covers the practical side: maintenance, privacy compliance, creator commerce, security.
  • Technical WordPress digs into block migrations at scale, WP-CLI automation, and plugin pipelines.
  • Beginning WP101 is the on-ramp for newcomers — or for clients you’re bringing along.
  • Three hands-on workshops round out the program, where you build something real in the room and leave with it.

The full session schedule isn’t out yet, but the speaker list alone is a useful signal. If someone on that page is a voice you follow, a tool you depend on, or a corner of WordPress you’re actively navigating, you now have a specific reason to be in the room.

🎟 us.wordcamp.org/2026/tickets — $100 General Admission · $750 Micro-Sponsor (includes listing on the sponsors page) 👥 Full speaker list →

Developing Gutenberg and WordPress

WordPress 7.1 Beta 1 was release on July 15, 2026. is now available for testing. The release post offers instructions how to sent up a test side and shows an extensive list of new features.

The security team released WordPress 7.0.2 with the urgent appeal to update right away. The security fixes were also backported in 6.9.5 and 6.8.6.

The security fix was also included in WordPress 7.1 Beta 2, so testing sites are also protected during this release cycle.

Huzaifa Al Mesbah, from the Core Test team, published the accompanying Help Test WordPress 7.1 post.

A few WordPress 7.1 Dev Notes are already available:

Plugins, Themes, and Tools for #nocode site builders and owners

In about 10 days, WooCommerce 11.0 release is schedule. Brain Coords has the skinny for you in what’s coming for developers in WooCommerce. Performance leads the release with 28 PRs — product object caching becomes the default for new stores, speeding up variable products by 9–12%. You’ll also find email verification connecting guest orders to accounts, new phone validation hooks, video embeds in the block email editor, and the final removal of the Product Editor beta. The beta is ready for your testing now.


Jamie Marsland followed his instincts and build Jamie’s Front-End Editor for Content Teams, a plugin that lets your editors click any paragraph or heading on the live page and start typing — no block editor required. With the latest updates, you can now edit text, links, buttons and images right on the live page. No wp-admin, no block editor, just click and change it in place.

Built on the Interactivity API with no build step, it preserves block markup on save, records edits as native block notes for an audit trail, and lets you restrict chosen roles to front-end-only editing. Let Marsland what you think.


Last week, I shared three migration stories from page builders to the Core block editor and block themes. Here’s a fourth perspective: The team at WP Expert, an Ottawa agency founded by Frederic Sune, put together a comprehensive post on migrating agency sites from page builders to Gutenberg, should you go on that journey, too. You’ll find the strategic arguments (better Core Web Vitals, smaller attack surface, less technical debt) alongside a practical playbook covering backups, staging, block theme selection, pattern development, and SEO safeguards. The post also explores what block-based architectures mean for an agency’s business model, from premium modernization packages to fewer layout-related support tickets. An FAQ rounds it out.

Theme Development for Full Site Editing and Blocks

Brian Coords tackles a common WooCommerce pain point: custom product templates for block themes. He combines two core WordPress features — the plugin template registration API from 6.7 and the venerable single_template_hierarchy filter — to serve custom templates for product collections, like all products in a category. His example plugin falls back to your Single Product template unless you override it. Clone the repo and give it a try; custom Product fields are next on his list.


On the WordPress Developer Blog, Troy Chaplin shows you how to build an on-brand maintenance mode for block themes. You add one small hook to your theme’s functions.php once, then design and manage the maintenance page entirely in the Site Editor with full access to your Global Styles. Renaming or deleting the template toggles maintenance mode on and off, no code needed. An SEO-friendly variant adds 503 headers so crawlers know the downtime is temporary.

“Keeping up with Gutenberg – Index 2026”
A chronological list of the WordPress Make Blog posts from various teams involved in Gutenberg development: Design, Theme Review Team, Core Editor, Core JS, Core CSS, Test, and Meta team from Jan. 2024 on. Updated by yours truly. 

The previous years are also available:
2020 | 2021 | 2022 | 2023 | 2024 | 2025

Building Blocks and Tools

On WP Mayor, Jean Galea untangles when to reach for WP-CLI, the REST API, or the Abilities API. His mental model: they’re layers, not rivals. WP-CLI lives on the server for bulk work, REST serves off-server callers like headless front ends, and the Abilities API tells AI agents what they’re allowed to do, complete with schemas and permission checks. Galea also shares how his own sites lean on all three at once.


Get up to speed how to make your custom blocks plugin work in the iframed post editor, if you haven’t yet. After five years of ruminating and communicating the switch is coming to WordPress 7.1. In his post, Ryan Welcher explains why the post editor is going full iframe in WordPress 7.1 and what that means for your custom blocks. You’ll find the fixes for the most common breakage — global window and document references, editor styles enqueued into the wrong document, stale admin-scoped CSS, and third-party libraries — plus a companion demo plugin with broken/fixed block pairs, Playground blueprints for testing both states, and a handy pre-flight checklist.


The video volunteers at WordCamp Portugal uploaded all recordings to WordPressTV and two of the talks caught my eye:

Imran Sayed walks you through the fastest way to build Gutenberg blocks with modern tools, scripts, and AI. If custom block development has felt complex or time-consuming, you’ll appreciate his focus on practical, real-world workflows you can adopt immediately — moving fast without over-engineering. The recording is available on WordPress.tv, and the presentation slides are linked below the video for easy reference.

Jorge Costa shows you how to use the AI building blocks already shipped in WordPress core (the WP AI Client, the Abilities API, and the MCP adapter) to bring AI-powered features into your own plugins, themes, and sites. He also tackles the bigger question: when agents can spin up entire projects on any stack, why is WordPress still the right bet? Slides are linked alongside the recording.


Check out the not so new any more Talk Devy to Me series on Ryan Welchers YouTube Channel! In the latest epsiode, Antonio Sejas demos Studio Code, the agentic AI assistant built into WordPress Studio’s desktop app and CLI. You can spin up sites, run performance audits, add content, and install plugins and themes through natural language conversation — all locally, so nothing you break goes public. Sejas explains how it works under the hood before building something live with the host. Studio Code is free while in beta, so now’s a good time to experiment.


If you rather want to read about the updates in WordPress Studio, Fredrik Rombach Ekelund shares three big updates to WordPress Studio: a new default Native PHP runtime makes your local sites load 30–50% faster while using a third of the memory, the Studio CLI now installs with one dependency-free command — no Node.js or npm required — and Claude Sonnet 5 is the new default model in Studio Code, improving multi-step work like tracing bugs across files. A Sandbox runtime remains available for testing untrusted code.


Need a plugin .zip from Gutenberg’s master branch?
Gutenberg Times provides daily build for testing and review.

Now also available via WordPress Playground. There is no need for a test site locally or on a server. Have you been using it? Email me with your experience.


Questions? Suggestions? Ideas?
Don’t hesitate to send them via email or
send me a message on WordPress Slack or Twitter @bph.


For questions to be answered on the Gutenberg Changelog,
send them to changelog@gutenbergtimes.com


Featured Image:


Matt: Important Security Update

WordPress 7.0.2 went out today with two important security updates. One is a type of pre-authorization RCE we (fortunately!) have only seen a few times in WordPress’ 23-year history; the last, I believe, in the PHPMailer class five years ago.

Major kudos to Adam Kues of Searchlight Cyber for finding the batch REST API RCE, to TF1T, dtro, and haongo on the facilitated SQL injection!

Thanks to responsible disclosure, the WordPress.org Security team was able to coordinate with hosts and CDNs to mitigate the attack at the network layer. Please upgrade anyway! But it’s a huge relief to know the vast majority of WordPress sites were protected by defense-in-depth even before the updates went out.

I really appreciate how people and organizations that otherwise might not be on the best of terms come together in times like this. (Full credits in the release post.) Everyone buries the hatchet to protect as many people as possible as quickly as possible.

I’ve said it before, I’ll say it again: security is going to be a big topic this year as the technology industry digests the incredible advances in AI models. It’s a good time to review your plans and processes, sweat the details, invest in maintenance, and hug a sysadmin. 🙂

Jovem morre após passar mal durante expediente em empresa de call center, em Campina Grande

Jovem sofreu um mal súbito enquanto trabalhava; causa da morte será confirmada por exames.

Um jovem morreu nesta sexta-feira (17) após passar mal enquanto trabalhava em uma empresa de call center, em Campina Grande. As informações preliminares apontam que a causa da morte pode ter sido um infarto, mas a confirmação dependerá dos exames oficiais.

Segundo relatos, o trabalhador aparentava estar bem durante o expediente. Ele conversava normalmente com colegas, utilizava o celular e participava de uma ligação, enviando áudios, quando foi ouvido um forte barulho. Em seguida, funcionários o encontraram caído no chão, apresentando convulsões.



Equipes de socorro iniciaram imediatamente os procedimentos de emergência. Durante cerca de uma hora, foram realizadas diversas tentativas de reanimação, incluindo massagens cardíacas, administração de medicamentos e uso de desfibrilador. Apesar dos esforços, o jovem não resistiu.

A vítima foi identificada como Douglas Doutxy, integrante da Junina Moleka. Em nota de pesar, a agremiação destacou a trajetória de mais de duas décadas do jovem no grupo, ressaltando sua dedicação, talento e contribuição para a história da quadrilha.

Até o momento, a empresa onde o caso ocorreu não se pronunciou oficialmente. As circunstâncias da morte serão esclarecidas após a conclusão dos exames periciais.

🕊️ O Papo Informativo se solidariza com familiares, amigos e colegas de Douglas neste momento de dor.

🗞️ Redação do papo informativo

CLIQUE AQUI E SIGA NOSSO CANAL NO WHATSAPP E FIQUE BEM INFORMADO

WordPress.org blog: WordPress 7.0.2 Release

WordPress 7.0.2 is now available.

The 7.0.2 security release addresses one critical and one high severity security issue.

Because this is a security release, it is recommended that you update your sites immediately. Due to the severity, the WordPress.org team have enabled forced updates via the auto-update system for sites running affected versions.

To manually update you can visit your WordPress Dashboard, click “Updates”, and then click “Update Now”, or you can download WordPress 7.0.2 from WordPress.org. On sites that support automatic background updates, the update process will begin automatically.

Security updates included in this release

The security team would like to thank the following people for responsibly reporting vulnerabilities and allowing them to be fixed in this release:

  • A facilitated SQL injection issue reported as a team by TF1T, dtro, and haongo
  • A REST API batch-route confusion and SQL injection issue leading to Remote Code Execution reported by Adam Kues at Assetnote / Searchlight Cyber

For more information on this release, please visit the HelpHub site.

Backports

  • WordPress 6.9 is affected by both vulnerabilities. Version 6.9.5 has been released containing fixes for both.
  • WordPress 6.8 is only affected by the first vulnerability. Version 6.8.6 has been released containing a fix.
  • The beta release of WordPress 7.1 is affected by both vulnerabilities. Version 7.1 beta2 has been released containing fixes for both.
  • Versions of WordPress prior to 6.8 are not affected.

CVE and GHSA references

Thank you to these WordPress contributors

This release was led by John Blackbourn and Barry Abrahamson. In addition to the security researchers mentioned above, WordPress 7.0.2 would not have been possible without the significant contributions of the following people: Aaron Jorbin, Alex Concha, annezazu, Barry, David Baumwald, Dominik Schilling, Ehtisham Siddiqui, Joe Dolson, Joe Hoyle, John Blackbourn, Jonathan Desrosiers, Marius L. J., Matt Mullenweg, Mohammad Jangda, Peter Wilson, Sergey Biryukov, vortfu, Weston Ruter, plus representatives from Altis, Automattic, Bluehost, Cloudflare, GoDaddy, Hostinger, and WP Engine.

Ultimate WordPress Spam Protection Guide – Step by Step (2026)

If you run a WordPress site, then you know that spam is a real annoying problem whether it comes to contact forms, WordPress comments, or user registrations.

The good news is that stopping spam in WordPress is a lot easier than you probably think, and you don’t need expensive tools either.

We have spent over 16 years testing anti-spam plugins, tools, and refining strategies to keep WPBeginner and our other business websites safe from daily spam attacks.

In this ultimate guide, we’ll walk you through how to block each type of WordPress spam, step by step from the basics to advanced modern automated spam protection. These are the exact methods we’re using to protect our own websites.

The Ultimate WordPress Spam Protection Guide - Step by Step

We’re covering a lot of ground in this ultimate guide, so use the quick links below to jump straight to the section you want to learn about first:

1. Free Built-In Settings to Turn On First

WordPress comes with several anti-spam options that can protect your site against spam. These built-in options won’t stop every bot, but they will remove the easiest targets right away.

We always recommend turning these settings on first, because they cost nothing and take only a few minutes to set up.

Tighten Your WordPress Discussion Settings

To prevent comment spam, the built-in discussion settings in WordPress act as your first line of defense. They allow you to control who can post, what kind of links are permitted, and how much control you have over the conversation.

To configure these anti-spam controls, go to Settings » Discussion in your WordPress dashboard.

Protecting the WordPress comment section against spammers

The most useful tool on this screen is the comment moderation queue. This tool acts as a holding area that keeps submissions hidden from the public until you have a chance to look them over.

Because nothing goes live automatically, spam never reaches your visitors, even if it manages to get past your other filters.

To turn this on, scroll down to the ‘Before a comment appears’ section and check the box next to ‘Comment must be manually approved.’

How to require manual approval for WordPress comments

If you want, you can also enable ‘Comment author must have a previously approved comment.’ This lets returning commenters post without waiting for approval. However, be sure to review your published comments regularly since they won’t appear in your moderation queue.

After that, scroll to the ‘Comment Moderation’ box, where you’ll find a setting that limits links. Because spam comments almost always contain web addresses, WordPress can automatically hold any submission that includes too many links.

The field labeled ‘Hold a comment in the queue if it contains [X] or more links’ is set to 2 by default. Lowering that number to 1 will help you catch even more junk.

Adding comments to an approval queue in WordPress

On the same screen, you can use the comment blocklist to automatically filter out unwanted content. This tool looks for specific words, names, email addresses, or web addresses and sends any matching comment straight to the trash.

In the ‘Disallowed Comment Keys’ box, you can paste your own trigger words, putting one on each line, and then save your changes.

Filtering your WordPress comments
Require a Name and Email, and Hold First-Time Commenters

Healthy discussions start with real people. Requiring commenters to enter a name and email encourages more thoughtful conversations and discourages anonymous drive-by comments.

Most genuine visitors won’t mind providing these details, and it helps create a more welcoming and trustworthy community around your website.

To enable this, scroll to the ‘Other comment settings’ section and check the box next to ‘Comment author must fill out name and email.’

How to block anonymous comments on your WordPress website

If you want to master the review process and manage your queue efficiently, our beginner’s guide to moderating comments in WordPress covers the full workflow.

Disable Comments Where You Do Not Need Them

Depending on the type of website you have, you may not need a comment section at all. If that’s the case, then you can simply disable comments entirely and that’ll get rid of the WordPress comment spam problem once and for all.

The most thorough option is the code method, which disables comment support across your entire site at once. It’s safest to add the snippet with a free code snippets plugin like WPCode rather than editing your theme’s files directly, so a theme update can’t undo it.

add_action('admin_init', function () {
    // Redirect any user trying to access comments page
    global $pagenow;
    
    if ($pagenow === 'edit-comments.php') {
        wp_safe_redirect(admin_url());
        exit;
    }

    // Remove comments metabox from dashboard
    remove_meta_box('dashboard_recent_comments', 'dashboard', 'normal');

    // Disable support for comments and trackbacks in post types
    foreach (get_post_types() as $post_type) {
        if (post_type_supports($post_type, 'comments')) {
            remove_post_type_support($post_type, 'comments');
            remove_post_type_support($post_type, 'trackbacks');
        }
    }
});

// Close comments on the front-end
add_filter('comments_open', '__return_false', 20, 2);
add_filter('pings_open', '__return_false', 20, 2);

// Hide existing comments
add_filter('comments_array', '__return_empty_array', 10, 2);

// Remove comments page in menu
add_action('admin_menu', function () {
    remove_menu_page('edit-comments.php');
});

// Remove comments links from admin bar
add_action('init', function () {
    if (is_admin_bar_showing()) {
        remove_action('admin_bar_menu', 'wp_admin_bar_comments_menu', 60);
    }
});

Our guide on how to completely disable comments in WordPress walks through that snippet along with the other options.

If you’d rather not go site-wide, you can also turn comments off on individual pages. This is handy when you only want them gone on specific pages, like your Contact or About pages, which rarely need a comment section.

To do this, open the page in the WordPress content editor. Then click the ‘Discussion’ option in the right-hand sidebar and select ‘Closed.’

How to disable comments on your WordPress pages

You can also stop spam from piling up on older content without touching your newer posts. If you don’t expect comments on old posts, then WordPress can close them automatically after a set number of days.

This gives spam bots fewer chances to target your archived content.

To set this up, head to Settings » Discussion and find the ‘Other comment settings’ section. Check the box next to ‘Automatically close comments on posts older than [X] days’, then set a sensible limit such as 30 or 90 days.

Automatically closing comments on older WordPress posts
Disable Trackbacks and Pingbacks

Trackbacks and pingbacks notify you when another website claims to have linked to one of your blog posts.

While they were originally designed to help bloggers connect conversations across different websites, they’re now commonly abused by spammers to send fake link notifications.

Turning this feature off completely removes a whole category of junk notifications from your dashboard.

To disable these notifications, go to the Settings » Discussion screen in your WordPress dashboard. Here, uncheck the box next to ‘Allow link notifications from other blogs (pingbacks and trackbacks) on new posts.’

Disabling pingbacks and trackbacks in WordPress Discussion settings
With that done, don’t forget to click ‘Save Changes’ at the bottom of the screen.

Just be aware that changing this option only protects the posts you publish from this moment forward. If you want to clean up the content you’ve already published in the past, you can follow our step-by-step guide on how to disable trackbacks and pings on existing WordPress posts.

2. Set Up Modern AI-Powered Spam Bot Protection for WordPress

In the era of AI where automated spam is increasing, the best defense against it is a modern AI-powered spam protection for WordPress.

These spam filtering solutions automatically detect and block spam on your WordPress comments, contact forms, and user registrations without the use of CAPTCHA which can hurt conversions.

On WPBeginner, we use ActiveLayer for this. It is AI-powered and runs server-side, so it stops spam invisibly, without a CAPTCHA and it’s GDPR compliant.

In the last 30 days, it has blocked over 25,739 spam comments and contact form submissions on our website. It even shows you a confidence score, and the reason behind every submission it flags, not just a pass-or-fail verdict when you look at their logs.

ActiveLayer Spam Stats Screenshot for WPBeginner

The free plan includes 1,000 spam checks with no credit card, and paid plans start at around $4 per month billed yearly.

The two other popular spam filtering plugins for WordPress you could try are Akismet or CleanTalk.

Akismet is very popular and still is a good fit for personal blogs, where its “name your price” plan can be free for non-commercial sites. But they have raised their prices significantly for commercial sites which is quite expensive for smaller businesses. For a business site, we would point you to either ActiveLayer or CleanTalk.

Whichever tool you choose, stick to just one, because running two spam filters at once can conflict and block real visitors. The benefit of these spam protection plugins are that they integrate with all other popular contact form plugins by default.

3. Power-User Tips for Stopping WordPress Comment Spam

So far we’ve configured the built-in spam prevention settings in WordPress, and an automated spam filtering plugin for WordPress. The combination of these two should block most spam.

However if you are not able to set up modern AI spam protection due to costs or another reason, then you can use one of these tips below to combat comment spam in WordPress.

Add a Free CAPTCHA to Your Comment Form

CAPTCHA is a simple test that most human visitors pass without any effort, while automated scripts fail it. We recommend adding Cloudflare Turnstile CAPTCHA to your WordPress comments because it’s free and fairly straight forward to set up.

To set it up, install and activate the free Simple Cloudflare Turnstile plugin. You will be asked to create a free account on Cloudflare’s website and connect it with the plugin.

Once that’s done, you can scroll to the ‘Enable Turnstile on your forms’ section. Simply check the boxes to protect all your WordPress forms and click ‘Save Changes’.

How to protect your site against spammers and spambots using the free Simple Cloudflare Turnstile plugin

Here’s our detailed guide on how to add Cloudflare Turnstile CAPTCHA in WordPress.

Google reCAPTCHA is another option, which you can add with the Advanced Google reCAPTCHA plugin. We no longer recommend it because Google has capped their free tier at 10,000 assessments per month for your entire organization whereas Cloudflare Turnstile stay free without limits.

Limit or Require Login to Comment

Another really effective way to stop comment spam in WordPress is to control who’s allowed to participate in comments.

If your comment section is open to everyone, then spammers can continuously flood your forms with automated links. Restricting comments to registered account holders ensures that only verified users can post. This forces a level of accountability that most bots will not bother trying to bypass.

Because it requires readers to go through the extra step of creating and logging into an account, this approach is best suited for membership sites, online forums, and private communities.

If you run an open, public blog, then we’d recommend using an automated filtering service or a reader challenge instead as those add less friction.

If you do decide to turn this restriction on, go to Settings » Discussion in your WordPress dashboard. Under the ‘Other comment settings’ section, check the box next to ‘Users must be registered and logged in to comment.’

Requiring user registration before allowing comments

As always, don’t forget to save your changes.

Use Antispam Bee for Free Keyword and Pattern Filtering

Some spam slips through basic checks by mimicking human writing. This is where a dedicated filtering plugin can help protect your site.

Antispam Bee is an excellent free, privacy-friendly anti-spam plugin that doesn’t require an API key or account registration. Installing Antispam Bee gives you a powerful set of local rules to analyze comment data before it even hits your database.

Once it’s activated, you can configure your rules by going to Settings » Antispam Bee.

Protecting your site against automated spam scripts using WordPress plugins

We recommend enabling the options to:

  • Trust approved commenters.
  • Mark as spam.
  • Do not delete.
  • Use regular expressions (which allows the plugin to scan for known text and link patterns).

You should also check the box to ‘Look in the local spam database.’ This allows Antispam Bee to cross-reference new submissions against previous spam history on your site.

Look in your local spam database

Under ‘Advanced,’ you can set Antispam Bee to delete existing spam after a set number of days, which keeps your database tidy without any manual effort.

We highly recommend leaving the email notifications for spam turned off in this section. A busy website can attract hundreds of automated submissions a day, and these alerts will quickly flood your inbox.

If you want to try one more free tweak, then you can remove the website address field from the comment form.

Our step-by-step guide on how to remove the website URL field from the comment form shows you how to do this in just a few quick steps.

4. Stopping WordPress Contact Form Spam (Best Practices)

Contact and lead forms are among the most attacked parts of any WordPress site. We know this firsthand because we once had to combat more than 18,000 spam entries flooding a single form.

We use WPForms to build forms on WPBeginner, and it’s a popular form builder plugin used by over 5 million websites. Their free version includes smart anti-spam protection, CAPTCHA integrations with Google / Cloudflare Turnstile, and the paid plans add the filtering options we cover below.

Other popular form builders like Gravity Forms and Fluent Forms have similar anti-spam settings, so check the options in whichever form builder plugin you use. We will show WPForms here because it’s what we use and consider the best fit for beginners.

Enable Default Anti-Spam Token (or Similar HoneyPot)

To combat lead form spam, WPForms silently attaches a unique, time-sensitive token to your form on every page load. The anti-spam token blocks automated scripts, which means spam entries are blocked before they reach your inbox.

It’s turned on by default for new forms, but it’s worth confirming.

Open your form, go to Settings » Spam Protection and Security, and make sure ‘Enable modern anti-spam protection’ is switched on.

An example of a form builder with built-in anti-spam protection

This is a modern version of the Honeypot technology which most WordPress form plugins come with, so it may be labeled as Honeypot in another form tool that you might be using.

Enable a CAPTCHA on Your Contact Form

More aggressive bots mimic human browsing and slip past the invisible token. Adding a visible CAPTCHA field stops them by forcing a challenge they can’t read or solve.

WPForms has both Cloudflare Turnstile and Google reCAPTCHA built in, and we default to Turnstile here. It’s free for everyone and runs its checks in the background, so most real visitors pass without solving a puzzle.

To set it up, go to WPForms » Settings » CAPTCHA and choose ‘Cloudflare Turnstile’.

Adding Cloudflare Turnstile CAPTCHA to a WordPress website

Then add the Site Key and Secret Key from your Cloudflare account, and save your settings.

Finally, add the CAPTCHA field to each form you want to protect.

Add Turnstile field to WPForms

For a full walkthrough, see our guide on how to add Cloudflare Turnstile CAPTCHA in WordPress.

Google reCAPTCHA is also selectable on that same WPForms » Settings » CAPTCHA screen. We default to Turnstile because it’s free without limits, but reCAPTCHA still works if you prefer it.

If you’d rather not send visitor data to Google or Cloudflare, then WPForms’ Custom Captcha field (available on any paid plan) builds the challenge on your own server instead.

Add the field, then set it to a random math problem or your own question and answer.

Setting a question and answer custom CAPTCHA in WPForms
Use Time-Based Behavioral Checks to Stop Contact Form Spam

A real person needs several seconds to read a question and fill out a form, while a bot submits in a fraction of a second. Time-based checks flag those impossibly fast submissions without changing anything the visitor sees.

With WPForms, the ‘Enable minimum time to submit’ option is enabled by default with a minimum time to submit of 2 seconds. However, you can update the minimum time to any value you like.

The WPForms minimum time to submit anti-spam setting
Block Form Submission by Country, IP, Email Address, and More

Some spam form submissions still gets through unless you screen the content itself. In the Pro version, WPForms lets you block entries by specific email address, by keyword, and by country or IP address.

To block a sender, open your form, select the Email field, open the Advanced tab, choose Denylist, and enter the addresses or domains to ban. A wildcard like *@example.com blocks an entire domain.

Advanced email allowlist and denylist filtering in WPForms

To block spammy phrases, go to Settings » Spam Protection and Security.

Turn on ‘Enable keyword filter’, open ‘Edit keyword list’, and add each term on its own line.

Creating a list of banned words for your online forms

And if you only serve certain regions, turn on ‘Enable country filter’ on the same screen to allow or deny locations.

Country filter in WPForms

Alternatively if your WordPress form solution doesn’t have this option, you can also block IP addresses in WordPress.

5. Stopping Spam User Registrations in WordPress (Best Practices)

On a membership site or WooCommerce store, spam registrations are more than a nuisance. Fake accounts clog your user database and skew your customer and email metrics.

Here’s what you can do to prevent spam user registrations in WordPress.

Turn Registration Off When You Do Not Need It

If you’re not running a membership site or an eCommerce store, then you likely don’t need to allow user registration. The easiest thing to prevent user registration spam there is to turn it off.

Simply go to Settings » General in your WordPress admin area, and uncheck the ‘Anyone can register’ box.

Disabling user registration on your website, blog, or eCommerce store
Require Email Confirmation Before an Account Activates

If you do need open registration, then the goal is to let only real people in while keeping spam bots out. The setting that stops the most fake signups is requiring a confirmed email address, or a manual review, before an account goes live.

Where that control lives depends on what plugin you’re using to manage user registration in WordPress. You will want to start with your platform’s default setting instead of bolting a general form plugin onto a system that already handles this.

If you run a WooCommerce store, then go to WooCommerce » Settings » Accounts & Privacy. This is where you decide whether shoppers can create an account at all, limit account creation to checkout, or keep guest checkout on so no account creation is needed.

Force guest checkout by disabling account creation and login during checkout in WooCommerce

WooCommerce core doesn’t add a separate email-confirmation step on its own. If you want one, then you’ll need a custom email verification extension or the custom signup form covered below.

Other membership and course platforms handle account verification in their own settings, so start there:

  • MemberPress: WordPress creates the account on registration, so pair it with the free User Verification plugin to keep the account inactive until the person confirms their email. See MemberPress’ documentation for the full details.
  • BuddyPress and BuddyBoss: email activation is built in, so new members stay inactive until they click the activation link. Enable registration under Settings » General (BuddyPress) or BuddyBoss » Settings » Login & Registration. See BuddyPress documentation and BuddyBoss documentation for more details.
  • LearnDash: registration runs on WordPress’s own user system, so there’s no native email-confirmation step. An account goes live the moment someone signs up. To hold new accounts until the email is verified, add that check at the WordPress or form level, using a user verification plugin or the custom WPForms registration form covered below.

If you’re building a custom registration form rather than using one of the systems above, then you can use WPForms User Registration addon which lets you turn on email activation under the form’s User Registration settings, with either an email confirmation link or manual admin approval.

Requiring email activation for new WordPress user accounts

Similar options are available in Gravity Forms, WSForm, and other popular WordPress form plugins. For the full walkthrough, see our guide on how to moderate new user registrations.

Add CAPTCHA and Honeypot to WordPress Signup Form

The same tips that protect your WordPress contact forms also work on WordPress signup form. Since you already set up Cloudflare Turnstile earlier, you can switch it on for your registration form in a click.

For a dedicated walkthrough, see our guide on how to add a CAPTCHA to your login and registration forms.

If you’re using the default WordPress registration page, then you can add hidden honeypot fields to your registration form with the free WP Armour plugin. The plugin logs every bot it blocks under WP Armour » Statistics.

The WP Armour WordPress plugin
Use AI-Powered Tools for Blocking WordPress Registration Spam

Honeypots and CAPTCHAs stop obvious bots, but they can’t spot someone signing up with a throwaway email or from a known-bad IP address.

That’s where automated detection helps. It screens each new signup against live reputation data and blocks the ones that look fraudulent.

ActiveLayer and CleanTalk both offer this for WordPress registrations, and you can switch it on for your signup form the same way you did for your contact forms.

6. Add a Site-Wide WordPress Firewall

A Web Application Firewall (WAF) screens every visitor and blocks malicious requests before they reach your site. Since most form spam is automated, a good firewall can stop a lot of it at the perimeter.

We recommend a DNS-level firewall, which filters traffic on the provider’s network before it touches your server.

On WPBeginner, we use Cloudflare, which has a free plan with basic firewall protection (setup requires pointing your domain’s nameservers to Cloudflare).

The Cloudflare website, a DNS level firewall for WordPress

Our guide on how to set up the free Cloudflare CDN and firewall walks through it.

Plus, our roundup of the best WordPress firewall plugins compares the other options if you want to weigh them up.

7. Cleanup WordPress Spam and Ongoing Monitoring

Stopping new spam is only half the job. If you’re like most websites, you already have a backlog of old junk that needs cleaning up.

A quick cleanup keeps your database tidy and helps your new tools run at their best.

🚨 Always create a complete WordPress backup before deleting anything in bulk. These actions permanently wipe data, with no undo button if you make a mistake.

Bulk-Delete Existing Spam Comments

WordPress spam filter flags junk comments but doesn’t delete them, so they can build up in your spam folder and take up database space until you clear them out.

In your dashboard, go to Comments, click the ‘Spam’ filter at the top, and hit ‘Empty Spam’ to permanently clear everything your filters caught.

Bulk deleting spam comments on your website, blog, or online store

If you have thousands of junk comments, the dashboard can freeze or time out. A free plugin like WP Bulk Delete is faster and more reliable for big backlogs.

For other methods, see our guide on how to bulk delete WordPress comments.

Clean Out Existing Fake User Accounts

Leaving bot profiles in your database is a security risk and skews your analytics. That’s why it’s important to clean out these fake accounts.

For a handful, go to Users » All Users, click the ‘Subscriber’ user role filter (the role almost all registration bots use), select the fake accounts, and choose Delete from the ‘Bulk actions’ menu.

⚠️ Be very careful to select only fake Subscriber accounts, and never an Administrator account.

Deleting fake users on your online store

For thousands of accounts, the free WP Bulk Delete plugin can remove users by role, inactivity, or registration date in one sweep.

For more information, see our guide on how to bulk delete WordPress users by role.

Handle False Positives

No filter is perfect, so never auto-delete your spam folder without a quick glance first.

In Comments » Spam, hover over a legitimate comment and click ‘Not Spam’. That also teaches your filter to recognize similar comments as safe in the future.

Marking a comment as Not Spam on WordPress
Set a Monthly Anti-Spam Review Routine

A few minutes each month keeps spam from piling back up. Add these three checks to your maintenance routine:

  • Scan for false positives: skim your spam comment folder and form entries so no real messages were caught by accident.
  • Empty your spam folders: once you’ve rescued anything real, clear them to keep your database lean.
  • Check your user list: glance at new registrations for gibberish usernames or suspicious email domains that slipped through.

Key Takeaways

Here is a summary of the best practices we have covered to completely protect your WordPress website from spam:

  • Start with free WordPress settings: turn on comment moderation, tighten your link limits, build a comment blocklist, and disable trackbacks. These cost nothing and clear out the easiest spam.
  • Use automated, invisible filtering: a server-side tool like ActiveLayer, Akismet, or CleanTalk blocks bots in the background without making real visitors solve puzzles.
  • Layer your contact form defenses: honeypots alone no longer stop modern bots, so combine them with timing checks, token validation, and an automated filter.
  • Secure your registrations: require email confirmation for new accounts and screen every signup with an automated tool.
  • Add a site-wide firewall: a DNS-level firewall like Cloudflare blocks a lot of automated spam at the perimeter, before it ever reaches your forms.
  • Run regular cleanup: bulk-delete old spam comments and fake accounts, then spend a few minutes each month checking for false positives.

Frequently Asked Questions About WordPress Spam Protection

Is free Akismet-style filtering enough, or do I need
more?

For a small personal blog with only comment spam, a single free filter like Akismet is usually enough. Once you add contact forms, signup forms, or user registration, you’ll want a service that protects those too, like ActiveLayer or CleanTalk.

Will adding a CAPTCHA hurt my form conversions?

It can. The extra step causes some real visitors to give up on the form. This is why we prefer invisible, server-side detection that blocks bots without asking anyone to solve a puzzle.

Why am I still getting spam after installing an anti-spam
plugin?

Usually because the plugin only guards one entry point. If it protects your
comments but not your signup or contact forms, bots just move to those
instead, and older tricks like basic honeypots no longer stop modern bots. The
fix is a layered setup: your built-in WordPress settings, an automated
filter, and a firewall working together.

How do I stop fake user registrations without turning off signups
completely?

Turn on email confirmation so new accounts stay inactive until the person
clicks a link in their inbox, which bots can’t do. Pair it with a honeypot and
an automated filter, and real people can still sign up freely.

Can spam actually hurt my SEO or get my site
blacklisted?

It can, but it depends on where the spam is. Comment spam sitting in your moderation queue is never published, so search engines never see it and your SEO stays safe.

Published spam is the real risk, because it can slowly pull down your rankings. WordPress does tag comment links as nofollow, which limits the damage.

We hope this article helped you learn how to protect your WordPress website against spam. You may also want to check out our ultimate WordPress security guide to improve your website security.

If you liked this article, then please subscribe to our YouTube Channel for WordPress video tutorials. You can also find us on Twitter and Facebook.

The post Ultimate WordPress Spam Protection Guide – Step by Step (2026) first appeared on WPBeginner.