Prevent Cross-Site Request Forgery attacks on your comments form.
As of April 2026, Comment Form CSRF Protection is a WordPress csrf plugin with 500 active installations and a 5/5 rating from 2 reviews. It has been downloaded 15K+ times in total. Requires WordPress 4.2+ and PHP 7.1+. Available on WordPress.org since 2019. Last updated 2 years ago — may have compatibility concerns. Top alternative: SameSite Cookies.
WordPress has a 12-year-old unfixed security vulnerability that it does not properly validate incoming comments.
An attacker can trick both anonymous and logged-in users to post comments on a victim site without them realizing, while using their own credentials.
See this issue for more information: https://core.trac.wordpress.org/ticket/10931
This is a tiny (fewer than 40 effect lines of code) module that adds a secure token to the comment form and validate it before accepting any comment, thus making your comment forms secure as they should\’ve been for all these years!
It provides no UI – just install it, and you are all set!
| WordPress | 4.2+ requiredTested up to 6.3.8 |
| PHP | 7.1+ required |
Plugin data sourced from WordPress.org. Analysis and metrics by PluginSift.