PluginSift
PluginsThemesCompare
Directory
  • Plugins
  • Themes
  • Compare Plugins
Plugin Comparisons
  • SEO
  • Security
  • Ecommerce
  • Page Builders
  • Caching
  • Backup
  • Forms
  • Analytics
Resources
  • About
  • Contact
  • llms.txt

© 2026 PluginSift. Data sourced from WordPress.org. · [email protected]

  1. Home
  2. Plugins
  3. Csrf
  4. Comment Form CSRF Protection
Comment Form CSRF Protection icon

Comment Form CSRF Protection

Prevent Cross-Site Request Forgery attacks on your comments form.

By Ayesh Karunaratne·Csrf·Free
5(2 reviews)
·500 active installs·Updated 2 years ago
DownloadVisit HomepageCompare

As of April 2026, Comment Form CSRF Protection is a WordPress csrf plugin with 500 active installations and a 5/5 rating from 2 reviews. It has been downloaded 15K+ times in total. Requires WordPress 4.2+ and PHP 7.1+. Available on WordPress.org since 2019. Last updated 2 years ago — may have compatibility concerns. Top alternative: SameSite Cookies.

5/52 reviews
500active installs
15K+total downloads
7 yearssince 2019

Overview

WordPress has a 12-year-old unfixed security vulnerability that it does not properly validate incoming comments.

An attacker can trick both anonymous and logged-in users to post comments on a victim site without them realizing, while using their own credentials.

See this issue for more information: https://core.trac.wordpress.org/ticket/10931

This is a tiny (fewer than 40 effect lines of code) module that adds a secure token to the comment form and validate it before accepting any comment, thus making your comment forms secure as they should\’ve been for all these years!

It provides no UI – just install it, and you are all set!

  1. This plugin adds a secret cryptographically-secure token to the comment form. This is a unique value and is computationally impractical to guess it.
  2. U…
Read full description on WordPress.org

Screenshots

Ratings & Reviews

52 reviews
5 ★
2
4 ★
0
3 ★
0
2 ★
0
1 ★
0

Compatibility

WordPress4.2+ requiredTested up to 6.3.8
PHP7.1+ required

Top Alternatives to Comment Form CSRF Protection

SameSite Cookies icon
SameSite Cookies
2.5900 installsUpdated 2 years ago
ViewCompare
Headit icon
Headit
010 installsUpdated 8 years ago
ViewCompare
View all csrf plugins →

Frequently Asked Questions

Changelog

1.0

  • Initial release.
View full changelog on WordPress.org

Contributors

Ayesh KarunaratneAyesh Karunaratne
Plugin Info
Version
1.4
Last Updated
Jul 23, 2023
WP Requires
4.2+
Tested Up To
6.3.8
PHP Requires
7.1+
Active Installs
500
Downloads
15K+
Added
Feb 21, 2019
Business
Free

Tags

csrfspamcommentssecurity

Developer

A
Ayesh Karunaratne
7 plugins0.0M+ total installs
View all plugins →

Quick Compare

Comment Form CSRF Protection vs SameSite Cookies→Comment Form CSRF Protection vs Headit→

Plugin data sourced from WordPress.org. Analysis and metrics by PluginSift.