When a spam comment is the sign of a website left on its own
A client of ours who specializes in motorcycle windshields hands a site back to us after a few years; we open the dashboard and the first thing that catches the eye is not a spectacular attack, but a queue of comments awaiting moderation. Dozens of messages, from scattered IP addresses with no connection to one another, sitting there for months.
A mundane scene, and precisely for that reason a useful one. Because those comments tell us something the client usually doesn’t know: the site is exposed, and no one is watching over it.
What they really are
Automated spam. Bots that scour the web looking for open comment forms and fill them with links — to fake financial forums, to “earning opportunities”, to pages of dubious nature. The goal is to place backlinks to manipulate search engines or lure clicks toward scams.
What gives them away is their origin. In a single article we found comments from addresses like 185.202.159.140, 67.159.17.51, 174.77.111.197, 69.61.200.104 and 192.252.208.70: different networks, different operators, different geographies. No human being comments like that. It’s the typical behavior of a botnet — a network of compromised servers and machines acting in a coordinated way — or of services that rent out IPs precisely to bypass filters.
Why it matters, even if it’s not “an attack”
It must be said honestly: a spam comment is not, in itself, the first move of an intrusion. That’s not where an attacker gets in. The real reconnaissance — the activity by which someone studies how to strike a site — happens elsewhere and in silence: repeated login attempts on the login page, probes toward system files, user enumeration, fingerprinting of the WordPress version and plugins. None of this shows up in the comment queue: it leaves traces in the server and firewall logs, where almost no one looks.
So why start from the comments? Because they are the visible symptom of an invisible condition. If a site accumulates spam for months without anyone noticing, it means it has no active filter and that moderation is abandoned — and almost always that the rest isn’t watched over either: late updates, abandoned plugins, uncertain backups, logs never read. Spam is the tip that emerges; underneath is everything you don’t see. A site like this doesn’t get breached because of the comments. It gets breached because it was left alone.
What it means to watch over a site
It doesn’t mean installing a security plugin and forgetting about it. It means a series of ordinary things, done consistently: keeping WordPress, PHP, themes and plugins updated, and removing what isn’t needed, because every unused component is one more door; filtering the most targeted entry points, from the login page to the services that expose the installation; enabling a serious antispam on comments, or disabling them altogether where they bring no value; reading the logs every now and then, because that’s where reconnaissance leaves its fingerprints; and having real, verified backups, not just “enabled” and never tested.
None of these things is spectacular. Put together, they are the difference between a site that holds and one that one day stops responding.
The lesson, in one line
When we open a site and the first thing we see is a neglected spam queue, we’re not alarmed by the spam. We’re alarmed by what it implies: that for months, or years, no one was watching. And a site that no one watches is, sooner or later, a site that someone will find.
Watching over a site costs little. Fixing it afterwards costs much more.