Wellenbrecher

Antispam Bee alternative: what the classic covers, and what it doesn't

Antispam Bee has been the default answer to comment spam since 2009: free, privacy-minded and well maintained. Here is what its own listing says it covers, where it stops, and when an alternative is worth it.

So you know who is writing: we build Wellenbrecher, one of the alternatives here. We still rate Antispam Bee as one of the best plugins from the German-speaking WordPress community. It is free, ad-free, privacy-minded and has been maintained for more than 17 years. There is little to hold against it.

People rarely look for an Antispam Bee alternative because detection is poor. They look because spam arrives elsewhere: through contact forms, fake accounts or shop reviews. Antispam Bee is built for comments and says so openly. The general case for local over cloud checking is in our Akismet alternative comparison, so this post sticks to Antispam Bee.

Sources on Antispam Bee: its WordPress directory listing with FAQ and changelog, the pluginkollektiv documentation and the GitHub source code, retrieved on 4 October 2026. Install and rating figures: our Census, reference date 28 August 2026.

Antispam Bee by the numbers: why the classic is everywhere

Sergej Müller wrote the plugin; today the pluginkollektiv maintains it. It has been in the directory since 10 January 2009. On our Census reference date it sat in the 700,000 to 799,999 active installs band. Its rating: 4.8 out of 5 from 226 votes, against a group median of 4.7. The last release was five days before the reference date, and it is tested up to WordPress 7.1. All figures are in the Antispam Bee Census profile.

In daily use, three traits matter more. It filters straight after activation, with no account and no key. Its FAQ says it is free forever, for personal and commercial projects, on as many sites as you like. And it asks little of your server: the listing names WordPress 4.6 and PHP 5.2 as minimums, so it still runs on old hosting plans that many current plugins have left behind.

What Antispam Bee covers

The core is the comment section, and the coverage there is thorough. The feature list and documentation name these checks:

  • Honeypot: a hidden comment field that people never see and bots fill in.
  • Known commenters: anyone with an approved comment is trusted. Optionally, so is anyone with a Gravatar image.
  • Local spam database: the URL, IP and email address of a new comment are compared with comments already marked as spam in your own database.
  • Patterns: regular expressions, bundled and your own, plus a check for BBCode links.
  • Timing: a comment submitted too quickly, by default under 5 seconds according to the documentation, counts as spam.
  • Language and country: allow comments only in certain languages, block or explicitly allow commenters from certain countries.

Then there is housekeeping: spam flagged with a reason instead of deleted, old spam removed after a set number of days, email alerts, dashboard statistics and an optional log file for Fail2Ban. Trackbacks and pingbacks are checked too, and you can exclude them.

There is no CAPTCHA, a choice we share. Why image puzzles and checkbox tests are a real barrier for many people is covered in our post on CAPTCHA accessibility.

How the verdict is reached

In the source code, the checks run in sequence, and the first one that fires decides: the comment is spam, with the reason recorded. Known commenters skip the rest. That is fast, easy to follow and almost always enough for comment spam. The listing mentions no score that weighs weak signals against each other, and no observe-only mode.

Privacy-minded, with three switches you flip yourself

The listing promises spam protection without sending personal data to third parties. Out of the box, that holds: according to the default settings in the source code on GitHub, the three checks that reach outside are off. Turned on, they work like this:

  • The country check sends a shortened IP address to a geolocation service and nothing else, according to the pluginkollektiv documentation. In the current source code, that service is iplocate.io.
  • The language check sends the comment text over HTTPS to a language detection endpoint on the pluginkollektiv domain, and only for comments of ten words or more. IP and email address are not included.
  • The Gravatar check asks Gravatar, using an MD5 hash of the email address, whether a profile image exists.

That is cleanly built and openly documented. Switch one on, and your privacy policy should mention the transfer (our view as developers, not legal advice).

What Antispam Bee does not cover, in its own words

This is why people go looking for an alternative, and the pluginkollektiv is refreshingly direct about it. The FAQ in the directory listing says Antispam Bee works best with default WordPress comments, does not protect form plugins and does not prevent spam registrations.

  • Contact forms: not covered. The FAQ says the team hopes to offer better hooks for other plugins in a forthcoming major version. It gives no date.
  • Registrations: not covered. If you run a membership area, a forum or customer accounts, Antispam Bee will not keep fake accounts out.
  • WooCommerce: not mentioned in the directory listing. Whether product reviews are checked is not stated there, so we make no claim either way.
  • Comment systems in an iframe: Jetpack comments, wpDiscuz and Disqus load their form in a way Antispam Bee cannot reach. The FAQ lists them as incompatible.
  • AJAX comments: it depends on where the form posts to. If it goes to admin-ajax.php, you need a filter, and further tweaks if not all fields are sent.

Three more FAQ points are technical but trip people up in practice. Antispam Bee hides its honeypot with inline styles, so under a Content Security Policy that forbids them, the field shows up for visitors until you hide it with a filter and your own CSS. The plugin needs your visitors' real IP address, which it will not see behind Varnish or a proxy without a server configuration change. And the FAQ advises against shortening IP addresses in comment data, because the IP is the only reliable signal. Shorten IPs for privacy, and you pay with accuracy.

When Antispam Bee is all you need

Our honest advice: if your spam lands under blog posts and nowhere else, stay with Antispam Bee, especially if this describes your site:

  • Comments use the standard WordPress form, not Jetpack, wpDiscuz or Disqus.
  • There is no contact form, or your form plugin has its own spam protection that holds.
  • Registration is closed, and there is no shop.
  • Your host runs an older PHP version. Antispam Bee gets by with PHP 5.2 and WordPress 4.6 according to its listing; Wellenbrecher needs WordPress 6.5 and PHP 8.1.

A second spam plugin for a door that is already shut does not make your site safer. It makes it harder to manage.

The middle path is fine too: Antispam Bee for comments, plus a form plugin with its own local protection. How the common form plugins deal with spam is in our Contact Form 7 alternative comparison. The catch only shows over time: two settings screens, two sets of logic, two places where a real customer can get stuck.

When an alternative is worth it

The most common trigger is the contact form. Antispam Bee cannot help, and the reflex is often reCAPTCHA, which brings in exactly what Antispam Bee avoids for comments: an outside service in your form, with the privacy and consent questions attached. False positives also cost more here. A lost comment is annoying. A lost enquiry can be a lost job.

The second trigger is fake accounts in a membership area, in shop customer accounts or on a multisite with open registration. According to its FAQ, Antispam Bee does not guard this door. As for WooCommerce reviews, which are public and shape buying decisions, the listing does not say whether they are checked. If you need certainty there, pick protection that names the channel explicitly.

Wellenbrecher as an alternative: what it does differently

Like Antispam Bee, Wellenbrecher works locally and without a CAPTCHA, but it is built for more entry points. The product page lists these channels:

  • Comments and trackbacks, optionally with XML-RPC comments and pingbacks switched off.
  • Registrations in WordPress, multisite and WooCommerce.
  • WooCommerce product reviews, with a trust bonus for verified buyers.
  • Leadlotse forms, with quarantine and one-click restore.
  • Newsletter sign-ups through Kurato, before a bot subscription is created.

Which form plugins from other vendors are connected, and how deeply, is listed one by one in the Wellenbrecher directory listing.

The bigger difference is how the verdict is reached. Instead of a chain of single checks, every submission gets a score built from many signals: an accessible honeypot, a time trap, JavaScript signals, a list of 8,143 disposable email domains and more rules. Three zones decide what happens: let it through, hold it in quarantine, or block it. Each rule can be switched off or reweighted, and you set the thresholds with a slider. Weak signals on their own never reach quarantine.

Three things help when you switch. For the first seven days, observation mode logs everything and blocks nothing. Every decision lands in the block log with its reason. And if the plugin hits an internal error, the submission goes through to normal moderation, never into a silent block.

On privacy, Wellenbrecher keeps its own log lean. There, an IP never appears in plain text, only as a non-reversible HMAC value under a key that changes weekly. Of email addresses, only the domain is stored. Blocked entries are deleted after 7 days, quarantine after 30, both adjustable. The version from the WordPress directory makes no outbound request at all. Outside checks such as GeoIP and ASN, AbuseIPDB or an AI second opinion exist only in Pro, each one opt-in, much like Antispam Bee's three optional checks.

Free costs nothing and is explicitly fine for commercial use. Pro is 19 € a year for one site, Fleet 69 € a year for ten sites, both excluding VAT; the pricing page lists what each tier includes.

Where Wellenbrecher is weaker

Wellenbrecher has been in the WordPress directory since 21 August 2026, Antispam Bee for more than 17 years. A young plugin has not been tested on as many sites. Its minimum requirements are much higher, WordPress 6.5 and PHP 8.1. If your theme renders the comment field itself, the honeypot and field-swap signals drop out, while all other rules keep working. If you use a page cache or a CDN, exclude the plugin's token route from caching.

Also, Wellenbrecher is not a security plugin. Login protection, a firewall and hardening belong in another tool; our comparison of WordPress security plugins covers the options. Both plugins check locally and therefore share one limit: neither has a network-wide reputation that spots a fresh spam wave across thousands of sites at once.

Comparison table

CriterionAntispam BeeWellenbrecher
Comments and trackbacksyesyes
Contact formsno, per its FAQyes, Leadlotse natively, others per directory listing
Registrationsno, per its FAQyes, WordPress, multisite, WooCommerce
WooCommerce reviewsnot mentioned in listingyes, with a bonus for verified buyers
CAPTCHA, outbound requests by defaultnonenone
Optional outside checkscountry, language, GravatarPro only: GeoIP/ASN, AbuseIPDB, AI second opinion
Verdictfirst check that fires, with a spam reasonscore with three zones, including quarantine
Observation modenot mentioned in listing7 days
IP addressesmatched against spam in your own database, shortening not advisedstored in the log only as an HMAC
MinimumWordPress 4.6, PHP 5.2WordPress 6.5, PHP 8.1
In the directory since10 January 200921 August 2026
Pricefree, commercial use included, unlimited sitesFree 0 €, Pro 19 € a year, Fleet 69 € a year for 10 sites

For scale, Census figures for the best-known spam plugins (reference date 28 August 2026):

PluginActive installsRatingIn the directory since
Akismet5,000,000 to 5,999,9994.7 from 1,18620 October 2005
Antispam Bee700,000 to 799,9994.8 from 22610 January 2009
CleanTalk200,000 to 299,9994.8 from 3,20818 May 2012

How to decide

Start by checking where your spam comes from. If it sits only in the comment queue, Antispam Bee is a very good choice and switching gains you little. If it arrives through forms, sign-ups or the shop, you need a second solution either way, and one plugin that checks every entry point with the same logic is the tidier answer. You do not have to arm Wellenbrecher right away: observation mode shows you for a week what it would have blocked.

Spam protection for every entry point, checked locally

Wellenbrecher checks comments, forms, registrations and WooCommerce reviews on your own server: no CAPTCHA, no outbound request in the directory version, and seven days of observation mode before you arm it.

Take a look at Wellenbrecher

Frequently asked questions

Is Antispam Bee free for commercial websites?

Yes, according to its FAQ in the WordPress directory, Antispam Bee is free forever, for personal and commercial projects alike. There is no limit on the number of sites and no paid tier. You do not need an account. Support runs only through the wordpress.org forum, not by email.

Does Antispam Bee protect contact forms?

No, by its own FAQ Antispam Bee does not protect form plugins and does not prevent spam registrations either. It works best with default WordPress comments. The team hopes to offer better hooks for other plugins in a forthcoming major version, without a date. Until then, forms need protection of their own, either from the form plugin or from a spam filter that covers forms.

Is Antispam Bee GDPR compliant?

Out of the box, Antispam Bee sends no data to third parties, and its directory listing describes it as fully GDPR compliant. Three optional checks do reach outside: the country check sends a shortened IP, the language check the comment text, the Gravatar check a hash of the email address. All three are off by default. If you switch them on, your privacy policy should mention them. That is our assessment, not legal advice.

Does Antispam Bee work with WooCommerce?

The Antispam Bee directory listing does not mention WooCommerce. Whether product reviews are checked cannot be read from it. According to its FAQ, the plugin does not prevent spam registrations in general, and that includes customer accounts. If you want to protect shop reviews and sign-ups, a plugin that names those channels explicitly is the safer pick.

What is the difference between Antispam Bee and Wellenbrecher?

Both check locally and without a CAPTCHA, but Antispam Bee covers only comments and trackbacks, while Wellenbrecher adds forms, registrations and WooCommerce reviews. Antispam Bee decides on the first check that fires; Wellenbrecher uses a score, a quarantine and a seven-day observation mode. Antispam Bee runs on PHP 5.2 and dates back to 2009. Wellenbrecher needs PHP 8.1 and WordPress 6.5 and was listed in August 2026.

Back to blog A post by hafenstudios