EP Comments
EP Comments is a proper comment system for PageMotor. Database-backed, admin moderation queue, threaded replies with email notifications, spam protection via honeypot and rate limiting, Gravatar avatars, and a WordPress-to-PageMotor comment import path.
Published by ElmsPark Studio.
Overview
Section titled “Overview”Comments attach to pages via a shortcode. Each page has a content-options toggle to enable or disable comments on that specific page, so you can let readers comment on blog posts but not on sales pages.
Features:
- Threaded replies. Reply to a comment and the parent commenter gets an email.
- Moderation queue. New comments start as pending by default. Admin reviews, approves, or rejects.
- Auto-approve option for sites where moderation is overkill, plus trusted returning commenters detection so regulars don’t queue every time.
- Honeypot spam protection on the form.
- IP-based rate limiting with a configurable interval.
- CSRF protection via double-submit cookie.
- Gravatars with initial-based fallback for commenters without one.
- Schema.org DiscussionForumPosting structured data for SEO.
- WordPress comment import from JSON so you can bring years of discussion across.
- Auto-close comments on posts older than N days.
Requirements
Section titled “Requirements”- PageMotor 0.8.2b or later
- EP Suite base class (bundled)
- EP Email (optional but recommended for styled notification emails; without it, the plugin falls back to PHP’s
mail())
Installation
Section titled “Installation”ep-comments.zipcomes with an EP Suite licence — ElmsPark supplies it directly (see EP Suite plugins); after install it updates through your site’s Updates screen.- Upload via Plugins → Manage Plugins. Activate.
- Drop the
[comments]shortcode on any page where you want comments.
Shortcodes
Section titled “Shortcodes”| Shortcode | Purpose |
|---|---|
[comments] | Full comment list for the current page, plus the submission form. |
[comment-form] | Form only, no list. Useful if you want the form above the list (default is below). |
Per-page comment toggle
Section titled “Per-page comment toggle”On any page’s content options:
- Enable comments. Checkbox. Default can be set globally; this overrides per page.
Pages without comments enabled won’t render the [comments] shortcode, even if the shortcode is present in the content.
Settings reference
Section titled “Settings reference”Accessed through EP Suite nav → Comments.
| Setting | Purpose |
|---|---|
| Admin notification email | Where admin-alert emails go when new comments are submitted. |
| Auto-approve | On: comments appear immediately without moderation. Off: comments queue for admin review. |
| Trusted returning commenter detection | When a commenter has N previously-approved comments under the same email, subsequent comments auto-approve even if global auto-approve is off. |
| Honeypot | On by default. Adds a hidden form field that bots fill but humans don’t. Submissions with the honeypot populated are rejected silently. |
| Rate limit interval | Seconds between comments from the same IP. Default 60. |
| Comments per page | Pagination size. Default 20. |
| Display order | Newest first or oldest first. |
| Auto-close after N days | Locks comments on pages older than this. |
Moderation dashboard
Section titled “Moderation dashboard”The admin dashboard lists every comment with:
- Filtering by status (Pending / Approved / Spam / Trash).
- Search by commenter name, email, or body text.
- Pagination.
- Bulk actions: approve, unapprove, mark as spam, trash, delete permanently.
Clicking a comment shows full context including the commenter’s history on your site.
How replies work
Section titled “How replies work”A commenter clicks Reply under any approved comment. Their reply is submitted with a parent_id reference. When approved:
- The reply is rendered nested under its parent in the comment list.
- The parent commenter gets an email notification telling them their comment was replied to, with a link back to the page.
Spam protection layers
Section titled “Spam protection layers”Three layers, applied in order:
- Honeypot. If the hidden field has a value, the submission is rejected. Most bots fill every field.
- Rate limit. Same IP cannot post faster than the configured interval.
- CSRF via double-submit cookie. Cross-site forms posting to your comments endpoint are rejected.
Bots that pass all three are rare. If you see any that do, they go through moderation (unless auto-approve is on) so no damage is done.
Gravatars
Section titled “Gravatars”The plugin looks up each commenter’s email against Gravatar. If they have one, their avatar renders next to their comment. If they don’t, a coloured initial-letter circle renders instead (based on the first letter of their name, with a deterministic background colour).
WordPress comment import
Section titled “WordPress comment import”From the settings page:
- Export your WordPress comments to JSON via a tool like WP All Export.
- Paste or upload the JSON into EP Comments’ import panel.
- Review the preview, click Import.
Imported comments are stamped with an import_batch_id. If something goes wrong, you can delete every comment from a specific import in one operation via the Import History panel.
Troubleshooting
Section titled “Troubleshooting”“Comments don’t appear on any page”
Section titled ““Comments don’t appear on any page””Check the page has Enable comments ticked in its content options, and that the [comments] shortcode is actually in the page body.
“Admin notifications aren’t arriving”
Section titled ““Admin notifications aren’t arriving””Install and configure EP Email. The plugin’s own mail() fallback often fails on modern hosts because raw PHP mail() is blocked or spam-filtered. EP Email with proper SMTP fixes this.
“Commenter got a reply notification for a reply to their own comment”
Section titled ““Commenter got a reply notification for a reply to their own comment””That’s the design — someone replied to their comment, they should know. If you don’t want that for some category of replies, the feature request can go in the review queue.
“All new comments are queuing as pending even though I turned auto-approve on”
Section titled ““All new comments are queuing as pending even though I turned auto-approve on””Check the global auto-approve setting saved correctly. Also check the trusted-returning-commenter threshold is 0 or low; if it’s high, first-timers still queue.
“A specific commenter keeps being marked as pending despite being trusted”
Section titled ““A specific commenter keeps being marked as pending despite being trusted””They may be submitting from different email addresses or different IPs. Trust is tied to email + approved history. Same commenter with three emails has three trust records.
“Spam is still getting through”
Section titled ““Spam is still getting through””Drop the rate limit to 120 or 300 seconds. Investigate specific IPs with the moderation dashboard’s IP filter and block persistent offenders at the nginx or Cloudflare level.
Feedback and corrections
Section titled “Feedback and corrections”For a quick question about this plugin, EP Support inside your admin is the fastest option. The chat widget sits on every EP plugin settings page and knows which one you’re on, with starter questions and links preloaded for that exact screen.
For anything bigger — a bug report, a feature request, or a “how do I…” that needs a real reply — open a ticket at help.elmspark.com. A real person, helped by AI, writes the reply. Usually within a few hours. Tickets don’t disappear into the void.
Changelog
Section titled “Changelog”1.1.20
Section titled “1.1.20”- Settings language menu. The language menu in this plugin’s settings now lists only the languages it is actually translated into, plus English, so you can no longer pick a language that changes nothing.
1.1.19
Section titled “1.1.19”- New-comment emails name the right page again. The email you receive when someone comments said the page was “Unknown” on PageMotor 0.9 and later. It now shows the page’s title.
- No settings change and nothing to do after updating.
1.1.18
Section titled “1.1.18”- Fixes a crash on the comment form when an older EP plugin is installed on the same site. Submitting the form returned an internal error and nothing was saved or sent. EP plugins share one common code library, and whichever copy loads first is the one every EP plugin on that site uses, so a single out-of-date plugin could leave this one calling a spam check its copy did not have. The check now carries its own fallback and no longer depends on another plugin being up to date.
- No change on a site where this never happened: the same spam check runs, and nothing else changed.
1.1.17
Section titled “1.1.17”- Blocks a spam bot that was getting past the form honeypot. The scraper changed its network address on every single request, so blocking by address never caught it, but it always sent a malformed browser identifier that no real browser sends. Forms now reject anything carrying that signature, with the same silent response a caught bot already got.
- It was not theoretical. One client site had taken 57 fake signups before this went in, and the same bot had hit 17 sites.