CommentAura

Description

CommentAura turns the native WordPress comment section into a modern discussion experience, without taking your data hostage.

Everything is stored in wp_comments and wp_commentmeta, exactly where WordPress puts it. Deactivate CommentAura and every comment, every reply, and every permalink still works. That is not a migration path — it is the architecture.

Built on three promises

1. Zero lock-in. Your comments are native WordPress comments. No iframe, no external service, no account for your visitors, no export step if you leave. Uninstalling removes CommentAura’s own data and never touches a single comment.

2. It works without JavaScript. The comment thread is rendered on the server, in your page’s HTML. Search engines index it. Readers with slow connections see it. Screen readers read it. Reading, posting, editing, voting and reacting all work as plain form submissions. JavaScript only makes them faster: a half-kilobyte script loads with the page, and the rest — including WordPress’s own React library — loads only when a reader scrolls near the comments. You can switch it off in Settings.

3. No ads, no trackers, no third-party requests. CommentAura sends nothing to anyone. There is no analytics beacon, no CDN call, no « sponsored » content injected into your discussions.

What you get

  • A comment section that feels familiar — soft comment bubbles, a quiet Like · Reply · time row, Top / Newest / Oldest sorting, and a « ⋯ » menu that keeps moderator tools out of readers’ way
  • 3D reactions people already know: Like, Love, Care, Haha, Wow, Sad and Angry by default. Rest on Like, long-press on a phone, or use the keyboard. Choose which of 16 faces appear, their order, their names and their icons — or add your own
  • Threaded discussions that work with both classic themes and block/full-site-editing themes
  • Comment subscriptions with proper double opt-in — nobody is emailed until they confirm, and every notification carries a one-click unsubscribe
  • Voting, one switch away in Settings, with duplicate prevention enforced by the database rather than hopeful bookkeeping
  • Comment editing for a configurable window, with every revision retained so moderators can always see what a comment used to say
  • Pinned comments and per-post discussion closing
  • A spam baseline — honeypot and timing checks, no CAPTCHA. CAPTCHAs tax every honest reader to inconvenience a bot that can solve them for a fraction of a cent. Works alongside Akismet if you use it.
  • Rate limiting that does not punish shared networks. WordPress core matches floods on IP or email, so two unrelated visitors behind one office or mobile network block each other. CommentAura keys on identity and address together.
  • Full GDPR support — registered with WordPress’s own personal-data exporter and eraser.
  • Privacy by construction — guest identities are stored as a one-way salted hash, never as a raw IP address.

Moving in, and moving out

Under CommentAura Import / Export:

  • Import from Disqus. Point it at a Disqus export file. Threads are matched to your posts by URL — including your old domain, since a move away from Disqus usually follows a domain change — and a discussion that cannot be matched is skipped rather than attached to the wrong post. Re-running the same file imports nothing twice.
  • Dry run first, always. Every import previews exactly what it would do before anything is written. That is the default.
  • Switch from another comment plugin. Your comments need no migration at all — wpDiscuz, Jetpack Comments and Subscribe to Comments Reloaded all store them in wp_comments already, which is where CommentAura reads from. What those plugins keep in their own tables is the material around the comments, so CommentAura brings across the part that would otherwise be lost: subscriber lists and votes. Nothing is deleted from the other plugin, and running it twice does not double anything.
  • Export every comment as JSON, streamed in batches so the size of your site does not decide whether the export finishes.

Note that Disqus exports produced since 2019 contain no email addresses and no IP addresses for guest commenters. CommentAura preserves the display name, imports with an empty address, and tells you how many were affected rather than letting you find out from a support ticket.

Performance

A page with CommentAura active but no comment thread loads zero CommentAura assets. Not a small file — none.

A page with a thread loads about 10 KB (compressed) until a reader reaches the comments. Everything CommentAura itself ships comes to about 19 KB. WordPress’s own React library, which the interactive parts use, loads only when the comments come into view. Reaction faces are small images, about 1 KB each, loaded only when they are shown.

Rendering a thread costs a fixed number of database queries regardless of how many comments a post has, because replies are fetched per level rather than per comment. A post with 10 comments and a post with 10,000 cost the same.

Credits

The reaction faces are Fluent Emoji by Microsoft (https://github.com/microsoft/fluentui-emoji), used under the MIT licence. The licence ships with the plugin in assets/reactions/LICENSE.txt. The faces are bundled inside the plugin; nothing is loaded from Microsoft or anyone else.

Developer friendly

  • A documented REST API under commentaura/v1
  • Every template is an overridable partial you can copy into your theme
  • Named callbacks throughout, so hooks can actually be removed
  • PSR-4, PHP 8.1+, strict types, PHPStan level 8
  • The readable source of every script ships in assets/src, next to its build in assets/build

Source code

The scripts in assets/build are compiled from assets/src with @wordpress/scripts 30, using the webpack.config.js included in the plugin. To rebuild them, run npm install @wordpress/scripts@30 and then npx wp-scripts build in the plugin folder.

Optional paid add-on

Everything described on this page is free and stays free. A separate paid plugin, CommentAura Pro, sold at https://waafaa.com/product/commentaura/, adds tools for the people who run the discussion: a moderation queue, rules, AI triage and analytics. It is never needed to use anything in this plugin.

Screenshots

Installation

  1. Install the plugin through Plugins Add New, or upload the folder to /wp-content/plugins/.
  2. Activate it.
  3. That is it — your existing comments are already there.

Optional settings live under CommentAura Settings in your admin menu. There are deliberately few of them.

FAQ

Will I lose my comments if I deactivate this?

No. This is the entire point of the plugin. Comments live in WordPress’s own tables the whole time. Deactivate CommentAura and your theme’s normal comment display returns, with every comment, reply, and link intact.

Does it work with page caching?

Yes. The thread is rendered into the page itself and sets no cookies, so a post with comments caches exactly like a post without them. Posting goes through WordPress’s own comment handler as a normal form submission, which is never served from a cache — so commenting works on a fully cached page without the plugin having to punch a hole in it.

Does it work with block themes?

Yes. CommentAura integrates with both the classic comments_template() path and the block editor’s core/comments block, and produces identical output through either.

Do my visitors need JavaScript?

No. Reading, posting, editing, voting and reacting all work with JavaScript disabled. With JavaScript, those happen without a page reload, replies open under the comment you are answering, and an unsent draft is kept in your browser.

Does it send data anywhere?

No. There are no third-party requests of any kind.

Can I choose the reactions?

Yes. Under CommentAura Settings Engagement Reactions you switch faces on or off, drag them into order, rename them, swap their icons and add your own, with a live preview beside the settings. One face on its own turns the bar into a simple Like button. Stored reactions are never lost: a face you switch off keeps its counts and brings them back when you switch it on again.

Where are votes and reactions stored?

In CommentAura’s own tables, because they do not fit WordPress’s comment schema. Your comments themselves are never copied, shadowed, or moved.

Is there a CAPTCHA?

No, and that is deliberate. CommentAura uses an invisible honeypot and a timing check instead, which cost your readers nothing.

Reviews

There are no reviews for this plugin.

Contributors & Developers

“CommentAura” is open source software. The following people have contributed to this plugin.

Contributors

Translate “CommentAura” into your language.

Interested in development?

Browse the code, check out the SVN repository, or subscribe to the development log by RSS.

Changelog

1.0.0

A new, familiar look with 3D reactions. Comments now work without page reloads, and two bugs that made comments look lost are fixed.

  • New: A redesigned comment section: soft comment bubbles, a quiet Like, Reply and time row, and a « ⋯ » menu that keeps moderator tools out of readers’ way.
  • New: 3D reactions. Rest on Like, long-press on a phone, or press Enter to open a bar of faces. Each person holds one reaction per comment.
  • New: Reaction settings under Engagement. Choose from 16 faces or add your own, reorder, rename and swap icons, with a live preview.
  • New: Sort comments by Top, Newest or Oldest.
  • Improved: Voting is off by default on new sites, because reactions are now the main feedback. Existing sites keep voting as they had it.
  • New: Voting, reacting, replying, editing and loading more comments now happen in place, without reloading the page. Everything still works with JavaScript switched off.
  • New: A comment box with a formatting toolbar and keyboard shortcuts, and an unsent comment is kept in your browser if you leave the page by accident.
  • New: Long reply chains fold behind « View more replies ».
  • Improved: A cleaner, simpler look for every CommentAura admin screen and a tighter comment thread, with far less text to read.
  • New: A setting to switch the interactive parts off, which leaves no CommentAura script on any page.
  • New: An Upgrade page, last in the CommentAura menu, describing the optional paid add-on. There are no notices or banners anywhere else.
  • Improved: Signed-in visitors see one short « Signed in as » line above the comment box.
  • Improved: When a visitor edits an approved comment, the new text goes through the same spam and moderation checks as a new comment.
  • Fixed: Held, spam and trashed comments can no longer be voted on or reacted to.
  • Fixed: A spam comment no longer sends a subscription confirmation email, and a pending subscription is re-sent at most once a day.
  • Fixed: Disqus imports from the Import / Export screen were refused with « Sorry, you are not allowed to upload this file type ».
  • Fixed: A guest who did not tick « Save my name » could not see their own comment while it waited for moderation, so it looked lost.
  • Improved: Long threads render faster: replies are fetched once per level instead of once per comment.
  • Improved: The plugin’s homepage link now points to waafaa.com/product/commentaura/.
  • Developers: New filters commentaura_island_scripts (load an add-on’s own script the same lazy way) and commentaura_collapse_after.
  • Developers: New filters commentaura_reaction_icon and commentaura_reaction_set_for_post, and the commentaura_reaction_settings_rendered action for adding fields to the Reactions settings.

0.2.0

Opens CommentAura to add-ons, and fixes one way a vote could count twice.

  • Fixed: A visitor who votes as a guest and then logs in now holds one vote, not two.
  • Improved: The plugin’s homepage link now points to waafaa.com/plugin/commentaura/.
  • Developers: New commentaura_loaded action. Add-ons receive the objects that own CommentAura’s callbacks, so they can replace one with remove_action().
  • Developers: New actions commentaura_vote_cast, commentaura_reaction_set, commentaura_subscription_confirmed and commentaura_subscription_removed. None of them passes who acted.
  • Developers: New filter commentaura_comment_action_types adds links to every comment’s action row, and commentaura_thread_args sets page size, sort order and whether held comments are shown.
  • Developers: Add-ons can queue their own background jobs with the commentaura_enqueue_job action.

0.1.0

Released 16 September 2026. The first public release.

  • New: Threaded comments for classic and block themes, with sorting, permalinks and pagination.
  • New: Guest commenting that works on fully cached pages.
  • New: Comment editing, with every earlier version kept for moderators.
  • New: Voting and reactions, with duplicates blocked by the database.
  • New: Pinned comments and per-post closing.
  • New: Reply notifications and subscriptions, with double opt-in and one-click unsubscribe.
  • New: Disqus importer, and migration of subscribers and votes from wpDiscuz, Jetpack Comments and Subscribe to Comments Reloaded. Every import runs as a dry run first.
  • New: Export of every comment as JSON.
  • New: Spam baseline (honeypot and timing check, no CAPTCHA) and rate limiting that does not block shared networks.
  • New: GDPR personal-data export and erasure, and a clean uninstall that never touches your comments.
  • New: REST API under commentaura/v1, hooks, and templates you can override in your theme.
  • New: A CommentAura admin menu with Dashboard, Settings and Import / Export screens.
  • New: Everything works with JavaScript switched off, and nothing is sent to any third party.