=== Commentinel Spam Comment Cleaner ===
Tags: spam, comments, delete-comments, moderation, antispam
Requires at least: 5.6
Tested up to: 7.1
Requires PHP: 7.0
Stable tag: 1.0.0
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Find spam comments by links, author URL or SQL injection probes, then bulk delete them in one click. Clean up thousands of comments fast.

== Description ==

Adds **Comments → Spam Cleaner** to wp-admin. Pick which folder to scan, hit *Scan comments*, and every comment that matches your rules is listed with the reason it was flagged. Tick what you want (everything is pre-ticked) and apply one bulk action to the lot.

Rules included:

* **Links in the comment** — any http://, https://, www., anchor tag or BBCode link. Threshold is configurable (default: 1 link).
* **Author website field filled** — the classic link-drop signal.
* **Link inside author name or email**.
* **SQL injection / scanner probes** — `PG_SLEEP`, `WAITFOR DELAY`, `UNION SELECT`, `BENCHMARK()`, `EXTRACTVALUE()`, `information_schema`, `' OR 1=1--`, `${jndi:` and more.
* **Script / HTML injection** — script and iframe tags, `javascript:` URLs, inline event handlers.
* **BBCode links** — `[url=...]`, `[link=...]`.
* **Custom keywords** — your own list, matched against comment, author, email, website and IP.
* **Numeric or empty author name** — catches the "1" that injection scanners use.
* **Repeat IP address** — an IP with more than N comments.

Bulk actions: Move to Trash, Mark as Spam, Delete Permanently, and Approve (to clear a false positive out of the list).

Scanning and deleting run in batches over AJAX, so tens of thousands of comments will not time the request out.

Optionally the same rules can run on new submissions: send matches straight to the spam folder, or reject them outright.

== Installation ==

1. Upload the `commentinel-spam-comment-cleaner` folder to `/wp-content/plugins/`, or upload the ZIP via **Plugins → Add New → Upload Plugin**.
2. Activate the plugin.
3. Go to **Comments → Spam Cleaner**.

== Frequently Asked Questions ==

= Will it delete legitimate comments? =

Nothing is deleted until you press Apply. The "Links in the comment" rule is broad by design — a genuine visitor pasting a URL will match it, so review the list before deleting, or raise the link threshold to 2+.

= Comments from my logged-in users are being flagged =

Under **Rules & settings → Safety**, "Comments from logged-in registered users" is skipped by default. Make sure it is ticked.

= Does deleting count as permanent? =

"Delete Permanently" removes the rows from the database and cannot be undone. Use "Move to Trash" first if you want a safety net.

== Changelog ==

= 1.0.0 =
* Initial release.
