=== Delta Dev Comment Lockdown ===
Tags: disable comments, comment security, pingbacks, rest api, hardening
Requires at least: 6.0
Tested up to: 7.1
Requires PHP: 7.4
Stable tag: 1.0.0
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Lock down the WordPress comment attack surface with layered protections while preserving existing comment data.

== Description ==

Delta Dev Comment Lockdown is a security-focused comment attack-surface hardening plugin developed by Delta Dev for WordPress sites that do not need the native comment system.

Instead of only hiding a comment form, the plugin applies multiple independent WordPress-native protection layers. It closes public commenting, blocks direct and core comment creation paths, removes core REST comment routes, disables comment-related XML-RPC/pingback surfaces, blocks comment feeds, and can remove related admin surfaces. It does not modify WordPress core files and it does not delete existing comments.

Default protections include:

* Forces comments closed on the public site.
* Hides existing comments without deleting them.
* Blocks normal WordPress comment submissions with HTTP 403.
* Stops new comments in the core comment approval pipeline.
* Removes and blocks the core REST API `/wp/v2/comments` endpoints.
* Disables pingbacks and trackbacks.
* Removes WordPress XML-RPC comment and pingback methods.
* Removes the `X-Pingback` response header.
* Disables comment-feed discovery links and direct comment-feed requests.
* Removes Comments and Trackbacks support from registered post types.
* Hides the Comments admin menu, toolbar item, and Recent Comments dashboard widget.

All protections can be configured from **Settings > Comment Lockdown**. Strict protection is enabled by default.

= Security design =

* Uses WordPress core hooks and APIs instead of modifying core files.
* Uses a defense-in-depth approach so disabling a theme comment form is not the only control.
* Settings are restricted to administrators with `manage_options`.
* Settings are saved through the WordPress Settings API and sanitized to strict boolean values.
* Admin output is escaped before rendering.
* No arbitrary code execution, file manager, remote executable downloads, telemetry, licensing gate, or external service is included.

= Privacy =

Delta Dev Comment Lockdown does not collect, store, transmit, or sell personal data. It does not use analytics, telemetry, cookies, external APIs, or third-party services.

= Compatibility note =

Some plugins use the native WordPress comment system for other features. WooCommerce product reviews are a common example. Enabling all protections can disable those comment-based review flows.

== Installation ==

1. In WordPress, go to **Plugins > Add Plugin > Upload Plugin**.
2. Upload the Delta Dev Comment Lockdown ZIP file and activate the plugin.
3. Open **Settings > Comment Lockdown**.
4. Keep all options enabled for a strict site-wide comment shutdown, or adjust individual protections as needed.

== Frequently Asked Questions ==

= Does the plugin delete existing comments? =

No. Existing comments remain in the WordPress database. They can be hidden publicly while the plugin is active.

= What happens after deactivation? =

All runtime protections stop. Existing WordPress comment data is left unchanged.

= Does this block REST API comments? =

Yes. The plugin removes the core comment endpoints and also blocks matching requests as a defense-in-depth measure.

= Does it disable XML-RPC completely? =

No. It removes comment and pingback XML-RPC methods while leaving unrelated XML-RPC functionality available for plugins or services that may still need it.

= Does it affect WooCommerce product reviews? =

It can. WooCommerce product reviews use the WordPress comment system. If you need product reviews, do not enable protections that conflict with your review workflow.

= Does the plugin send data to Delta Dev? =

No. The plugin has no telemetry, tracking, external API calls, or phone-home functionality.

== Changelog ==

= 1.0.0 =
* Initial public release.
* Added frontend comment shutdown.
* Added direct submission and core comment insertion protection.
* Added REST API comment blocking.
* Added pingback, trackback, XML-RPC, and comment-feed protection.
* Added configurable admin UI controls.
* Added privacy-friendly, no-telemetry defaults.
