Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To stop WordPress from saving an IP address in the comment-author IP field for new comments, use the pre_comment_user_ip filter to return an empty string. This affects that WordPress field only: it does not erase IPs already saved or control logs kept by your host, web server, proxy, security tools, or other plugins.

Prevent WordPress from saving IPs for new comments

WordPress provides the pre_comment_user_ip filter before it records a comment author’s IP. The official hook reference explains: “With this filter, we can change the comment author’s IP before it’s recorded.” Returning an empty string prevents the incoming value from being populated in WordPress’s comment-author IP field for comments processed with the filter active.

Add the filter through maintained site code

Put this callback in a small site-specific plugin or a code-snippet mechanism that you maintain. Avoid adding it to a parent theme’s files, which can be replaced by theme updates.

add_filter( 'pre_comment_user_ip', '__return_empty_string' );

The callback returns the empty string WordPress should use for the comment IP. The comment insertion function accepts the comment-author IP field, and WordPress applies the filtered value before saving it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Verify the change on your site

  1. Enable the filter using your site-specific plugin or maintained snippet mechanism.
  2. Submit a test comment through the site’s normal comment form.
  3. Inspect the saved comment record and the WordPress Comments screen. Confirm that the comment IP field is blank.
  4. Test moderation, spam handling, and comment editing with the filter active.
  5. Repeat these checks after changing comment, security, or anti-spam plugins, or after changing site code that affects comments.

These checks confirm the behavior of your installation; the hook documentation alone cannot establish how every plugin or custom integration on your site handles a blank IP.

Choose prevention, display masking, or cleanup based on the data you need to change

Approach Effect on new comment records Effect on existing comments Moderation and logging implications
Return an empty string from pre_comment_user_ip Prevents the IP value from being populated in WordPress’s comment-author IP field for new comments processed while the filter is active. WordPress hook reference; WordPress comment insertion reference. Does not change historic records. May remove information used by IP-based moderation or spam controls. Does not govern separate logs.
Change what is returned or shown for a comment Does not prevent the stored field from receiving an IP. Does not change the stored field by itself. WordPress’s comment IP retrieval function reads the saved value. Changes returned or displayed data, not the underlying record or other logs.
Clean up existing comment data Does not prevent future IPs from being stored unless paired with the pre-recording filter. Can address historic rows if performed through an appropriate database cleanup or supported erasure process. WordPress’s comment deletion function is one documented operation, but deletion is not the same as selectively clearing an IP field. Consider the effects on moderation records and any retention obligations before changing historic data.

Account for moderation and spam-control trade-offs

WordPress documentation lists IP addresses among possible comment moderation and blocklist criteria. Removing them from new comment records can therefore reduce the information available to moderators or integrations that rely on IPs. A WordPress.org support discussion describes an anti-spam compatibility issue involving the comment IP filter; treat it as a reason to test your specific setup, not evidence that every anti-spam tool will fail.

After enabling the filter, verify your own moderation queue, spam detection, and any integrations that use comment IPs. If a control depends on that value, decide whether to use a different signal or retain the value under an appropriate policy for your site.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Check other places that may retain IP addresses

This filter concerns WordPress’s comment-author IP field. It does not establish that an IP is absent from web-server, hosting-provider, CDN, proxy, firewall, analytics, or security-plugin logs. Review those services and their retention settings separately. WordPress’s privacy guidance notes that personal-data collection can involve WordPress core, themes, and plugins.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Handle existing data and privacy obligations separately

Turning on the filter does not remove addresses already saved with comments. For historic comments, plan a separate database cleanup or use an appropriate supported erasure process. A display-only change is not a storage control: WordPress can return a modified value for display while the database field remains unchanged.

WordPress identifies IP addresses as personal data and documents privacy-policy, export, and erasure tools in its privacy guidance. Those tools do not by themselves stop comment IP collection. Whether your site may retain IP addresses, and for how long, depends on your jurisdiction, purposes, and circumstances; WordPress’s documentation does not establish a universal legal retention rule.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.