Hello,
We’re trying to set a meta tag (noindex) for several BuddyPress pages (like Members) via Yoast SEO. But these settinsg don’t seem to be picked up.
It looks like BuddyPress adds the following tag:
<meta name=”robots” content=”max-snippet:-1, max-image-preview:large, max-video-preview:-1″/>
Is there a conflict between BuddyPress and Yoast SEO? How could we solve this?
or try “All In One WP Security & Firewall”
There are several options that will protect you from bots
I thought Askimet was just for comments – can you also configure it for private messages? I do have it set up and running right now, along with Wordfence, a reCaptcha V2 on registration form (and for bbPress), and a BuddyPress Private Message Rate Limiter.
Right now I’m using these plugins:
– Askimet
– Wordfence
– Advanced noCaptcha & invisible Captcha (On registration form)
– Anti-Spam by CleanTalk
– BuddyPress Private Message Rate Limiter
It helps, but apparently not enough – just had a user sign up last night, receive a spam message, and request to have their account deleted this morning. It’s obviously frustrating, so if Askimet could be doing something extra that I just haven’t configured it for, that would be great…
But I’m not sure how it could even successfully flag the messages based on content? Some are very bland “Hi Dear, I like you profile and would love to talk, please contact me privately via e-mail at xxxxxxxx ” Which don’t seem that different from legitimate messages, except that they’re being sent out en masse from users with profiles that say they’re in US, but with IP’s in Africa, etc.
Does anyone know if these same bots would also send out mass friend requests? I remember seeing a mention of restricting private messaging to friends, which might be my next step… But I don’t want to implement an additional hurdle for users if the bots would also just abuse that. 🙁
Sorry for the long post, but thanks for any help!
That’s an interesting idea. What about using the Akismet anti-spam service to check the content of the message?
I’ve also had bots send spam messages via private messaging, and it’s a pain once it gets started.
Spambots created 81K groups on a client’s BP site. I assume I need to delete them from the database, as it will take too long to delete them in wp-admin.
There are no other groups on this site, so I need to delete all groups.
If I am deleting them from the db using phpmyadmin, what do I need to do to make sure I delete all their data without touching other data?
Is there a better way to delete all 81K groups?
Hi,
For evryone that experienced the same with the user with same ip adress in failed login report I found an soloution.I installed many security plugin even bought some but the problem was still there. Then One day I started to do 2 things. First I removed all the page that where not necessairy for my site. Second what I did was I removed couple plugins that where there but just in deactivation mode. Those 2 combination did the trick. Ore there was a plugin that was doing strange things ore it got confused off all the diffrente page in the background that i didnd’t needed. I easily removed 30 page.
I hope one day if a person experience the same problem as me that this can guide him to a solution.
For all the spambots, for me the All In One WP Security & Firewall helped really well to block spambots even before it could enter my site.
greetings
Thanks for your suggestion, @wasanjones. Google Search Console told me that some of the member pages have been indexed despite being blocked by my robots.txt
So I still keep my fingers crossed that the BuddyPress-Team will soon figure out how to solve this issue by changing the core code or whatever solution might work.
Hi,
Could you help me ore give advice? I would like to find a plugin ore a way to track malicious code. A couple a weeks ago i noticed many spambots where getting true my security messures. I become suspicous when i noticed spam was created as a new group by the admin (me). I clicked on the icon of group admin that created the new spam group and it came back to my profile. So i started to do some investigation. Looking in the all in one security I noticed under failed login another user with my ip adress. This user had a bizare name (93e60…) During last 2 weeks he/she changed alot his/here username. Im 100 % shure that i’m the only person at home that use the site. It’s remarkable The user with my ip adres has no email adres in the all in one security. Anoter plugin i installed was stop spammers. It confirmed that an author with my ip adress by the name (93e60…) had a good cache in /wp-login.php, again there was no email adres.
Did someone placed malicious code on my site? How can it be that they use my ip adress? I did a virus scan on my pc. Nothing was found. I contacted my host. They did a malware scan on the site, nothing was found. But the user with my ip is still there. I don’t know what to do, could you give me advise? Is there a plugin that could help, one that can track bad codes?
Thank you very much
you should be able to use robots.txt to prevent indexing of specific pages too.
not sure about member profiles — but I think a /members/* wildcard (properly written) should work
@venutius oh thanks for the suggestions, appreciate the plugin links…but they don’t accomplish what i need to do
i need specific avatars for classes of users, ones that correspond to the styling and hierarchy of my site
so identicons being ‘fun’…? sadly i don’t need fun, lol….i need a streamlined business look and fun with random identicons won’t work
and creating local gravatar avatars for users that ‘don’t have one’ is also random — not corresponding with my site; if i wanted to have default gravatar avatars populate i’d just choose the options that come with WordPress by default — that already is an option
and gravatar is incredibly cumbersome with its pinging to the servers where the gravatars are stored….it may seem minor to many, but it does burden a site
plus, gravatars have weak coding that allow the email address of the user to be ‘scraped’ by bots
so to protect my users from future spam and to keep my site as speedy as possible AND to have my site avatars correspond to the styling of my site i need gravatars to never ever ever be used, and nothing random either
Ah great! Glad that one is solved. It’s only half of the solution though. These bots will still plague your site with registration requests. To get rid of those try https://wordpress.org/plugins/simple-google-recaptcha/ thi sworked like a treat on my sites, totally eliminating spam bot registrations (for now…).
hi there,
could someone please help with some code to set buddypress members profile pages and profile tabs to noindex? (without using robots.txt)
thanks a lot!
br, Eric
Perfect would be to make it flexible enough that you can fetch from many social networks and not only from Reddit.
I’m not really sure how these bots work on Slack or Discord. Maybe I can try to figure that out and that might shed some light on a possible implementation in buddypress.
> Why you didn’t tried it with jquery ?
Maybe search robots will not run JavaScripts.
Is there a way to automatically post in a specific Buddypress group when a post is created in a specific subreddit? I’ve seen. Any bots do this in discord or slack, so I was wondering if there’s something similar for Buddypress.
Not to sound harsh or anything but Im not bothered about people from outside the UK/ USA… English speaking countries signing up to my website as most of the time they are just bots.
Is there any functions.php I could add to block signups from IP ranges outside uk and USA.. or any other English speaking country?
I would hope this would drastically reduce spam sign-ups for me.. as even with akismet, and google ReCaptcha bots still make it through.
Thank you.
Buddypress installs, but has no functionality.
Hosting on local server/system
Ubuntu 18.04 LTS
Net-tools
Mysql
Apache2
php-curl php-gd php-mbstring php-xml
Wordpress 4.9.6
Buddypress 3.0.0
Fresh install of OS, WordPress, and Buddypress – The only plugin installed before Buddypress was ‘All In One WP Security’ (using only it’s default settings) to prevent bots/spam. De-activating WP Security plugin, and then uninstalling/reinstalling Buddypress does not solve the problem.
Wordpress – Directory install
Buddypress path – /user/share/wordpress/wp-content/plugins/buddypress/
Wordpress works fine on it’s own – default WordPress theme Twenty-seventeen
* The following code was added to wp-config:
define(‘FS_METHOD’, ‘direct’);
define(‘WP_HOME’, ‘http://MySiteName.com’);
define(‘WP_SITEURL’, ‘http://MySiteName.com’);
define(‘WP_MEMORY_LIMIT’, ‘256M’);
* Buddypress: installs, activates, and creates it’s blank pages (Registration, Activation, Members, Activity…) but all pages return 404 errors.
* I do see the ‘Welcome to Buddypress’ splash page, and under Dashboard>Settings>Buddypress, all options are available, but have no effect on the installation. It’s as if Buddypress and WordPress are sharing the same space, but are not interacting. I do not find ‘Buddypress Theme’ in my dashboard either.
Thank you for your time.
Phishing bots are spamming users on my site with private messages and its doing my head in lol!
Everyday I get a new user that bypasses akismet and google recapcha doesnt post anything but starts spamming private messages to people.
How can I make it so only friends can send private messages to each other?
Also is there a way to auto delete accounts that are bots which sign up and dont post naything after a certain period of time?
Thanks.
TParticipant
Hello,
It appears that myself and many many others have succumb to the issue where new registrants get the activation email, but it directs them to the red “invalid activation key” error.
The key does not show up in the database (phpmyadmin).
There needs to be a fix for this as there appears to be no solution at the moment. It appears to be a very common issue.
I personally need help as soon as possible please. I’ve scoured the forums and the web for answers, and currently have many frustrated people trying to join my site. (I was getting too many bots creating users so a “professional” told me to change the register page URL. It seems to have broken the link from the register page to the database. I changed the URL back, but it didn’t help. I’m now told in the buddypress support forum here that there’s no way to recover from this…???)
Any help, advice, updates (I’m running the latest version Version 2.9.4 on WordPress 4.9.5) would be amazing and beyond appreciated, please. I can’t redo my site as I have about 100 users and about 300 pages.
Thanks so much,
T
There’s a function to tell when you’re on a BP page is_buddypress() so this is a guess at how you could do it:
add_action( 'wp_head', function() {
if ( is_buddypress() ) {
echo '<meta name="robots" content="noindex">';
}
});
Ah, forgot to answer these:
- WordPress ver. 4.9.4
- BuddyPress ver. 2.9.3
- Installation: Runs in main directory (public_html)
- Upgraded from WordPress ver. — I’m going to guess 4.9.3?
- Yep, WP was working fine. It still is, I just recovered it from a pretty bad PHP error. (disclaimer, I have NO idea how to PHP)
- Upgraded from bbPress 2.9.2
- Other Plugins: Akismet 4.0.3; bbpress 2.5.14; Blackhole for Bad Bots 1.8; Comment Mention Notifications 1.0.0; Custom Sidebars 3.1.2; Fancybox for WordPress 3.0.13; Jetpack 5.8; MailChimp 4.1.15; Maintenance 3.6.1; SiteOrigin Page Builder 2.6.2; Patreon for WordPress 2.6.2; Responsive Menu 3.1.13; Shortcodes Ultimate 5.0.3; SiteOrigin CSS 1.1.5; SiteOrigin Widgets Bundle 1.11.4; UpdraftPlus – Backup/Restore 1.14.4; User Role Editor 4.4; WooCommerce 3.3.3; WooCommerce Services 1.11.0; WordPoints 2.4.1; WP Super Cache 1.5.9; Yoast SEO 6.3.1
- Parent Theme: Rose
- I’ve uploaded the Rose theme and made a child theme. I’ve also altered wp-config.php to allow Multisite functionality.
- bbp-custom.php– I made one now! There are no functions.
- Hosted through BlueHost.
- Server OS: More than likely Linux (Apache).
Recent errors:
[03-Mar-2018 00:25:08 UTC] PHP Warning: Missing argument 1 for WP_Widget::__construct(), called in /home1/database/public_html/wp-includes/class-wp-widget-factory.php on line 100 and defined in /home1/database/public_html/wp-includes/class-wp-widget.php on line 162
[03-Mar-2018 00:25:08 UTC] PHP Warning: Missing argument 2 for WP_Widget::__construct(), called in /home1/database/public_html/wp-includes/class-wp-widget-factory.php on line 100 and defined in /home1/database/public_html/wp-includes/class-wp-widget.php on line 162
[03-Mar-2018 00:25:08 UTC] PHP Warning: Missing argument 1 for WP_Widget::__construct(), called in /home1/database/public_html/wp-includes/class-wp-widget-factory.php on line 100 and defined in /home1/database/public_html/wp-includes/class-wp-widget.php on line 162
[03-Mar-2018 00:25:08 UTC] PHP Warning: Missing argument 2 for WP_Widget::__construct(), called in /home1/database/public_html/wp-includes/class-wp-widget-factory.php on line 100 and defined in /home1/database/public_html/wp-includes/class-wp-widget.php on line 162
[03-Mar-2018 00:25:08 UTC] PHP Warning: Missing argument 1 for WP_Widget::__construct(), called in /home1/database/public_html/wp-includes/class-wp-widget-factory.php on line 100 and defined in /home1/database/public_html/wp-includes/class-wp-widget.php on line 162
[03-Mar-2018 00:25:08 UTC] PHP Warning: Missing argument 2 for WP_Widget::__construct(), called in /home1/database/public_html/wp-includes/class-wp-widget-factory.php on line 100 and defined in /home1/database/public_html/wp-includes/class-wp-widget.php on line 162
[03-Mar-2018 00:25:08 UTC] PHP Warning: Missing argument 1 for WP_Widget::__construct(), called in /home1/database/public_html/wp-includes/class-wp-widget-factory.php on line 100 and defined in /home1/database/public_html/wp-includes/class-wp-widget.php on line 162
[03-Mar-2018 00:25:08 UTC] PHP Warning: Missing argument 2 for WP_Widget::__construct(), called in /home1/database/public_html/wp-includes/class-wp-widget-factory.php on line 100 and defined in /home1/database/public_html/wp-includes/class-wp-widget.php on line 162
[03-Mar-2018 00:25:08 UTC] PHP Warning: Missing argument 1 for WP_Widget::__construct(), called in /home1/database/public_html/wp-includes/class-wp-widget-factory.php on line 100 and defined in /home1/database/public_html/wp-includes/class-wp-widget.php on line 162
[03-Mar-2018 00:25:08 UTC] PHP Warning: Missing argument 2 for WP_Widget::__construct(), called in /home1/database/public_html/wp-includes/class-wp-widget-factory.php on line 100 and defined in /home1/database/public_html/wp-includes/class-wp-widget.php on line 162
Now that wannguard is inactive/not supported (I think), I have been trying to find how I can stop spam sign ups.
Wangguard was really good as a feature I really liked about it was the fact that you could set a custom anti spam question unique to your site. This for me seemed to stop all spammers from signing up and seemed to out do captcha as even with recpatcha there are programs and services that allow bots to fill those out but with a custom question its unique to your site.
Is there some plugin or code that doesn’t need updating and is what it is.. that would allow me to add custom question and then add akismet support and that should be enough to protect my site?
—Also would like the plugin or code to be trusted, widely used and updated as according to wordfence even plugins in the wordpress repository are being exploited by hackers (seems some hacker is going around buying plugins to exploit).
Help would be great! Thank you.
Bots can’t register, because nobody can register.
As for users, there are 23k records in the users table and almost 84k records in the bp_friends table.
with my default bp installs just about everything IS public.. it’s actually not easy to make the bp pages like activity and groups and such private.
I think most of those things are fine to be public – and people can choose to make groups members only, logged in only, or public viewable.. default is all public I think..
Most profile fields the user can choose similar privacy settings for certain fields if you allow..
Sometimes I make a group non-pulbic viewable as super admin..
I also choose a lot of things to be blocked by the robot search engine spiders – as there is no need for them to go pulling 100 pages of activity feed and such – so even though most of my BP site is publicly viewable, only about half of it is (supposed to be) crawled by the big engines – most follow the robots.txt directive – but not all..
@januzi_pl – how many members are there?
Are there strong anti-spam / anti-bot sign up measures in place? not a captcha – something like “good question” or other answer correct question to get through kind of thing.
using wp spmshield or some kind of akismet type thing?
I don’t have the kind of graph you show there – but I can say I saw a HUGE difference.. back in the day we had tons of bots signing up for new accounts, sending pms to other users, and all kinds of activity that was not obvious on the front end to the average visitor or site admin.. only after a few complaints and some digging did I realize that 90% of server resources were being sucked away by bot registrations / spammers, and bots that were crawling for the various “search engines” – once you get a hold on those things, then it’s good to know how many users you have and if they are active all day and night or just certain times of the day and such..