Skip to main content
< All Topics
Print

Allow people to submit comments on new posts

WARNING: Enforcing this setting changes the default behavior for new posts and can affect publishing workflows or community features that rely on comments. Confirm that comments are not required for normal site operation before enabling enforcement.

Description of the control

This control sets how CMSSPM handles Allow people to submit comments on new posts on the Core Hardening page. The available options are Off (prefer comments disabled)Enforced (keep new posts closed to comments), and Audit only.

The control also includes a risk acceptance checkbox labeled Override comments are intentionally core to the site; do not score this against me. The help text states that this suppresses audit findings and does not change enforcement.

Procedure

  1. In WordPress admin, open Posture Management.
  2. Select Core Hardening.
  3. In the WordPress Interfaces section, locate Allow people to submit comments on new posts.
  4. Select one of these options:
    • Off (prefer comments disabled)
    • Enforced (keep new posts closed to comments)
    • Audit only
  5. If comments are intentionally part of the site and the goal is only to suppress audit findings, select Override comments are intentionally core to the site; do not score this against me.
  6. Click Save changes.

Validation

After saving, reload Posture Management -> Core Hardening and confirm the selected option is still shown for Allow people to submit comments on new posts.

If Enforced was selected, create a new test post or review a newly created post and confirm comments are closed by default.

Table of Contents