Akismet integration sends a wrong post count
-
The Akismet integration reports the wrong post count for any author with 1,000 or more posts. The formatted count (for example
'1,309') is cast toint, which gives1. Akismet then receives an experienced member as someone with a single post.Environment
- bbPress 2.6.19
- WordPress 7.1.2
- PHP 8.2
Where
BBP_Akismet::check_post()inincludes/extend/akismet.php, line 115:$user_data['total_posts'] = (int) bbp_get_user_post_count( $post_data['post_author'] );
The value is then sent to Akismet as
comment_total(line 162).Cause
Without the second argument (
$integer = true),bbp_get_user_post_count()runs through thebbp_get_user_post_countfilter.bbp_number_formatis hooked to that filter inincludes/core/filters.php(line 267), so the function returns a formatted string. Casting that string tointstops at the thousands separator:(int) '1,309' // 1 (int) '12,045' // 12
With a locale that uses a space or a non-breaking space as the separator, the result is the same.
Impact
Every new topic or reply from an author with 1,000+ posts is checked by Akismet with a post total of 1–999 instead of the real number. The real number is the part of the user history that most separates a long-standing member from a fresh spam account, so the most active members are the ones most likely to be judged worse than they should be. There is no error or notice; the value is just wrong.
Steps to reproduce
- Activate Akismet, so bbPress loads its integration.
- Use an account whose
_bbp_reply_count+_bbp_topic_countuser meta add up to 1,000 or more. - Post a reply and inspect the request sent to Akismet (for example via the
bbp_akismet_check_postfilter):comment_totalis the digits before the first separator, not the real count.
Suggested fix
$user_data['total_posts'] = bbp_get_user_post_count( $post_data['post_author'], true );
The
(int)cast is then unnecessary, since the_intfilter path already returns an integer.
- You must be logged in to reply to this topic.