A comment box is small on the page but can create moderation, privacy and maintenance work. Payload Comments is an MIT-licensed plugin for Payload CMS 3 that keeps comment records in the site's own database rather than a third-party widget. That gives a team control over data and policy; it also gives the team responsibility for spam handling and backups.
Key takeaways
- Payload Comments is MIT-licensed and supports Markdown bodies, reactions, and nested replies up to three levels deep.
- Built-in spam controls include a honeypot, rate limiting and length or link rules, but a public site still needs moderation.
- It requires Payload CMS 3.x plus React and React-DOM as peer dependencies, and an environment variable for IP hashing.
What does the Payload Comments plugin actually include?
The project README lists Markdown-rendered comment bodies with XSS protection, optional pre-publication approval that can be toggled at runtime, configurable emoji reactions on comments, and nested replies up to three levels deep. It also documents built-in anti-spam measures, including a honeypot field, rate limiting, and length and link rules, which help but do not eliminate the need for a human moderation process on a public site. An admin statistics dashboard provides filtering and key metrics about comment volume and activity, and the plugin can be enabled or disabled per Payload collection rather than globally across the whole site. Integration is available either through a ready-to-use React component or by calling the plugin's REST API directly from a custom frontend, which matters if your site's frontend is not built with the same React version the component expects.
What should you check before installing it?
Decide which Payload collections should actually allow comments and who on your team has permission to moderate them, since enabling comments broadly by default is harder to walk back than enabling them selectively. Determine whether an email address is required or optional for a commenter, and how the privacy notice around that data is presented, since this affects your site's privacy compliance obligations. Plan for what happens to a collection's comments when the underlying article is unpublished or deleted, since orphaned comments can be confusing or create a data-retention question you had not considered. Confirm your site can realistically handle abusive submissions, routine backups and data-subject requests for comment data specifically, not just for your main content, since comments are personal data once a name or email is attached to them.
What technical requirements does it have?
The plugin requires Payload CMS version 3.x; it will not work on the earlier Payload 2.x line, so check your CMS version before planning an installation. React and React-DOM are peer dependencies, which matters if your frontend uses a different framework or an older React version than the plugin expects. The plugin also needs an environment variable used as a salt for hashing commenter IP addresses, a detail that supports basic spam and abuse tracking without storing raw IP addresses in the database. Payload's own collection access-control documentation explains the framework-level permission system the plugin builds on top of, worth reading first if your team has not customized Payload access control before. Test anonymous, unauthenticated write paths directly before enabling comments on any public-facing collection.
Who is this plugin actually for?
It suits a team already running Payload CMS 3 that wants comments stored in its own database, under its own access-control rules, and that has the capacity to handle moderation and abuse reports as an ongoing task rather than a one-time setup. A hosted commenting widget from a third-party service may be simpler to operate for a site that lacks that capacity, though it introduces an external dependency, a different privacy posture, and typically a recurring cost. The plugin's MIT license means you can also fork and modify it freely if your requirements diverge from what it supports out of the box, a meaningful option for a team with in-house React and Payload expertise. See the ITHub profile and the current installation instructions before deciding.
Sources checked 27 September 2026.
Frequently asked questions
How deep can comment replies nest in this plugin?
Replies can nest up to three levels deep according to the project README. Deeper conversational threads will need to be flattened or handled differently by your frontend, since the plugin does not support unlimited reply depth.
Does Payload Comments work with Payload CMS 2.x?
No, the plugin requires Payload CMS 3.x specifically. If your site still runs Payload 2.x, you would need to upgrade your CMS version before this plugin can be installed.
Does the plugin store commenters' raw IP addresses?
No, IP addresses are hashed using a salt provided through an environment variable rather than stored in plain text. This supports basic spam and abuse tracking while limiting how much raw personal data the database retains.