The long-established commenting widget: a shared identity across every site using it, with moderation, threading and voting.
Build me a commenting system that replaces Disqus: comments on my pages, from my own domain, with no third party watching my readers. STACK - Node 20+ with Fastify - SQLite through better-sqlite3, WAL mode - One embeddable script under 15KB gzipped, served from my own domain - Caddy in front THE DATA MODEL - sites: id, domain, name, moderation_mode, allow_anonymous, close_after_days, akismet_key - threads: id, site_id, identifier, url, title, is_closed, created_at — the identifier is mine to choose and never the URL alone, because URLs change - comments: id, thread_id, parent_id, author_id, author_name, author_email_hash, author_url, body_md, body_html, status, ip_hash, user_agent_bucket, created_at, edited_at, deleted_at - votes: id, comment_id, voter_hash, direction, created_at - authors: id, email_hash, display_name, avatar_seed, is_trusted, is_blocked, created_at - subscriptions: id, thread_id, email, token, kind, confirmed_at — reply notifications, opt-in - moderation_log: id, comment_id, action, actor, reason, created_at — append-only IDENTITY WITHOUT AN ACCOUNT - A commenter gives a name and optionally an email. The email is stored as a salted hash for the avatar and reply notifications; the plain address is kept only if they asked for notifications, and is deletable by a link in every one of those emails - Avatars are generated from the hash — a deterministic identicon drawn as SVG. No Gravatar, no request to anyone else's server - An email that has had a comment approved becomes trusted, and trusted comments appear immediately. This is the whole moderation strategy for a small site - Optional sign-in with a magic link, if a site wants persistent identity; never required SPAM, WHICH IS THE ACTUAL WORK - A honeypot field and a minimum time-on-form, both of which stop most of it - Rate limits per address hash and per thread - Link count, first-comment-with-a-link, and a keyword list, each configurable, each pushing to the queue rather than rejecting - Optional Akismet, off by default, and the README says clearly that turning it on sends comment text to a third party — which is the thing this tool exists to avoid - Every rejected comment is stored, never silently dropped, so a false positive can be found and released THREADING AND READING - Nested replies to a configurable depth, then flat — three levels is enough and deeper is unreadable on a phone - Sort by newest, oldest or most voted - Markdown, restricted: emphasis, links, lists, code, quotes. Rendered on the server and sanitised there, with the sanitised HTML stored so a page render is never a parse - Edit window of a few minutes; an edited comment says so - Deleting leaves a tombstone so the replies underneath still make sense THE EMBED - One script and a container div, given the thread identifier and the page title - Renders server-side HTML fetched in one request, so the comments are readable before any JavaScript runs where possible - Shadow DOM, inherits my font and accent, dark and light - Lazy: nothing loads until the container is near the viewport, because comments are at the bottom of the page and most readers never reach them - No cookies unless the reader comments; no third-party requests, ever MODERATION - A queue with approve, reject, block author, and a note; every action written to the log - Bulk actions, and a keyboard-driven review screen because moderation is repetitive - Email to the owner on a new comment, batched, with approve and reject links that work from the mail MIGRATION - Import from a Disqus XML export: threads, comments, authors, timestamps and parent relationships - Match threads by identifier first, then URL, and report what could not be matched instead of guessing - Export in the same shape, so leaving this is as easy as arriving OPERATIONS - .env: DATABASE_PATH, BASE_URL, HASH_SALT, SESSION_SECRET, SMTP_URL, ALLOWED_ORIGINS - Migrations on boot, each once - The read path is one prepared statement and an in-memory cache with an ETag - Nightly backup off the machine, restore script - Health endpoint WHAT MATTERS MOST Spam handling and the trusted-author rule. Build the honeypot, the rate limits and the queue first, then leave it exposed on a real page for a week. A commenting system with no spam defence takes about three days to become unusable. Give me the repository, the embed script, the Disqus importer, migrations, .env.example, a seed thread, and a README with deploy steps behind Caddy.
What you lose
- A shared account, so a reader can comment without signing up again
- Moderation and spam filtering at very large scale
- Threading, voting and notifications already built
If you would rather not build
- No comments at all, which many sites find they prefer
What it costs
as published on their pricing page
| Plan | Billed monthly | Billed yearly | Last read |
|---|---|---|---|
| — | $11/mo | — | — |
Their pricing page is where these came from. Seeing a different price? Tell us.
The escape hatch
open source · no votes, no paid placement
Why this verdict
our own opinion · changed only by a person
88/100
Verdict yes at 88. The migration is the only real work, and the export makes it tractable. The page-weight saving is immediate.
History
tracked since 10 Aug 2026 · nothing is ever overwritten
Questions about Disqus
answered from the record above
Is Disqus free?
No — the plan we track is $11 a month. Plus at around $11/month billed monthly to remove advertising; the free tier is ad-supported.
Can you replace Disqus by building your own?
YES. Replaceable in one session with an AI coding agent. Replacement score 88 out of 100, build time one session. Read what you lose before you decide.
How much does Disqus cost?
$11 a month on Plus — $132 a year. Recorded 10 Aug 2026.
What do you lose by replacing Disqus?
A shared account, so a reader can comment without signing up again; Moderation and spam filtering at very large scale; Threading, voting and notifications already built. If any of those carry weight for you, keep paying.
Is there an open-source alternative to Disqus?
Yes: Isso, giscus. The prompt on this page is for when you want it your way instead.
Related entries
same category first, most replaced first
Every week, something stops being worth paying for.
New verdicts, prices that moved, entries added. One email a week. Unsubscribe in one click. Nothing is being sent yet — your address is kept here, and the first issue is the first thing it is used for.
free forever · no tracking pixel · stored here, never passed to anyone

