A commenting system for blogs and documentation with no advertising and no tracking, moderation tools and single sign-on into your own accounts.
Build me a commenting system that replaces Hyvor Talk: comments on my site, signed in with my own accounts, with no advertising and nothing loaded from a third party. STACK - Node 20+ with Fastify - SQLite through better-sqlite3, WAL mode, with FTS5 for moderation search - One embeddable script under 15KB gzipped, from my own domain - Caddy in front THE DATA MODEL - sites: id, domain, name, moderation_mode, allow_anonymous, sso_secret, close_after_days, language - threads: id, site_id, identifier, url, title, is_closed, comment_count, created_at — the identifier is chosen by me and is never the URL alone, because URLs change - comments: id, thread_id, parent_id, author_id, body_md, body_html, status, score, ip_hash, created_at, edited_at, deleted_at - authors: id, site_id, external_id, display_name, email_hash, avatar_url, is_trusted, is_blocked, comment_count, created_at - votes: id, comment_id, voter_key, direction, created_at - reports: id, comment_id, reporter_key, reason, note, created_at, resolved_at - moderation_log: id, comment_id, action, actor, reason, at — append-only - subscriptions: id, thread_id, author_id, kind, token — reply notifications SINGLE SIGN-ON, WHICH IS WHY THIS IS CHOSEN - My application signs a small token containing the user's external id, display name, avatar and email, and the widget is initialised with it - Signed with a shared secret, short-lived, verified on the server. Never a plain user id, which anyone can type - The author record is keyed on the external id, so a user renamed in my system is renamed here - Anonymous commenting allowed per site as an option, with a name and an optional email hashed for the avatar - No third-party login buttons, no social identity, no request to anybody else's server. The reader's browser talks to my domain and nowhere else, which is the property being bought MODERATION - Modes: everything published, first comment held per author, everything held, or nothing held - An author whose comment has been approved becomes trusted and posts immediately afterwards. This one rule is most of the moderation strategy for a normal site - A queue with approve, reject, block author and a note, all logged, all reversible - Keyboard-driven review, because moderation is repetitive and volume is what makes it unbearable - Reports from readers with reasons, queued, and acting automatically at a threshold by hiding pending review - Bulk actions, and search across comment bodies and authors SPAM - Honeypot and a minimum time on form, which stops most of it - Rate limits per author and per address hash - Link count, first-comment-with-a-link, and a configurable phrase list, each scoring rather than deciding - Every rejected comment stored, never silently dropped — a false positive is a reader who thinks they were ignored - Optional third-party spam checking off by default, with the privacy consequence stated plainly in the README READING AND WRITING - Nested replies to three levels, then flat. Deeper is unreadable on a phone - Sort by newest, oldest or most voted - Markdown, restricted to emphasis, links, lists, code and quotes, sanitised on the server, with the rendered HTML stored so a page render is never a parse - Voting up and optionally down, one per voter per comment, changeable - An edit window of a few minutes, with edited comments marked - Deleting leaves a tombstone so the replies underneath still make sense - Reactions as an alternative to voting, if the site prefers them THE EMBED - One script and a container element, given the thread identifier, the page title and optionally the signed token - Nothing loads until the container is near the viewport; comments live at the bottom of the page and most readers never reach them - Shadow DOM, inherits my font and accent, dark and light following the host page - Keyboard navigable, labelled for screen readers, usable at 320px - No cookie unless the reader comments; no third-party request, ever, including for avatars — an anonymous avatar is generated locally as an SVG identicon NOTIFICATIONS - Reply notifications by email, opt-in, with a one-click stop that needs no login - A digest to the site owner for the queue, batched, with approve and reject links that work from the mail OPERATIONS - .env: DATABASE_PATH, BASE_URL, HASH_SALT, SESSION_SECRET, SMTP_URL, ALLOWED_ORIGINS - Migrations on boot, each once - The read path is one prepared statement plus an in-memory cache with an ETag - Nightly backup off the machine, restore script - Health endpoint WHAT MATTERS MOST Single sign-on and the trusted-author rule. Build token verification and the automatic promotion first, then leave the widget on a public page for a fortnight. The identity link is why this product is chosen over the free ones, and the trust rule is what keeps moderation from becoming a daily chore. Give me the repository, the embed script, migrations, .env.example, the token-signing snippet for my backend, and a README with deploy steps behind Caddy.
What you lose
- Spam filtering tuned across many sites, which is most of the work once comments are open
- Moderation queues, bans and reporting already built
- Hosting for a widget that must load fast on every page
If you would rather not build
- Commento, for the same job
What it costs
read from their page 15 Aug 2026
| Plan | Billed monthly | Billed yearly | Last read |
|---|---|---|---|
| — | $5/mo | — | 15 Aug 2026 |
Their pricing page is where these came from. Seeing a different price? Tell us.
The escape hatch
open source · no votes, no paid placement
Isso
$0A lightweight self-hosted commenting server with moderation.
isso-comments/issofree · open source
Why this verdict
our own opinion · changed only by a person
85/100
Verdict yes at 85. Comments are a table; the sanitiser and the three spam layers are what keep them from becoming a liability.
History
tracked since 10 Aug 2026 · nothing is ever overwritten
Questions about Hyvor Talk
answered from the record above
Is Hyvor Talk free?
No — the plan we track is $5 a month. From around $5/month billed monthly for a single site.
Can you replace Hyvor Talk by building your own?
YES. Replaceable in one session with an AI coding agent. Replacement score 85 out of 100, build time one session. Read what you lose before you decide.
How much does Hyvor Talk cost?
$5 a month on Starter — $60 a year. Recorded 10 Aug 2026.
What do you lose by replacing Hyvor Talk?
Spam filtering tuned across many sites, which is most of the work once comments are open; Moderation queues, bans and reporting already built; Hosting for a widget that must load fast on every page. If any of those carry weight for you, keep paying.
Is there an open-source alternative to Hyvor Talk?
Yes: Isso, giscus. The prompt on this page is for when you want it your way instead.
Related entries
same category first, most replaced first
Every week, something stops being worth paying for.
New verdicts, prices that moved, entries added. One email a week. Unsubscribe in one click. Nothing is being sent yet — your address is kept here, and the first issue is the first thing it is used for.
free forever · no tracking pixel · stored here, never passed to anyone

