Open source · PHP 8.4+, SQLite · AGPL-3.0 · open GitHub repository

  • PHP
  • Comment system
  • Self-hosted
  • Accessibility
  • Open source

I needed a comment system for plain PHP websites: no framework, no CMS, nothing more than the classic LAMP stack that every shared host offers. Hosted services such as Disqus were out of the question, since they load third-party trackers into every page and keep the conversation on someone else's servers. A self-hosted script was what I wanted.

I found HashOver on GitHub, a free comment system written by Jacob Barkdull that does exactly that. Its design was right, but its last release dates from 2019: seven years without updates is a long time for PHP code that faces the open internet. So I brought it up to date with Claude Code, Anthropic's AI coding assistant: first a port to PHP 8.4 with a security audit, then a complete rewrite on a modern base. The result is HashOver 2, and you are looking at it: the comment section at the bottom of this page runs on it.

What changed in HashOver 2

  • Current PHP. Runs on PHP 8.4 and newer, with strict types and Composer, and stores comments in an SQLite database.
  • Security hardened with current practices. Every request is checked against cross-site forgery, passwords are hashed with password_hash(), e-mail addresses are encrypted, and comments go through an HTML5 sanitiser with an allow-list.
  • Tested. A PHPUnit test suite and static analysis at PHPStan's strictest level guard every change.
  • Accessible. Built to WCAG 2.1 level AA, the standard behind RAWeb and EN 301 549.

Main features

  1. Conversations. Threaded replies, likes, the most popular comments highlighted, and four sort orders.
  2. No account needed. Visitors can comment anonymously; only the comment itself is required. Adding a password lets them edit or delete their comments later, from any browser.
  3. Moderation. An administrator login to edit or delete any comment, straight from the page.
  4. Notifications. E-mails to the site owner for every new comment, and to commenters when someone replies to them.
  5. Works without JavaScript. Comments are rendered on the server and work with plain links and forms; with JavaScript, posting, replying and sorting happen without reloading the page.
  6. Five languages. English, French, German, Spanish and Japanese, chosen per page, so the translations of an article can share a single thread.
  7. Spam protection. A honeypot, signed form timestamps and rate limits are built in; Akismet and Cloudflare Turnstile can be switched on.
  8. RSS feeds and comment counts. A feed per page, and comment counts for links in article lists.

Privacy by default

Comments stay on your own server. Gravatar, storing IP addresses and every external service are off unless you turn them on, and stored IP addresses are forgotten after a retention period. HashOver 2 also works under a strict Content-Security-Policy: no inline scripts, styles or event handlers.

Requirements

Any LAMP host with PHP 8.4 or newer and the dom, mbstring, pdo_sqlite and sodium extensions. No separate database server: SQLite is a single file. HashOver lives outside the website's document root, so its code, configuration and comments can't be downloaded; the installation guide also covers shared hosting.

See it in action

HashOver 2 runs on this website. The comment section at the bottom of this page is HashOver 2, and so is the one under every project, every IT tip and every blog article. On the blog, the English, French and German versions of an article share one conversation, each with the comment form in its own language. Feel free to leave a comment and try it out.

Further information

Comments

Post a comment on “HashOver 2”

You may use <b>, <i>, <u>, <s>, <code>, <pre>, <ul>, <ol>, <li> and <blockquote>. Web addresses become links; [img]address[/img] shows an image on request.

About you (all optional)

Never shown. Only used to notify you of replies.

Lets you edit or delete your comment later, from any browser, by logging in with the same name.

To post, like or reply, please complete this security check by Cloudflare Turnstile.

The security check needs JavaScript. Please turn it on to post, like or reply.

Logging in with the name and password of earlier comments lets you edit them.

0 comments

No comments yet. Be the first to comment!