{"id":102,"date":"2026-10-06T23:13:52","date_gmt":"2026-10-06T22:13:52","guid":{"rendered":"https:\/\/sripuwath.com\/index.php\/2026\/10\/06\/akismet-upgrade-to-the-official-akismet-drupal-module\/"},"modified":"2026-10-06T23:13:52","modified_gmt":"2026-10-06T22:13:52","slug":"akismet-upgrade-to-the-official-akismet-drupal-module","status":"publish","type":"post","link":"https:\/\/sripuwath.com\/index.php\/2026\/10\/06\/akismet-upgrade-to-the-official-akismet-drupal-module\/","title":{"rendered":"Akismet: Upgrade to the official Akismet Drupal module"},"content":{"rendered":"<p class=\"wp-block-paragraph\">If your Drupal site still runs the community Akismet module (<code>drupal\/akismet<\/code>), the official Akismet module (<code>drupal\/akismet_antispam<\/code>) can upgrade it in place. You swap the Composer package, run database updates, and your API key and protection settings come along. We built it so you don\u2019t have to uninstall, reinstall, and re-enter everything. This post walks through the steps.<\/p>\n<h3 class=\"wp-block-heading\">Which sites this covers<\/h3>\n<p class=\"wp-block-paragraph\">The update needs Drupal 10.3 or later on PHP 8.1 or later. That covers sites on the community module\u2019s 2.0.x releases and its 8.x-1.x dev branch.<\/p>\n<p class=\"wp-block-paragraph\">If you\u2019re on an older setup:<\/p>\n<ul class=\"wp-block-list\">\n<li><strong>8.x-1.0-alpha2 (Drupal 8 or 9):<\/strong> update the community module to 2.0.0-alpha2 while you update core, then follow this post.<\/li>\n<li><strong>7.x:<\/strong> upgrade Drupal first, then install the official module fresh. Your Akismet account and API key still work.<\/li>\n<\/ul>\n<p class=\"wp-block-paragraph\">The <a href=\"https:\/\/www.drupal.org\/docs\/extending-drupal\/contributed-modules\/contributed-module-documentation\/akismet-anti-spam\/migrating-from-the-community-akismet-module\">migration guide on drupal.org<\/a> has a table for every release if you\u2019re not sure which one you run.<\/p>\n<h3 class=\"wp-block-heading\">Before you start<\/h3>\n<ul class=\"wp-block-list\">\n<li><strong>Back up the database.<\/strong> The update only goes one way.<\/li>\n<li><strong>Note which roles have \u201cBypass Akismet protection.\u201d<\/strong> The update removes that permission (more on that below).<\/li>\n<li><strong>Plan one deploy for the whole swap.<\/strong> Between the Composer change and <code>drush updb<\/code>, spam protection is off and some admin pages break, so don\u2019t leave a gap between them.<\/li>\n<\/ul>\n<h3 class=\"wp-block-heading\">What carries over, and what doesn\u2019t<\/h3>\n<p class=\"wp-block-paragraph\">These come along:<\/p>\n<ul class=\"wp-block-list\">\n<li>Your API key<\/li>\n<li>Your connection timeout, if it\u2019s between 1 and 60 seconds<\/li>\n<li>Your comment, contact and registration protection settings<\/li>\n<\/ul>\n<p class=\"wp-block-paragraph\">These don\u2019t:<\/p>\n<ul class=\"wp-block-list\">\n<li><strong>Check history.<\/strong> The community module\u2019s <code>akismet<\/code> table is dropped, so the Spam tab starts empty. Those rows hold submitted content, including author emails and IP addresses, and the official module has no way to erase them later. <\/li>\n<li><strong>Per-form settings.<\/strong> The community module could protect some comment types or contact forms and not others. The official module has one toggle per category, and it covers all of them.<\/li>\n<li><strong>Per-form \u201cdiscard spam.\u201d<\/strong> This becomes one site-wide strictness setting.<\/li>\n<li><strong>Test mode, custom API endpoints and the \u201cblock all submissions\u201d outage policy.<\/strong><\/li>\n<li><strong>The \u201cBypass Akismet protection\u201d permission.<\/strong> The update removes it from every role that had it. The official module\u2019s equivalent is <code>bypass akismet<\/code>, and it isn\u2019t granted automatically.<\/li>\n<li><strong>Webform handlers.<\/strong> You\u2019ll need to re-attach the Akismet handler to each webform that used it.<\/li>\n<\/ul>\n<p class=\"wp-block-paragraph\">You don\u2019t have to track any of this by hand. The update prints a report that names every item above that applies to your site.<\/p>\n<h3 class=\"wp-block-heading\">The migration<\/h3>\n<div class=\"wp-block-code\">\n<div class=\"cm-editor\">\n<div class=\"cm-scroller\">\n<pre>\n<code class=\"language-shell\"><div class=\"cm-line\">composer remove drupal\/akismet<\/div><div class=\"cm-line\">composer require drupal\/akismet_antispam <span class=\"tok-propertyName\">-W<\/span><\/div><div class=\"cm-line\">drush cr<\/div><div class=\"cm-line\">drush updb<\/div><\/code><\/pre>\n<\/div>\n<\/div>\n<\/div>\n<p class=\"wp-block-paragraph\">Run them in that order, back to back.<\/p>\n<ol class=\"wp-block-list\">\n<li><strong><code>composer remove<\/code><\/strong> first, and leave the module installed in Drupal. Don\u2019t uninstall it, because the update reads its database state. The official module\u2019s <code>composer.json<\/code> conflicts with <code>drupal\/akismet<\/code>, so Composer won\u2019t install them side by side.<\/li>\n<li><strong><code>composer require ... -W<\/code><\/strong> lets Composer update shared dependencies, like the Akismet PHP SDK or the PSR HTTP packages, if your lock file pins an older version. Without <code>-W<\/code>, Composer can refuse with \u201cthe package is fixed to \u2026 (lock file version).\u201d<\/li>\n<li><strong><code>drush cr<\/code><\/strong> before anything else. The community module shipped services that no longer exist, and Drupal still has them cached. Until you rebuild, logged-in pages return a 500 and drush commands die on shutdown. <code>drush cr<\/code> works when nothing else does.<\/li>\n<li><strong><code>drush updb<\/code><\/strong> runs the update. Stay off the comment admin screens until it finishes.<\/li>\n<\/ol>\n<figure class=\"wp-block-jetpack-videopress jetpack-videopress-player\">\n<div class=\"jetpack-videopress-player__wrapper\">\n<div class=\"jetpack-video-wrapper\"><\/div>\n<\/div>\n<\/figure>\n<p class=\"wp-block-paragraph\">Read the report. It\u2019s also logged to watchdog, so you won\u2019t lose it if your terminal scrolls away. Then export and commit the new configuration:<\/p>\n<div class=\"wp-block-code\">\n<div class=\"cm-editor\">\n<div class=\"cm-scroller\">\n<pre>\n<code class=\"language-shell\"><div class=\"cm-line\">drush cex<\/div><\/code><\/pre>\n<\/div>\n<\/div>\n<\/div>\n<p class=\"wp-block-paragraph\">On every other environment, rebuild the cache before anything else touches it:<\/p>\n<div class=\"wp-block-code\">\n<div class=\"cm-editor\">\n<div class=\"cm-scroller\">\n<pre>\n<code class=\"language-shell\"><div class=\"cm-line\">drush cr &amp;&amp; drush deploy<\/div><\/code><\/pre>\n<\/div>\n<\/div>\n<\/div>\n<h3 class=\"wp-block-heading\">Check that it worked<\/h3>\n<ul class=\"wp-block-list\">\n<li><strong>Settings:<\/strong> confirm your protection toggles at <code>\/admin\/config\/content\/akismet<\/code>.<\/li>\n<li><strong>Status report:<\/strong> check the Akismet entries at <code>\/admin\/reports\/status<\/code>.<\/li>\n<li><strong>Test submission:<\/strong> post a comment as an anonymous user named <code>akismet-guaranteed-spam<\/code>. Akismet always flags that name, so the comment should land in the Spam tab.<\/li>\n<\/ul>\n<h3 class=\"wp-block-heading\">Already on the official module 1.0?<\/h3>\n<p class=\"wp-block-paragraph\">Upgrading to 1.1 is one command and a database update:<\/p>\n<div class=\"wp-block-code\">\n<div class=\"cm-editor\">\n<div class=\"cm-scroller\">\n<pre>\n<code class=\"language-shell\"><div class=\"cm-line\">composer update drupal\/akismet_antispam <span class=\"tok-propertyName\">-W<\/span><\/div><div class=\"cm-line\">drush updb<\/div><\/code><\/pre>\n<\/div>\n<\/div>\n<\/div>\n<p class=\"wp-block-paragraph\">The <code>-W<\/code> matters here. Version 1.1 needs Akismet PHP SDK 1.5, and if your lock file still pins 1.4, Composer stops with:<\/p>\n<div class=\"wp-block-code\">\n<div class=\"cm-editor\">\n<div class=\"cm-scroller\">\n<pre>\n<code><div class=\"cm-line\">drupal\/akismet_antispam 1.1.0 requires automattic\/akismet-sdk ^1.5 -&gt; found automattic\/akismet-sdk[v1.5.0] but the package is fixed to v1.4.0 (lock file version).<\/div><\/code><\/pre>\n<\/div>\n<\/div>\n<\/div>\n<p class=\"wp-block-paragraph\"><code>-W<\/code> (short for <code>--with-dependencies<\/code>) lets Composer update the SDK along with the module.<\/p>\n<h3 class=\"wp-block-heading\">Questions<\/h3>\n<p class=\"wp-block-paragraph\">If something in the report surprises you, or the update doesn\u2019t go the way this post says, open an issue in the <a href=\"https:\/\/www.drupal.org\/project\/issues\/akismet_antispam\">issue queue<\/a>. The <a href=\"https:\/\/www.drupal.org\/docs\/extending-drupal\/contributed-modules\/contributed-module-documentation\/akismet-anti-spam\/migrating-from-the-community-akismet-module\">migration guide<\/a> and the module\u2019s README have the full details.<\/p>","protected":false},"excerpt":{"rendered":"<p>If your Drupal site still runs the community Akismet module (drupal\/akismet), the official Akismet module (drupal\/akismet_antispam) can upgrade it in place. You swap the Composer package, run database updates, and [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[],"class_list":["post-102","post","type-post","status-publish","format-standard","hentry"],"_links":{"self":[{"href":"https:\/\/sripuwath.com\/index.php\/wp-json\/wp\/v2\/posts\/102","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sripuwath.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sripuwath.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sripuwath.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/sripuwath.com\/index.php\/wp-json\/wp\/v2\/comments?post=102"}],"version-history":[{"count":0,"href":"https:\/\/sripuwath.com\/index.php\/wp-json\/wp\/v2\/posts\/102\/revisions"}],"wp:attachment":[{"href":"https:\/\/sripuwath.com\/index.php\/wp-json\/wp\/v2\/media?parent=102"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sripuwath.com\/index.php\/wp-json\/wp\/v2\/categories?post=102"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sripuwath.com\/index.php\/wp-json\/wp\/v2\/tags?post=102"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}