WordPress: Avoid Gravatar third-party connections
A comment can be stored locally and still trigger an external connection when displayed: WordPress supports Gravatar as an avatar service.
Prerequisites
WordPress administrative access and a page with actually displayed author or comment avatars.
Why this is relevant
If an external avatar image is loaded directly from the browser, its server technically sees the IP of the page visitor as well as usual HTTP connection data. This is different from storing the comment IP.
Data-efficient variants
If avatars are not required, deactivate the avatar display. If avatars are required, prefer local solutions that deliver images from your own domain and do not only contact a third-party provider when the visitor is retrieved.
Check
Load a page with comments in a fresh browser profile and check in the network panel whether resources are requested from Gravatar/Automattic domains.
Check third-party connections
As a technical basis, additionally External fonts and CDNs: avoid unnecessary third-party connections Use: The decisive factor is which external hosts the browser actually contacts and whether the resource can be delivered locally.
Dismantling
If external avatars are needed again, specifically reactivate the previous integration and then check the resulting third-party requests again.
Related guides
Sources and verification
This guide is based on multiple current sources. Vendor documentation is not treated as proof that every concrete installation automatically follows the same privacy characteristics.
- WordPress Support: Settings Discussion Screen
- WordPress Developer: get_avatar
- Gravatar Developer: Images
Important: IP processing is not IP storage
An IP address has to be processed to establish and deliver a network connection. Hosting providers, firewalls or DDoS protection may also process or retain it for a limited time for security purposes. No Logging distinguishes this security layer from unnecessary persistent visitor logging by the website, application and ordinary access logs.