If your Drupal site still runs the community Akismet module (drupal/akismet), the official Akismet module (drupal/akismet_antispam) can upgrade it in place. You swap the Composer package, run database updates, and your API key and protection settings come along. We built it so you don’t have to uninstall, reinstall, and re-enter everything. This post walks through the steps.
The update needs Drupal 10.3 or later on PHP 8.1 or later. That covers sites on the community module’s 2.0.x releases and its 8.x-1.x dev branch.
If you’re on an older setup:
The migration guide on drupal.org has a table for every release if you’re not sure which one you run.
drush updb, spam protection is off and some admin pages break, so don’t leave a gap between them.These come along:
These don’t:
akismet table is dropped, so the Spam tab starts empty. Those rows hold submitted content, including author emails and IP addresses, and the official module has no way to erase them later. bypass akismet, and it isn’t granted automatically.You don’t have to track any of this by hand. The update prints a report that names every item above that applies to your site.
composer remove drupal/akismetcomposer require drupal/akismet_antispam -Wdrush crdrush updb Run them in that order, back to back.
composer remove first, and leave the module installed in Drupal. Don’t uninstall it, because the update reads its database state. The official module’s composer.json conflicts with drupal/akismet, so Composer won’t install them side by side.composer require ... -W lets Composer update shared dependencies, like the Akismet PHP SDK or the PSR HTTP packages, if your lock file pins an older version. Without -W, Composer can refuse with “the package is fixed to … (lock file version).”drush cr before anything else. The community module shipped services that no longer exist, and Drupal still has them cached. Until you rebuild, logged-in pages return a 500 and drush commands die on shutdown. drush cr works when nothing else does.drush updb runs the update. Stay off the comment admin screens until it finishes.Read the report. It’s also logged to watchdog, so you won’t lose it if your terminal scrolls away. Then export and commit the new configuration:
drush cex On every other environment, rebuild the cache before anything else touches it:
drush cr && drush deploy /admin/config/content/akismet./admin/reports/status.akismet-guaranteed-spam. Akismet always flags that name, so the comment should land in the Spam tab.Upgrading to 1.1 is one command and a database update:
composer update drupal/akismet_antispam -Wdrush updb The -W matters here. Version 1.1 needs Akismet PHP SDK 1.5, and if your lock file still pins 1.4, Composer stops with:
drupal/akismet_antispam 1.1.0 requires automattic/akismet-sdk ^1.5 -> found automattic/akismet-sdk[v1.5.0] but the package is fixed to v1.4.0 (lock file version). -W (short for --with-dependencies) lets Composer update the SDK along with the module.
If something in the report surprises you, or the update doesn’t go the way this post says, open an issue in the issue queue. The migration guide and the module’s README have the full details.
The Union Cabinet has approved the establishment of a Rs 10,000 crore SME Growth Fund…
Eva Marie Saint, the acclaimed actress famed for her iconic role in ‘On the Waterfront’,…
Christa Pike, a death row inmate in Tennessee, is recovering at a hospital following a…
India is experiencing a noticeable slowdown in the shift to 5G smartphones due to rising…
The Closing Auction Session faced volatility as weekly derivatives contracts expired in Indian markets. Nifty…
The World Bank has revised India's economic growth projection to 7.1% for 2026-27, up from…