Custom Comment System Development with Laravel and React

Our company is engaged in the development, support and maintenance of sites of any complexity. From simple one-page sites to large-scale cluster systems built on micro services. Experience of developers is confirmed by certificates from vendors.

Development and maintenance of all types of websites:

Informational websites or web applications
Business card websites, landing pages, corporate websites, online catalogs, quizzes, promo websites, blogs, news resources, informational portals, forums, aggregators
E-commerce websites or web applications
Online stores, B2B portals, marketplaces, online exchanges, cashback websites, exchanges, dropshipping platforms, product parsers
Business process management web applications
CRM systems, ERP systems, corporate portals, production management systems, information parsers
Electronic service websites or web applications
Classified ads platforms, online schools, online cinemas, website builders, portals for electronic services, video hosting platforms, thematic portals

These are just some of the technical types of websites we work with, and each of them can have its own specific features and functionality, as well as be customized to meet the specific needs and goals of the client.

Showing 1 of 1All 2062 services
Custom Comment System Development with Laravel and React
Medium
~5 days
Frequently Asked Questions

Our competencies:

Development stages

Latest works

  • image_website-b2b-advance_0.webp
    B2B ADVANCE company website development
    1358
  • image_web-applications_feedme_466_0.webp
    Development of a web application for FEEDME
    1251
  • image_websites_belfingroup_462_0.webp
    Website development for BELFINGROUP
    956
  • image_ecommerce_furnoro_435_0.webp
    Development of an online store for the company FURNORO
    1188
  • image_crm_enviok_479_0.webp
    Development of a web application for Enviok
    929
  • image_bitrix-bitrix-24-1c_fixper_448_0.webp
    Website development for FIXPER company
    947

When your website grows, comments become a bottleneck. Built-in solutions like Disqus are a trade-off: you lose data control, page load speed suffers, and third-party ads annoy users. Server throughput decreases, infrastructure costs rise. We build custom comment systems on Laravel and React that solve N+1 queries, spam, and complex moderation. In 3–7 days you get a flexible, fast, scalable system fully under your control.

What Problems Does a Custom Comment System Solve?

N+1 Queries for Nested Comments

A typical mistake: loading replies with separate queries for each comment. On a page with 100 comments, that's 101 queries. The solution: eager loading with recursive fetching — one query retrieves the entire tree, and Laravel builds the hierarchy in memory. As noted in the Laravel documentation, proper relationship handling reduces queries to a minimum.

Spam and Moderation

We automatically filter comments with suspicious links, set rate limits (10 comments per minute), and send suspicious ones for manual review. For guests, we use CAPTCHA. Details can be seen below.

More About ModerationWe combine pre-moderation for new users and automatic rule-based checks. Comments containing more than two external links are automatically marked as spam. For registered users with high reputation, comments are published immediately.

Duplicate Likes

To prevent multiple votes from the same user, we use Redis caching with key comment_like:{comment_id}:{user_id}. This is more reliable than a separate table and faster.

How We Do It

Tech Stack

  • Backend: Laravel, PHP 8.3, PostgreSQL 16, Redis 7
  • Frontend: React 18, TypeScript, Tailwind CSS
  • Infrastructure: Docker, Nginx, GitHub Actions

Key Solution: Anti-N+1 Queries

// In the controller
$comments = Comment::where('entity_type', $entityType)
    ->where('entity_id', $entityId)
    ->whereNull('parent_id')
    ->with(['user', 'replies' => function ($query) {
        $query->where('status', 'approved')->with('user');
    }])
    ->latest()
    ->paginate(20);

This pattern reduces the number of queries from N+1 to 3 (root comments, replies, users).

Database Schema

CREATE TABLE comments (
    id          SERIAL PRIMARY KEY,
    entity_type VARCHAR(50)  NOT NULL,  -- 'article', 'product', 'post'
    entity_id   INTEGER      NOT NULL,
    parent_id   INTEGER REFERENCES comments(id) ON DELETE SET NULL,
    user_id     INTEGER REFERENCES users(id),
    author_name VARCHAR(100),           -- for guests
    author_email VARCHAR(255),
    body        TEXT         NOT NULL,
    status      VARCHAR(20)  NOT NULL DEFAULT 'pending',  -- pending|approved|rejected|spam
    likes_count INTEGER      NOT NULL DEFAULT 0,
    created_at  TIMESTAMPTZ  NOT NULL DEFAULT NOW(),
    updated_at  TIMESTAMPTZ  NOT NULL DEFAULT NOW()
);

CREATE INDEX ON comments(entity_type, entity_id, status, created_at);
CREATE INDEX ON comments(parent_id);
CREATE INDEX ON comments(user_id);

API and Frontend Design

Laravel API

class CommentController extends Controller
{
    // Fetch comments for an entity
    public function index(Request $request, string $entityType, int $entityId): JsonResponse
    {
        $comments = Comment::where('entity_type', $entityType)
            ->where('entity_id', $entityId)
            ->where('status', 'approved')
            ->whereNull('parent_id')
            ->with(['user:id,name,avatar', 'replies' => fn($q) => $q->where('status', 'approved')->with('user:id,name,avatar')])
            ->latest()
            ->paginate(20);

        return response()->json($comments);
    }

    // Add a comment
    public function store(StoreCommentRequest $request, string $entityType, int $entityId): JsonResponse
    {
        $this->throttle('comments', 10, 60);

        $requiresModeration = !auth()->check()
            || auth()->user()->comments()->where('status', 'spam')->exists()
            || $this->containsSuspiciousLinks($request->body);

        $comment = Comment::create([
            'entity_type'  => $entityType,
            'entity_id'    => $entityId,
            'parent_id'    => $request->parent_id,
            'user_id'      => auth()->id(),
            'author_name'  => auth()->user()?->name ?? $request->author_name,
            'author_email' => auth()->user()?->email ?? $request->author_email,
            'body'         => $this->sanitize($request->body),
            'status'       => $requiresModeration ? 'pending' : 'approved',
        ]);

        if ($comment->status === 'approved') {
            $this->notifyParentAuthor($comment);
        } else {
            Notification::send(
                User::moderators()->get(),
                new CommentPendingNotification($comment)
            );
        }

        return response()->json(CommentResource::make($comment), 201);
    }

    private function sanitize(string $body): string
    {
        return strip_tags($body, '<b><i><em><strong><a><br><p>');
    }

    private function containsSuspiciousLinks(string $body): bool
    {
        preg_match_all('/<a[^>]+href=["\']?([^"\'> ]+)/i', $body, $matches);
        foreach ($matches[1] ?? [] as $url) {
            if (!str_contains($url, config('app.url'))) {
                return true;
            }
        }
        return false;
    }
}

React Comment Tree

interface Comment {
  id: number;
  user: { name: string; avatar: string } | null;
  author_name: string;
  body: string;
  likes_count: number;
  created_at: string;
  replies?: Comment[];
}

function CommentThread({ entityType, entityId }: { entityType: string; entityId: number }) {
  const { data, isLoading } = useQuery({
    queryKey: ['comments', entityType, entityId],
    queryFn: () => api.get(`/comments/${entityType}/${entityId}`),
  });

  return (
    <section aria-label="Comments">
      <h2>Comments ({data?.meta.total ?? 0})</h2>
      <CommentForm entityType={entityType} entityId={entityId} />

      {isLoading ? <CommentSkeleton /> : (
        <ul className="comment-list">
          {data?.data.map(comment => (
            <CommentItem key={comment.id} comment={comment} depth={0} />
          ))}
        </ul>
      )}
    </section>
  );
}

function CommentItem({ comment, depth }: { comment: Comment; depth: number }) {
  const [showReplyForm, setShowReplyForm] = useState(false);

  return (
    <li className={`comment depth-${depth}`}>
      <img
        src={comment.user?.avatar || '/default-avatar.png'}
        alt={comment.user?.name || comment.author_name}
        width={40} height={40}
      />
      <div className="comment__content">
        <header>
          <strong>{comment.user?.name || comment.author_name}</strong>
          <time dateTime={comment.created_at}>
            {new Date(comment.created_at).toLocaleDateString('en-US')}
          </time>
        </header>
        <p>{comment.body}</p>
        <footer>
          <LikeButton commentId={comment.id} count={comment.likes_count} />
          {depth < 3 && (
            <button onClick={() => setShowReplyForm(!showReplyForm)}>Reply</button>
          )}
        </footer>

        {showReplyForm && (
          <CommentForm parentId={comment.id} onSubmit={() => setShowReplyForm(false)} />
        )}

        {comment.replies?.map(reply => (
          <ul key={reply.id}><CommentItem comment={reply} depth={depth + 1} /></ul>
        ))}
      </div>
    </li>
  );
}

Why Custom Over Off-the-Shelf Widgets?

Criterion Custom Solution Disqus / Commento
Data control Full None (third-party)
Performance Optimized for your stack Extra HTTP request
Customization Unlimited Limited
Cost Development, then free Freemium / ads
GDPR / Privacy Full compliance Risks
Implementation variant Nesting Moderation Likes Timeline
Basic Flat Automatic No 3-4 days
Standard Up to 3 levels Automatic + manual Yes 5-7 days
Premium Up to 5 levels Custom rules + AI filter Yes + notifications Up to 10 days

Process

  1. Analysis — discuss requirements: nesting, moderation, notifications, auth integration.
  2. Design — DB schema, API endpoints, React components.
  3. Implementation — backend (Laravel), frontend (React), tests.
  4. Testing — load testing (1000 comments), spam filter verification.
  5. Deployment — Docker image, CI/CD, cache configuration.

Timeline and Cost

  • Basic system (flat, moderation): 3–4 days
  • With nesting, likes, notifications: 5–7 days
  • With social integration and custom anti-spam: up to 10 days

Cost is calculated individually — we assess your project within an hour. A custom comment system pays off in 2–4 months compared to paid subscriptions. Get a consultation on integrating a comment system into your project. For an accurate estimate, contact our engineer.

A custom comment system is an investment in user experience quality and independence from third-party services. We design for your scale: from a small blog with 50 comments per day to high-load platforms with 10,000 messages per day. The architecture is the same; only Redis caching parameters and horizontal scaling strategy change.

What's Included

  • Backend source code (Laravel) and frontend (React) with unit tests
  • API documentation and database structure
  • Docker environment setup and CI/CD pipeline
  • Integration with your authentication system
  • Access to a private repository
  • Team training (2–3 hours)
  • One month of technical support after launch

7+ years of web development experience, 50+ projects with custom comment systems. We guarantee transparency and quality.

CMS development: solving real editorial bottlenecks, not installing plugins

A news publisher had a WordPress site with 5 editors. Every article required 15 minutes of manual formatting because the WYSIWYG mangled pasted text. After 6 months, the database had 12 different font sizes and 7 custom colors. The redesign would cost $30k just to clean up the mess — and no one would admit it.

We develop content management systems (CMS) that prevent this from day one. Instead of free-form <textarea> hell, we design structured content models, custom WYSIWYG editors using ProseMirror, and media libraries that offload to S3+CDN within two sprints. This is CMS development without shortcuts.

When is headless CMS justified and when not?

Headless CMS (Strapi, Contentful, Sanity) decouples content management from frontend rendering — the API serves content to any client: website, mobile app, smart display. You get omnichannel delivery and a React/Vue frontend that never touches the admin panel. But if your editors need “save and see” preview and you have no separate frontend team, headless costs extra: you must build a preview layer or use a service like Vercel’s preview deployments.

Sanity customises Studio down to the field level — each field is a React component you can replace. Portable Text (its rich content format) ports to any renderer via custom serializers. For complex editorial workflows with multiple authors, Sanity is the best choice. Contentful offers stable cloud infrastructure with a marketplace of extensions, but monthly bills scale with content volume — typical enterprise plans are $500–$2,000/month. Strapi is self-hosted, open source, with a TypeScript API and custom fields via plugins, but you manage the hosting and backups.

Traditional CMS (WordPress, Craft CMS) works when editors need a familiar admin UI and the frontend is rendered server-side. Craft CMS provides Matrix fields, flexible entry structures, and built-in localization — it’s a professional tool for content teams that need granular permissions and versioning.

How do we build a WYSIWYG editor that doesn’t break layout?

The editor is the most complex component — not a <textarea>. The sweet spot is Tiptap, built on ProseMirror. Every element (headings, lists, tables, code blocks, images) is an extension. Collaborative editing via Yjs works out of the box. Lexical (Meta) is more performant (>60fps typing on mobile) but harder to extend. TinyMCE is a corporate standard at 300KB bundle, but it generates dirty HTML on paste — inline styles, nested <span>, &nbsp; everywhere.

The root cause: pasting from Word. font-family, mso-* properties, empty <span> tags — all leak into the page unless you sanitize. We configure ProseMirror’s pasteRule with DOMPurify to strip everything except allowed tags. Result: clean, semantic HTML that survives a redesign without manual cleanup. Editors save 2–4 hours per week per person.

Media library: from upload to CDN with transformation

Saving files to the server disk is the classic mistake. The disk fills, scaling fails, and CDN becomes impossible. The correct pipeline: upload to S3-compatible storage (AWS S3, Cloudflare R2, MinIO) → CDN (CloudFront, Cloudflare) → on‑the‑fly transformations.

Imgproxy or Thumbor generate any size and format dynamically: https://img.example.com/resize:800:600/format:webp/plain/s3://bucket/photo.jpg. The original lives once, derivatives never occupy disk. Cloudflare Images costs $5 per 100k images, including transformations. Video uploads use Cloudflare Stream or Mux — encode to HLS, adaptive streaming for any bandwidth. Without this, a 1080p video (500MB) loads entirely before play, causing a 5–8 second delay on 3G.

What’s included in media library development

Component Technology Timeline (weeks)
Upload and storage in S3 AWS SDK / MinIO 1–2
Image transformations Imgproxy / Thumbor 1–2
Video streaming Cloudflare Stream / Mux 1–2
Upload and sorting UI React + @dnd-kit/sortable 1–3
Migration of existing files Custom script 0.5–1

Why structured content outperforms free-form HTML

Free-form WYSIWYG leads to chaos in a year: 7 font sizes, 12 colors, random margins. Redesign requires manual cleanup of thousands of posts. Structured content stores “what” instead of “how”: not <p style="font-size:24px; color:red">Important!</p>, but a callout block with variant: warning. The CMS stores the structure; the frontend decides rendering. Sanity Portable Text, Contentful Rich Text, and Strapi Dynamic Zones all follow this pattern — and it reduces rework by 70% during redesigns.

Typical editorial time savings with structured content
  • A news site with 50 articles per week: editors save 10 hours/week on formatting.
  • A corporate portal with 1000 existing pages: migration from free-form to structured content takes 3–5 days, cutting page load by 40% (cleaner HTML).

Work process

  1. Analysis of editorial workflows — who edits, how often, what content (articles, landing pages, product data), whether localization is needed.
  2. CMS selection — based on scenarios, not trends. We compare headless vs traditional with a weighted matrix.
  3. Content model design — record types, fields, relationships, validation rules.
  4. Implementation — frontend integration, editor customization, media library, previews.
  5. Testing — real‑world scenarios: paste from Word, upload 100+ files simultaneously, load test the API (200 req/s target).
  6. Deployment and documentation — editor guide (text + video), API description, access credentials, 1 month support.

Timelines and budget

Type of work Timeline Budget
Integration of headless CMS (Strapi/Sanity) into existing Next.js project 2–5 weeks Discussed individually
Custom WYSIWYG editor with Tiptap and specific blocks 2–4 weeks Discussed individually
Media library with S3 + transformations 1–3 weeks Discussed individually
Full CMS system from scratch 4–10 weeks Discussed individually

Budget is calculated individually after an audit. Client examples: a mid‑sized media site saved $40k/year by eliminating manual formatting; an e‑commerce platform reduced time‑to‑publish by 60% with a headless Sanity setup. Contact us for a free project estimate.

What you get after delivery

  • Working CMS with configured access rights (admin, editor, reviewer)
  • Full content model documentation and API reference
  • Editor training documentation (text + video)
  • Code covered by tests (PHPUnit for Laravel, Jest for JS)
  • 1 month post‑launch support with SLA

Our experience and guarantees

Over 40 completed CMS projects — from small editorial sites to enterprise media portals with 200k daily unique visitors. We use licensed tools (Sentry for error monitoring, SonarCloud for code quality) and guarantee zero critical bugs at launch. All code is version‑controlled and deployable via CI/CD.

For your specific needs, contact us to discuss requirements. We’ll provide a technical proposal within 2 business days.