Wikipedia:Edit filter/Requested/Archive 6

Long term abuse case
Black Kite (talk) 10:45, 14 February 2015 (UTC)
 * Task: Filter to prevent addition of "techno" to genres from given IP ranges. Something like User:Black Kite/filter greek (these are the correct ranges).  Thanks.
 * Reason: Per Long-term abuse/Techno genre warrior from Greece.
 * Log only for now at Special:AbuseFilter/663. Sam Walton (talk) 11:37, 14 February 2015 (UTC)
 * Altered to only check for additions, other flagged edits seem to be correct. Give it another week. Sam Walton (talk) 13:28, 14 March 2015 (UTC)
 * Can you check whether edits made since 14 March are all indicative of this user and are disruptive enough for the filter to be set to disallow? Or is log only sufficient? Sam Walton (talk) 00:14, 21 March 2015 (UTC)
 * ; as far as I can see every one of those is abuse and very typical of the IP editor (works in bursts, targets particular articles). I would set the filter to disallow as it seems to be working properly. Black Kite (talk) 21:48, 7 April 2015 (UTC)
 * I'll consolidate the conversation here but note that Binksternet has provided a great analysis of the hits thus far at User talk:Binksternet. Given the feedback from you both I think it's definitely a good idea to switch to disallow. As for the edits we missed, I'm not sure I'm confident enough to broaden the filter by much. We're already covering a large number of IPs and I worry that including more common words like house and disco will throw up false positives, which we really want to avoid when disallowing. As long as we're disallowing some edits and able to catch the IPs for reverting missed edits and/or blocking then I think this filter is working well. Per the directions at the LTA page I've set this filter to report IPs to AIV. Sam Walton (talk) 22:04, 7 April 2015 (UTC)
 * I agree that trying to enact "disallow" from words such as house and disco will rack up too many false positives. At the same time, I would like to see a "no action" filter logging any edits from those IP ranges if there is the word techno in the article. Can we have two filters, a narrow one set to disallow techno additions and a wider one set for only logging? Binksternet (talk) 00:13, 8 April 2015 (UTC)
 * ,; any reason why the filter has been set back to log-only? I only noticed it had been tripped today because Z-Bot flagged it up. Black Kite (talk) 13:46, 20 April 2015 (UTC)
 * I did some tweaking and wanted to make sure it worked as intended first. I see that we've got an accurate hit on 19 April, so I've set it back to disallow. Best &mdash; MusikAnimal  talk  14:50, 20 April 2015 (UTC)
 * OK, thanks! Black Kite (talk) 10:40, 2 May 2015 (UTC)

Brian Thompson vandal
- Ron h jones (Talk) 20:35, 4 March 2015 (UTC)
 * Task: Prevent a set of names being added to articles
 * Reason: There is an IP vandal (usually on a blackberry address) who keeps changing CEOs on various articles to...
 * Brian T. Thompson
 * Brian Touche Thompson
 * Brian Toussaint Thompson
 * Brian Thompson Vice Chairman
 * Brian To us saint Thompson
 * It was brought to my attention by User:Bahooka at AIV (but there are others watching out for him) - see also User_talk:Bahooka. I did find the following item - User_talk:NawlinWiki/Archive_89 - but it does not seem to have resulted in any edit filter (or if it did, it's not working).
 * User:ThePhantomBot has been setup to detect this user. Currently this report is linked to as the evidence of long term abuse, is there an LTA case? Phantom Tech  (talk) 00:46, 26 March 2015 (UTC)
 * No idea. I arrived rather late on the scene - I suspect User:Bahooka could give you more information Ron h jones (Talk) 20:54, 26 March 2015 (UTC)
 * Created log only for now at Special:AbuseFilter/674. Will probably need some tweaking with the range of middle names used. Sam Walton (talk) 22:05, 29 March 2015 (UTC)
 * Besides a brief period of false flags (I made a bad change and didn't notice for a few hours), the filter seems to be working well. What do you think would be the best thing to do now, disallow edits entirely or report to AIV? Sam Walton (talk) 09:09, 4 April 2015 (UTC)
 * It's a dynamic IP, he'll keep switching addresses - just disallow edits, I think Ron h jones (Talk) 14:57, 5 April 2015 (UTC)
 * Alrighty, ✅. Lets see how that goes, please help me keep an eye on IPs caught in the log in case any edits slip through. Sam Walton (talk) 15:00, 5 April 2015 (UTC)

Aas Mohamad Ali Khan Abbasi

 * Task: Find variants of a name and log. Userspace, new articles that get quickly deleted, existing articles.
 * Reason: User creating many socks: User:Anna Frodesiak/Orange sandbox. He drops his name either as a username, userpage content at a userpage (often an unrelated username), in fake or promo articles, and sometimes as a minor cast member in bollywood articles. An idea of the variants can be seen in the Orange sandbox. Many thanks for your consideration. Anna Frodesiak (talk) 11:18, 21 February 2015 (UTC)


 * I can probably find all with searches, so feel free to decline this one. Anna Frodesiak (talk) 11:24, 21 February 2015 (UTC)
 * are you sure? This wouldn't be too hard a filter to set up. Sam Walton (talk) 20:08, 25 February 2015 (UTC)
 * Hi, Sam! :) Do you mean a few minutes of effort? Would it make the servers glow orange and catch fire or even slow things down a teensy bit? If yes and no, then yes please. :) Anna Frodesiak (talk) 20:12, 25 February 2015 (UTC)
 * Well, I was going to say that there would be no fire in sight, but given that I just created the filter at Special:AbuseFilter/666 I can't make any promises. Log only for now! Sam Walton (talk) 23:09, 1 March 2015 (UTC)
 * ✅ Working fine. Sam Walton (talk) 13:18, 14 March 2015 (UTC)

File:http//

 * Task: Warn new users trying to add  to any page.
 * Reason: Help users to do the right thing and prevent some useless edits. This would help avoid inline linking of images. A discussion of how this is a problem is at Bot requests. See Edit filter/Requested/Archive/2 for a similar application. -   t  u coxn \ talk 03:31, 10 January 2014 (UTC)
 * We already have Special:AbuseFilter/220 to do basically what you're asking for. Jackmcbarn (talk) 03:49, 10 January 2014 (UTC)
 * I noticed. It's not catching everything that it should. Here are several diffs it didn't catch on 9 January alone (I can find more, especially for other days): 1, 2, 3, 4, and 5 which is a page creation. I've noticed some edits that have the summary "(Tag: Incorrectly formatted external link or image)" but those listed above don't have that. Also, It doesn't seem that the filter is deterring this improper way of inserting files into articles (see Es Bua log 1 and Es Bua log 2, showing an edit going through after the filter caught it). Please correct me if the abuse filters are not supposed to provide deterrence -- I'm learning still about them. Thanks for your help! -   t  u coxn \ talk 08:05, 10 January 2014 (UTC)
 * It looks like File:|Image:| should be added right before both occurrences of &lt;img. Jackmcbarn (talk) 15:24, 10 January 2014 (UTC)
 * I can't say whether or not that's the correct change but it might be worth a try. It would also be good to upgrade the warning. The notes say "Kill warning, it can be fixed later -P". After correctly implementing the  change would be a good time to try this repair -- or if the warning was re-implemented (Changes) a stronger warning would be better. Thanks! -    t  u coxn \ talk 02:31, 11 January 2014 (UTC)
 * See these diffs (certainly 1 and 2; but also 3, 4, and 5 which might not get caught by this new code) for recent examples of hot-linked images that editors tried to add to articles. Users making constructive edits are still waiting for an edit filter manager or an administrator to implement this change.... Thanks in advance! -    t  u coxn \ talk 01:02, 19 January 2014 (UTC)
 * This is still happening and implementing the filter change would help. See the following diffs (and these come just from today's edits): 1, 2, 3, 4, 5, and 6. Thanks in advance for your help. -   t  u coxn \ talk 12:46, 26 January 2014 (UTC)
 * , did you get around to implementing the solution you proposed above? Hard to tell. Thanks, Sam Walton (talk) 00:29, 16 February 2015 (UTC)
 * Yes. Jackmcbarn (talk) 01:09, 16 February 2015 (UTC)

Spam links on disambiguation pages

 * Task:


 * When unconfirmed users edit disambiguation pages, prevent them from adding any external links (unless a link includes the four letters "wikt").


 * Reason:


 * I once was editing the OCN disambiguation page, and I noticed that a COI user had added an inappropriate link to the page. (Diff.) And surely similar problems have happened on other disambiguation pages too. Is this a systemic problem? I don't know. Dear all: Please provide your input.


 * The relevant guideline says that external links (except to Wiktionary) are inappropriate. So you should only allow external links to  or   or.


 * —Unforgettableid (talk) 01:13, 28 November 2013 (UTC)
 * Support. Disambiguation pages are intended to function solely as navigational devices to guide users to the right Wikipedia topic; an external link is no more appropriate on a disambiguation page than it is on a redirect page. Note, however, that any restriction will have to allow links to Wikipedia pages in other languages, as we do allow those. bd2412  T 20:49, 6 December 2013 (UTC)
 * Log only for now at Special:AbuseFilter/657. Haven't specified unconfirmed only for now. Sam Walton (talk) 12:03, 22 January 2015 (UTC)
 * Unforgettableid, BD2412 the filter seems to be working relatively well, it's catching a fair amount of spam. The only issue is with references; some disambiguation pages contain legitimate references, and changing those causes a false flag. I could change the filter to not flag when tags are in the diff, but it seems some spammers just put their spam link in a reference. I'm not sure what to do about that yet but suggestions are welcome. Sam Walton (talk) 21:09, 25 January 2015 (UTC)
 * Actually, disambiguation pages are not supposed to contain references at all. They are supposed to be more or less like the index in a paper book, listing nothing more than the articles reflecting the terms that the reader might have been looking for, in order to send the reader quickly on their way. Editors adding references to a disambiguation page often do so because the topic is not notable enough to merit an article (or be mentioned in another article), and therefore should not be in the encyclopedia at all. bd2412  T 21:18, 25 January 2015 (UTC)
 * This is true. I saw this edit and thought surname pages, which often contain a reference or two about the surname, might give false flags. That said, they should be tagged with the surname template not disambiguation and so generally won't be an issue. I've started a warning message at MediaWiki:Abusefilter-warning-EL-in-disambiguation. Let me know what you think and feel free to make changes. Sam Walton (talk) 21:56, 25 January 2015 (UTC)
 * ✅ Filter set up to warn & tag. Sam Walton (talk) 20:33, 2 February 2015 (UTC)

Deny posting of "Annabeth Chase" to List of people from San Francisco

 * Task: disallow posting of "Annabeth Chase" (with or w/o caps) to List of people from San Francisco
 * Reason: Vandalism persisting for months, posted by nearly a dozen different IPs and users (e.g., ,), acknowledged by the vandal in the first place as nonconstructive. Reversions, blocks, and page protections have all been applied over and over, and are unnecessarily time-consuming if this could just be disallowed. postdlf (talk) 22:12, 1 December 2014 (UTC)
 * I unprotected the page and created such a filter. It's log only for now, but once it gets a hit and I see there's no FPs (which I doubt will be a problem for a filter this specific, but better safe than sorry), I'll set it to disallow. Jackmcbarn (talk) 22:57, 1 December 2014 (UTC)
 * Thanks, what happens next? As the filter creator, do you get notifications when there's a ping, or do you just have to check it periodically? postdlf (talk) 23:02, 2 December 2014 (UTC)
 * There's no notifications, unfortunately. The best you can do is to check [ the log] once in a while. Note that I have now set it to disallow. Jackmcbarn (talk) 03:35, 7 December 2014 (UTC)
 * ✅ and operational. Sam Walton (talk) 14:56, 20 January 2015 (UTC)

Driver 3 - Liv and Maddie

 * Task: On the Driver 3 article, block any edit that attempts to add the text Liv and Maddie or a link to the Liv and Maddie article.
 * Reason: Since 27 October 2014, 88% of the edits to this article are either an IP editor adding this text/link, or a user reverting it. The editor uses different IP addresses in different ranges, so IP or range blocking will be ineffective, an edit filter will be a better solution and will be targeted specifically at this vandal. - X201 (talk) 09:13, 19 January 2015 (UTC)
 * ✅ Jackmcbarn (talk) 16:57, 19 January 2015 (UTC)
 * Thanks. - X201 (talk) 17:10, 19 January 2015 (UTC)

Jetix filter

 * Task - Block any edits by new users or IPs that use terms like "Jetania" and "Jetanian".
 * Reason Due to the long term abuse by HoshiNoKaabii2000 socks. Luke no 94  (tell Luke off here) 23:57, 8 January 2015 (UTC)
 * Lukeno94 I'm going to try to take a look at this one, but being my first Edit Filter I might be a little while with it! Sam Walton (talk) 21:56, 17 January 2015 (UTC)
 * That's not a problem :) It's sporadic vandalism, but it is a very long-term issue. Luke no 94  (tell Luke off here) 22:12, 17 January 2015 (UTC)
 * ✅ at Special:AbuseFilter/654. I'm making it log only for a few days to make sure it's working properly, but tests with known accounts flag correctly. Sam Walton (talk) 11:03, 18 January 2015 (UTC)
 * Well it didn't pick up anything it shouldn't have today & did flag the vandal, so I'm going to add it to Mr.Z-bot's filter list to be reported to AIV when the filter is tripped. Sam Walton (talk) 19:47, 18 January 2015 (UTC)
 * Incorporated into Special:AbuseFilter/16. Sam Walton (talk) 18:47, 19 January 2015 (UTC)

'YOLO' and 'Swag' in Article namespace
- ♥ Solarra ♥ ♪ 話 ♪  ߷  ♀ 投稿 ♀  05:04, 26 June 2014 (UTC)
 * Task: Please add both of the words 'YOLO' (not case sensitive) and 'swag' (not case sensitive)
 * Reason:, huge amount of vandalism done to mainspace recently using both words. example.  Even if it was just a warning, it might cut back on the amount of the relevant vandalism.
 * There is a filter named ""Yolo Swag" Vandalism". Why is it private? It's just common vandalism. Can you make it public (considering that we've many other public filters for usual vandalism)? --Glaisher (talk) 09:50, 28 July 2014 (UTC)
 * You're right, no reason for it to be private. It's public now, see at Special:AbuseFilter/614. I intentionally did not filter the words "yolo" or "swag" by themselves, as at least during the first few days in log-only I got several false positives. On the contrary, something like "swaggg", "yolololo" or "yolo swag" is almost always going to vandalism. I will try to tweak the filter and put it back to warn/tag mode rather than disallow. Increasing the edit_delta might catch more instances as well. Thanks &mdash; MusikAnimal talk 14:25, 28 July 2014 (UTC)
 * MusikAnimal, do you consider this request completed? Sam Walton (talk) 12:24, 18 January 2015 (UTC)
 * As good as it's going to get, yes. I patrol recent changes regularly and still see "swag" a lot but there's far too many false positive to disallow that word. There's a wrestler with the same name, a few songs, and plenty of quotes. I think we're good to close this near 1-year old request! Thanks for cleaning up the backlog :) &mdash;  MusikAnimal talk 16:58, 18 January 2015 (UTC)

Moved the below discussion on a similar proposal from below to here. Sam Walton (talk) 12:40, 18 January 2015 (UTC) Thanks &mdash; MusikAnimal talk 16:49, 17 October 2013 (UTC)
 * Task: Prevent addition of the exact adjacent words "yolo swag" (any capitalization) by unconfirmed users and IPs.
 * Reason: This is a common slang term that has quickly become a popular vandalistic addition to any article or page of any subject. I can't imagine a situation where such an addition would be considered constructive, unless we were documenting the term itself, hence why I recommend applying the filter to unconfirmed users. Our RCPs generally quickly remove this vandalism, but why bother when we can prevent it with a filter?
 * Note the existence of User:YOLO Swag. He's not edited since January, but he's been around since 2006, and he sometimes will go on months-long breaks and then return, so we shouldn't assume that he won't be back.  We definitely don't want to prevent people from talking about him in pages outside of mainspace.  Nyttend (talk) 21:50, 27 October 2013 (UTC)
 * Good point, I'd say prevention solely within the article namespace will suffice. &mdash; <b style="color:black;">MusikAnimal</b> <sup style="color:green;">talk 15:02, 28 October 2013 (UTC)
 * ✅ Reaper Eternal (talk) 13:12, 16 November 2013 (UTC)
 * How about [//en.wikipedia.org/w/index.php?title=Portal:History/Featured_article/15&diff=prev&oldid=591136576 this edit] in portal space? -- John of Reading (talk) 17:03, 17 January 2014 (UTC)
 * ❌ I am still seeing this get through from IPs and unconfirmed users. Examples  and my own test edit when logged out with  &mdash; <b style="color:black;">MusikAnimal</b> <sup style="color:green;">talk  16:38, 23 January 2014 (UTC)
 * It's still appearing. Epicgenius (talk) 15:42, 10 February 2014 (UTC)
 * Still happening if we can also add yolo and swag themselves as protections in the main article space, it would be fantastic :-) <b style="color:#FC89AC;font-family:Comic Sans MS;">♥ Solarra ♥</b> <sup style="color:green">♪ 話 ♪  ߷  <sub style="color:#006400">♀ 投稿 ♀  07:35, 25 June 2014 (UTC)

Ref desk protection

 * Task: Prevent edits from specified IP ranges to the reference desk pages, including its talk pages
 * Reason: The ref desk is unique in that page protection defeats the purpose of the project. Recent persistent trolling from the "Venezuala troll" has caused the desks to be repeatedly protected, the very thing we don't want to do.  Range-blocking has proved ineffective as the range available is much too big to shut him out and the more range blocks that are done the more the collateral damage grows.  However, an intersection of IP range and ref desks would have very little to zero collateral damage.  Spinning  Spark  00:19, 13 June 2014 (UTC)
 * I have created a filter myself (filter 618) which is currently running in logging mode only. Any checking you can do on it would be welcome.  Spinning Spark  09:42, 18 June 2014 (UTC)
 * ✅ Seems to be working fine. Sam Walton (talk) 12:26, 18 January 2015 (UTC)

The elevator vandal

 * Task: Block creation of vandal talk pages of subpages of Portal:Current events, referring to elevators.


 * Reason: Since August 2012, an IP-hopping editor, known as "the elevator vandal", has been repeatedly creating pages with titles of the format Portal talk:Current events/2005 March 10, Portal talk:Current events/2009 August 29, etc. These pages contain trivial little stories, virtually all of which refer to riding elevators, and contain one or both of the words "elevator" and "elevators". All the IP addresses that I know of are listed at User:JamesBWatson/The elevator vandal. They are registered to the ISP Canaca-com, in either Ontario or Montreal. Almost all of them start 66... or 67... or 69..., but there is also 173.248.236.19, - JamesBWatson (talk) 11:45, 11 May 2013 (UTC)


 * I will work with JamesBWatson and John of Reading on implementing this. -- Gogo Dodo (talk) 04:56, 23 October 2013 (UTC)


 * I live in Ontario. I don't think http://www.canaca.com/ is an ISP: it looks like it's a webhost. Have you tried phoning them up and speaking with their abuse department? Or, could you block anonymous edits from that entire webhost's IP range? (Note: There exists a small ISP with a similar name, "Acanac". But as far as I know, Canaca-com is not an ISP.) Cheers, —Unforgettableid (talk) 07:08, 4 November 2013 (UTC)


 * The netblocks are registered to Canaca-com Inc., but many of the IPs are registered to acanac.net/acanac.com which provides DSL and cable modem service. I believe this vandal is using the DSL service. I plan to have the edit filter deny certain edits from the netblocks. I have no plans to phone or contact the ISP, because, well to be honest, I really don't want to talk to anybody about it. I know that there are people that have tried to contact ISPs, but I can't really see this being a high priority for an ISP, especially since they won't be able to see the "abuse" in question. -- Gogo Dodo (talk) 05:17, 5 November 2013 (UTC)


 * He's back! See Portal talk:Current events/2007 September 21. -- John of Reading (talk) 20:24, 10 November 2013 (UTC)


 * Thanks! The filter has now been written as Special:AbuseFilter/596. Filter is set to log-only mode to make sure the filter is working properly. Once the next IP is picked up by the filter and there are no false positives, I will set the filter to deny the edit. -- Gogo Dodo (talk) 06:13, 11 November 2013 (UTC)
 * Thanks. We'll see what happens. I know very little about regexp, but it looks to me as though this one may only look for the word elevators in the plural, not singular elevator. Is that right? If so, it might be a good idea to change it. Or have I misunderstood the working of "rlike"? JamesBWatson (talk) 08:11, 11 November 2013 (UTC)


 * It looks for both. "rlike" is a regexp and the "?" means that the previous character is optional so it looks for "elevator" or "elevators".  Technically it matches a little more than that since I didn't use any word boundaries, but at the point it is doing the word matches, the lack of word boundaries should be fine as the chances of a false positive are pretty slim.  You can use the debugging tool to see what a statement matches.  If you test "elevator" rlike "elevators?" and "elevators" rlike "elevators?", you will see that they evaluate to 1. -- Gogo Dodo (talk) 18:34, 11 November 2013 (UTC)


 * Thanks for the clarification. As I said, I know very little about regexp, and it seems that it was the ? that I didn't understand. JamesBWatson (talk) 12:14, 13 November 2013 (UTC)


 * ✅  After the first hit on the filter and with no false positives for the past few days, I have set the filter to disallow edits.  Hopefully that will put at end to this. -- Gogo Dodo (talk) 06:47, 13 November 2013 (UTC)


 * He's back again after the filter was disabled: Portal talk:Current events/2007 December 15. -- John of Reading (talk) 08:32, 12 January 2014 (UTC)


 * ✅  I thought this might happen with how long he has been at it.  I re-enabled the filter. -- Gogo Dodo (talk) 06:09, 20 January 2014 (UTC)


 * Unfortunately he's switched to portal pages [//en.wikipedia.org/w/index.php?title=Portal:Current_events/2009_February_28&diff=592729438&oldid=397370548 diff]. -- John of Reading (talk) 07:15, 28 January 2014 (UTC)


 * Interesting. That corresponding Portal talk page is one that I protected from recreation. I adjusted the filter to handle the target shift. -- Gogo Dodo (talk) 23:12, 28 January 2014 (UTC)


 * I hope you haven't accidentally blocked [//en.wikipedia.org/w/index.php?title=Special%3ASearch&profile=advanced&search=elevator+intitle%3Acurrent&fulltext=Search&ns100=1&profile=advanced genuine news items about elevators]. -- John of Reading (talk) 20:52, 29 January 2014 (UTC)


 * It shouldn't be a problem. -- Gogo Dodo (talk) 05:35, 30 January 2014 (UTC)

Dan Howell
-  Acroterion   (talk)   00:51, 10 September 2012 (UTC)
 * Task: Flag insertion of "Dan Howell" and be able to disallow the edit if necessary.
 * Reason: A flood of throwaway accounts and IPs have been inserting references to Dan Howell into random articles, with particular focus on Delia Smith (see history), then moving on to random articles after that was semi-protected. Inappropriate article creation, general silliness from a wide range of UK addresses. Since the entire meme depends on Dan Howell, it should be easy to filter for it. "Dan" alone would be harder to deal with. An emphasis on "Maltesers" is presumably significant to Dan and his entourage. See, , ,.
 * Added to filter 58. Sole Soul (talk) 03:00, 10 September 2012 (UTC)
 * Thanks: it's intercepted three accounts. You might want to add "Phil Lester" for the time being, since that's showing up in the meme too.   Acroterion   (talk)   14:25, 10 September 2012 (UTC)
 * More coming in: see Milkshake, Falling (accident), Phan. "Daniel Howell" will need to be intercepted.  Acroterion   (talk)   16:12, 10 September 2012 (UTC)
 * ✅ Reaper Eternal (talk) 16:32, 10 September 2012 (UTC)
 * Thanks, glad to see this "danisnotonfire" might be a good term to add too. Mark Arsten (talk) 17:21, 10 September 2012 (UTC)
 * ✅ too. Reaper Eternal (talk) 17:26, 10 September 2012 (UTC)
 * Oh thank heavens!! --Sue Rangell &#91; citation needed &#93; 03:51, 29 October 2012 (UTC)

Dan Howell (2nd request)

 * Task: Filter "Dan Howell" / "danisnotonfire"
 * Reason: We need to double check the "Dan Howell" / "danisnotonfire"-related vandalism filter. I was told this would be a good thing to request since it is already supposed to be filtered out. --Sue Rangell &#91; citation needed &#93; 03:43, 30 October 2012 (UTC)
 * Nobody has replied to you for a year. I think this is because we don't understand your request. 1. Is the vandalism still ongoing? If so: 2. Are you requesting that a new filter be created? 3. Or are you requesting that a change be made to an existing filter? 3a. If so, do you happen to know the filter number? 3b. Are there certain edits which the filter is failing to catch? 3c. Could you please provide diffs? 3d. Who told you this would be a good thing to request? 3e. Could you please point us to the discussion? I have just dropped you a talkback template to point you here. Cheers, &mdash;Unforgettableid (talk) 23:24, 30 September 2013 (UTC)
 * It's been too long. LOL. I no longer remember the incident that prompted this. Feel free to mark this issue as closed. Thank you.--<span style="white-space:nowrap;text-shadow:#ff55ff 0em 0em 0.8em,#55ffff -0.8em -0.8em 0.9em,#ffff55 0.7em 0.7em 0.8em;color:#ffffff">Sue Rangell ✍ ✉ 18:29, 1 October 2013 (UTC)

Delete Article Feedback filters
- Jackmcbarn (talk) 19:29, 3 March 2014 (UTC)
 * Task: Disable and mark deleted the following filters:
 * 458
 * 460
 * 463
 * 472
 * 473
 * 474
 * 487
 * 520
 * 521
 * 604
 * Reason: The ArticleFeedbackv5 extension has been removed, so no filters in the "feedback" group have any use anymore.
 * ✅ Legoktm (talk) 20:25, 3 March 2014 (UTC)

Filter 380: Multiple obscenities
- Jackmcbarn (talk) 19:56, 6 December 2013 (UTC)
 * Task: Change \b(p|P)ussy| to \b(p|P)ussy\b|
 * Reason: Edit filter/False positives/Reports
 * ✅. Sole Soul (talk) 12:03, 31 December 2013 (UTC)

Recursive redirect
- Magioladitis (talk) 16:35, 11 September 2013 (UTC)
 * Task: Warn when pagetitle of a redirect matches redirect target.
 * Reason: Similar to Filter 163. Today I cleaned 9 such cases.
 * ✅ Reaper Eternal (talk) 13:24, 16 November 2013 (UTC)

nowiki in main namespace

 * Task: The filter would look for  tags in the main namespace, and tag the edits with a 'nowiki' tag.
 * Reason: There is seldom any reason to insert nowiki tags in the main namespace. This filter will allow users to track edits where nowiki tags were added by the user by mistake (with the wikitext editor toolbar) or automatically by VisualEditor. This will be particularly useful to track "dirty diffs" generated by VE. guillom 09:51, 4 July 2013 (UTC)
 * I think something like this should work:

article_namespace == 0 & " " in lcase(added_lines)
 * <span style="font-family: Georgia, Garamond, serif;"> Kudu ~I/O~ 02:59, 7 July 2013 (UTC)
 * FYI, there's now such a filter on the French Wikipedia: fr:Spécial:Filtre antiabus/171 (in case it's useful). guillom 17:05, 9 July 2013 (UTC)
 * ✔️ This is Special:AbuseFilter/550. — This, that and the other (talk) 12:45, 18 July 2013 (UTC)

Exempt confirmed users from Filter 34: New or unregistered user blanking someone else's user or user talk page
Jackmcbarn (talk) 03:21, 27 September 2013 (UTC)
 * Task: Make Filter 34: New or unregistered user blanking someone else's user or user talk page not apply to users in the "confirmed" group.
 * Reason: Edit filter/False positives/Reports and Edit filter/False positives/Reports
 * ✅ Reaper Eternal (talk) 13:15, 16 November 2013 (UTC)

Feedback: Adding email addresses
- Se4598 (talk) 20:39, 19 January 2013 (UTC)
 * Background: It's about this filter (Feedback: Adding email addresses): At November 20, 2012 the filter was public visible and the german wikipedia copied it because of their introduction of AFTv5.
 * Task: consider replaceing  with   (but i have only little knowledge about regexp)
 * Reason: We've discovered that domains like t-online.de (with a hyphen) were not detected.

✅ Thanks, Triplestop (talk) 03:59, 21 September 2013 (UTC)


 * Just FYI: There is a regexp for email addresses at the WHATWG HTML5 specification. It can catch things the above regexp does not catch (for instance, the use of + or - in the local part). --cesarb (talk) 01:46, 24 September 2013 (UTC)

Detect (and warn) insertion of "unknown" symbol U+FFFD
Thanks,  Ignatz mice•talk 00:59, 23 September 2013 (UTC)
 * Task: This filter should detect when the Unicode symbol U+FFFD: � is inserted into an article, for easy cleanup later. If possible, it could display a warning before save.
 * Reason: See this discussion at VPT.


 * ✅ Special:AbuseFilter/590 Triplestop (talk) 04:01, 23 September 2013 (UTC)

OverBlood
✅ I finally got to the root of this issue myself. It was very difficult since I'm not an admin and I couldn't see from the logs what the filter's number was nor did I have access to the filter details once I knew its number, but an admin at the Village Pump (technical) tracked down the editors who maintain the filter in question and although one of them is on semi-retirement, the other was able to restore functionality for this filter which had failed 7 months ago. Thanks for all the support. This takes a lot off my mind. -Thibbs (talk) 21:19, 27 February 2013 (UTC)
 * Task: This is really a request to move a filter from one article to another. The original filter was intended to curb a persistent stream of vandalism at this article where the vandals change the name of the main character from "Raz Karcy" to "Wienerless Steve". Because these vandals are often poor spellers the term "Weinerless Steve" ("ei" rather than "ie") is often used and filter end-runs like "Steve without a Wiener" are also frequently used. I'm not sure how the old filter works, but it should be enough to filter for the words "wiener" and "weiner" in any context. Anyway the request is to move the filter from "Overblood" (the old name of the article) to its new name, "OverBlood" (capitalized "B" in "Blood").
 * Reason: The old filter is protecting a redirect and the new article has no filter on it and has become the subject of renewed vandalism since August. This whole issue has been going on since January 4, 2011 (close to 2 years). The logs for the old page show a long history of ineffective page-protections. The filter was the only thing that worked. -Thibbs (talk) 16:54, 20 December 2012 (UTC)

The word 'cocksucker'
There may be some valid use cases for adding the word "cocksucker" (case-insensitive, singular and plural) to articles (pornography articles, perhaps, as well as reported speech), but it probably ought to be filtered in the article namespace for non-confirmed users or even just IP users. —Tom Morris (talk) 21:49, 8 January 2013 (UTC)
 * ✅ Callanecc (talk • contribs • logs) 06:21, 25 September 2014 (UTC)

Racist vandalism against Lewis Hamilton

 * Task: Prevent editors adding the word "baboon" to articles containing the text "Lewis Hamilton"
 * Reason: The racist vandal who prompted the creation of edit filter 311 a while ago is apparently back. For the past few days they have amused themselves by adding "baboon" in the vicinity of the text "Lewis Hamilton" in the 2014 Formula One race articles ("baboon" is a racist slur against Hamilton, who is black) under a variety of accounts - as one account is blocked they simply create a new one. I think reviving edit filter 311 and tweaking it to prevent the addition of "baboon" (instead of "black baboon") should fix the problem. - DH85868993 (talk) 06:10, 9 September 2014 (UTC)
 * ✅ with a couple changes. Callanecc (talk • contribs • logs) 09:14, 9 September 2014 (UTC)

Tag articles moved from sandboxes to mainspace

 * Task: Tag when an editor moves an article from their sandbox into mainspace
 * Reason: Blackhat paid editors frequently create articles in sandboxes and then move them into mainspace in order to avoid NPP and even in some cases use other accounts to patrol them see for example: SPI 1 and SPI 2 (the Wiki-PR socks used the same trick). If we had a filter to tag when new accounts (say >100 edits) move articles into mainspace we might be should be able to spot these edits more easily. It's difficult to know how many false positives there would be, but if the filter could somehow be restricted to BLPs and company articles that would reduce these to a minimum. SmartSE (talk) 21:38, 24 August 2014 (UTC)
 * Testing it with my test filter (using a higher limit, since your intended targets can see the number you wrote here), to see how this looks. עוד מישהו Od Mishehu 19:20, 27 August 2014 (UTC)
 * Still testing, but you may want to take a look at Lambda architecture, Duong Dynasty (An Nam), NewsWatch TV, and Septum (cell biology) - I believe that these are all proper hits. עוד מישהו Od Mishehu 02:54, 28 August 2014 (UTC)
 * ✅ as filter 630. עוד מישהו Od Mishehu 14:01, 29 August 2014 (UTC)

Dishonest edit summaries filter

 * Task: Flag edits as "possible vandalism" or "possible false edit summary" (or whatever other label seems most fitting) IF the edit summary includes the phrase "fix typo", "fix grammar", "fixing typo", "fixing grammar" or variations thereof AND the editor is non-confirmed (IP or new editor) AND the edit changes the article's size by more than, say, 200 bytes.
 * Reason: Many vandals and trolls (particularly, IP-vandals/trolls and vandal-only accounts) try to slip in disruptive edits by labelling them as "typo fix" or similar. While the combination "fix typo" and a relatively large change in article size tends to attract scrutiny on its own, this relies heavily on the edit in question being noticed, which does not quite always happen. By having these edits tagged, not only are they less easily overlooked, it also gives an easy way to search for these edits. While the occasional actual typo-and-grammar-fixing resulting in such a large change exists (for example, [//en.wikipedia.org/w/index.php?title=List_of_Lepidoptera_of_Ukraine&diff=prev&oldid=594546606 this edit by me]), it is very, very uncommon. AddWittyNameHere (talk) 20:37, 12 August 2014 (UTC)
 * Example: to today's FA. -- Red rose64 (talk) 13:50, 13 August 2014 (UTC)
 * One likely exception: if a user tries to add a substituted template, and either mistypes the template name to the name of a non-existant template, or mistypes the word "subst", fixing this may result in a big diff size; it would also fit all the criteria mentioned above if done by a new user. עוד מישהו Od Mishehu 19:24, 27 August 2014 (UTC)
 * An other quite reasonable exception: A user does multiple things in a single edit, amnd states all of them. One happens to be a typo fix, and an other changes the length of the page significantly. As a single edit, it will be a hit if done by a new user. עוד מישהו Od Mishehu 19:51, 30 August 2014 (UTC)
 * Testing now at my test filter. עוד מישהו Od Mishehu 07:40, 31 August 2014 (UTC)
 * ✅ as filter 633. עוד מישהו Od Mishehu 07:27, 3 September 2014 (UTC)

Archive.is message
Jackmcbarn (talk) 18:29, 25 October 2013 (UTC)
 * Task: Give the archive.is filter a more specific reason as to why the link is disallowed.
 * Reason: A lot of users ending up posting FP reports because they have no idea what happened.
 * Does this still need addressing? Sam Walton (talk) 17:55, 22 January 2015 (UTC)
 * No, it's since been done. Jackmcbarn (talk) 01:19, 23 January 2015 (UTC)

Joy Richard Preuss

 * Task: Prevent edits containing the name “Joy Richard Preuss” and this persons bank account number (which can be seen in the [now-oversighted] edit: https://en.wikipedia.org/w/index.php?title=Balancing_test&diff=next&oldid=541649751)
 * Reason: Joy Richard Preuss is an, apparently mentally ill, aspiring something that spams the web with promotional nonsense (and his/her bank account information). We have a filter that prevents this on dawiki, which has been very successful at stopping him/her, but it appears that he/she has started spamming enwiki as well. Also, perhaps the edits he/she has made that contains his/her bank account information should be hidden, despite it being quite public already (it's all over the web due to the aforementioned spam). --Cgtdk (talk) 00:00, 5 March 2013 (UTC)
 * Special:AbuseFilter/534. Log only for now. Someguy1221 (talk) 11:27, 5 March 2013 (UTC)
 * Cgtdk, have you found any more edits recently? Over the last year I have requested oversight of all the ones I could find that give away personal information, although it's hard to find them in article histories (most get reverted quickly by other editors). There was a big batch which Someguy1221 very helpfully dealt with in the last day or two. bobrayner (talk) 13:34, 5 March 2013 (UTC)
 * I just rolled back a JRP edit, but it did not contain any sensitive information. Other than that and the one I posted in my original request, I have not seen any recently. --Cgtdk (talk) 13:46, 5 March 2013 (UTC)
 * ✅ Edit filter is active. Sam Walton (talk) 18:22, 22 January 2015 (UTC)

Restore filter 342 and list pages caught by it on Special:NewPages and Special:NewPagesFeed
- —Swpbtalk 18:35, 18 December 2014 (UTC)
 * Task: Re-enable filter 342 (redirect becoming article), and show pages caught by it on Special:NewPages and Special:NewPagesFeed. Apply to all pages in mainspace, and all non-autopatrolled editors (i.e., remove the editcount restriction).
 * Reason: See discussion at Village Pump: This will allow patrolling of what are, for all practical purposes, new content pages that currently bypass patrolling. Please advise if the second part requires developer action.
 * I think this needs closing first since there were some opposes and discussion. Additionally it seems software changes are needed before such a filter would be useful to anyone. Sam Walton (talk) 14:50, 20 January 2015 (UTC)
 * Special:AbuseFilter/342 re-enabled, log only for now. Sam Walton (talk) 00:25, 7 March 2015 (UTC)
 * ✅ Working correctly and phab request made. Sam Walton (talk) 13:30, 14 March 2015 (UTC)

Sockpuppeteer

 * Task Modify Special:AbuseFilter/483. It already records users creating their own user page, but it needs to record those creating it with their signature.
 * Reason When he creates a new sock, a prolific sockpuppeteer and WMF-banned editor almost always creates its talk page with his signature. The filter would provide an easy way of locating any socks which CheckUser cannot detect. I understand that the four tildes are not edit filter syntax, but it surely must be extremely easy to add a condition to this filter which pays attention to 2012, the current year in the new text. WilliamH UK (talk) 16:49, 25 August 2012 (UTC)
 * Actually, I think it is the reverse. The filter will detect the four tildes but not "2012 (UTC)". Sole Soul (talk) 14:18, 7 September 2012 (UTC)
 * That is correct. Reaper Eternal (talk) 03:06, 10 September 2012 (UTC)
 * Appears to be ✅ Sam Walton (talk) 13:23, 2 April 2015 (UTC)

Navbox directly added
- Magioladitis (talk) 07:52, 13 April 2015 (UTC)
 * Task: Check whether navbox was directly added in article namespace like, ,.
 * Reason: To replace with the correct template. It messes code for good by adding wrong categories, noinclude tags, etc.
 * I don't think this is adequate for an edit filter. If you want to track this happening you could search for "How to manage this template's initial visibility", which appears to show where this has happened. Sam Walton (talk) 11:57, 25 May 2015 (UTC)

Ref desk troll
- Jayron <b style="color:#090">32</b> 21:03, 17 April 2015 (UTC)
 * Task: Prevent IP addresses and new accounts (not yet autoconfirmed) from blanking sections of the Ref Desk. Recommend "disallow and report" so we can quickly block accounts.
 * Reason: See Sockpuppet investigations/CapriSon33333 for some background. A few weeks ago, a regular ref desk troll, who had been gone for some time, was blocked again for his trolling questions.  He took exception to this, and started massive DDOS-like attacks against the Ref Desks by rapidly and repeatedly blanking large sections of them as soon as they aren't semi-protected.  He has a massive sock puppet farm and apparently nothing better to do, because within minutes of being unprotected, he starts his rapid attacks which are impossible to control.  We don't want the ref-desks to be indefinitely semiprotected, but that's all we've been able to do to contain him.  A report at ANI caught the attention of a checkuser, who said he had a rangeblock he thought would work.  Apparently, it didn't.  The next step seems to be to try an edit filter.  I'm not so good on the technical aspects of writing an edit filter, but this doesn't seem like too hard of a filter to code for, just prevent any removal of text from the reference desks from non-autoconfirmed accounts and IPs, and report any accounts or IP addresses that repeatedly attempt to do so.  Thanks again for your prompt attention to this!
 * Actually, there is also the action "block", though it is very rarely used. --<b style= "color:red">T</b><b style= "color:#FF4200">L</b><b style= "color:#FF7400">2</b><b style= "color:#FFA700">2</b> (<i style= "color:green">talk</i>) 01:20, 18 April 2015 (UTC)
 * The abuse filter extension supports a "block" action, but that action is not presently enabled on enwiki. Dragons flight (talk) 23:14, 18 April 2015 (UTC)
 * I'm fine with manually blocking when it comes up, human eyes would cut down on false-positives anyways. But we need some means of shutting this guy down so we can re-open the ref-desks to IPs with legitimate questions.  -- Jayron <b style="color:#090">32</b> 01:24, 19 April 2015 (UTC)
 * Testing as filter 683. עוד מישהו Od Mishehu 18:07, 23 April 2015 (UTC)
 * Disabled as none of the hits from the past month were removal of a section. Sam Walton (talk) 11:33, 25 May 2015 (UTC)
 * Thanks. It seems to have died down.  Let's keep this on in our pockets in case he returns.  -- Jayron <b style="color:#090">32</b> 00:26, 26 May 2015 (UTC)

Persistant spam/ sockpuppetry username

 * Task Disallow creation of username involving "Ramzi".
 * Reason Name being used by sockpuppets of promotion-only account to advertise their Jewelry company, see Sockpuppet investigations/Ramzi's custom jewelry/Archive and Sockpuppet investigations/Ramzi's custom jewelry. Joseph2302 (talk) 13:37, 25 May 2015 (UTC)
 * Is this a long term issue? I'm only seeing the two usernames. Sam Walton (talk) 13:46, 25 May 2015 (UTC)
 * there's been 3 over the space of a week or so. Is this only for long-term issues (like 20+ users) then? If so, my mistake and feel free to decline thid. Joseph2302 (talk) 13:51, 25 May 2015 (UTC)
 * Yeah, wait for it to become a long term issue before requesting an edit filter, it's entirely possibly this will stop in the next week. Sam Walton (talk) 13:59, 25 May 2015 (UTC)

Kenny Loggins hoaxes
- Binksternet (talk) 16:32, 10 May 2015 (UTC)
 * Task: Disallow a range of IPs from editing any article containing the surname Loggins, and disallow the IPs from adding Loggins to an article.
 * Reason: See Long-term abuse/Kenny Loggins vandal. For a couple of weeks now, IP6s have been brought to bear on various Kenny Loggins-related pages. All of the IP6s start with 2602:306:BD7E:CAA0, so this string could be filtered along with the surname Loggins. Or a rangeblock can be set, but there will be collateral damage to others who are innocent.
 * ❌ It seems a rangeblock has been placed. Please re-request if this doesn't solve the problem. Sam Walton (talk) 11:24, 25 May 2015 (UTC)

David Beals
- Ian.thomson (talk) 23:29, 16 April 2015 (UTC)
 * Task: Block all edits with summaries that start with "goo.gl/", maybe report the user, too?
 * Reason: Sockpuppets of LTA David Beals has been using this tactic to spam videos of ceiling fans.
 * Still going. This is the sort of thing edit filters were made for, right? Ian.thomson (talk) 23:00, 28 April 2015 (UTC)
 * ❌ David Beals regularly evades the edit filter. Reaper Eternal (talk) 19:17, 29 April 2015 (UTC)

Russian Beatles copyvio
-  Acroterion   (talk)   01:58, 31 May 2012 (UTC)
 * Task:A highly dynamic IP and an occasional named sock account ( is the latest sock of the master ) has been plaguing the OTRS noticeboard and other pages with spurious statements of permission to upload Beatles songs or to link to a Russian copyright-violating host. Typically includes a link to britishcouncil.org, which I'd rather not have blacklisted the usual way, and statements like "Team of the volunteers of the British Council gives the permission to use these materials", "The Beatles for Cultural Diversity" and all IPs are from Russian ranges. See, , , , and so on.
 * Reason: Obviously Apple Records, Paul McCartney, Ringo Starr and the estates of George Harrison and John Lennon will disagree with the idea that somebody at the British Council has given permission to Russians to upload Beatles songs to WP or to link to Russian copyvio sites, and given the incredible persistence of this user, a filter might be helpful - it's been going on for months. No actual uploads that I know of, but the spurious permissions are becoming tiresome. I believe the copyvio host has long since been blacklisted.
 * Is this still needed? — This, that and the other (talk) 12:58, 18 July 2013 (UTC)
 * I haven't seen any activity of this kind in the past few months, so I'd let it drop unless they start up again.  Acroterion   (talk)   13:35, 18 July 2013 (UTC)
 * Update: they're back, Russian IPs on Jimbo's talkpage, so I'd like to pursue this again. See, and  and User:Music1245's contributions.   Acroterion   (talk)   00:43, 15 August 2013 (UTC)
 * Marking stale, if the vandal is still active remove the tag. Phantom Tech  (talk) 06:06, 20 March 2015 (UTC)
 * ❌ per inactivity. Sam Walton (talk) 12:06, 25 May 2015 (UTC)

Retard
- FrankDev (talk) 02:41, 16 January 2013 (UTC)
 * Task: Filter redirects to pages like Mental retardation.
 * Reason: Very likely an attack page.
 * Hmm, I think this could be a good filter, but could cover more than just this term. I'd propose writing up a list of pages that would be offensive if redirected to and go from there. Sam Walton (talk) 19:23, 22 January 2015 (UTC)
 * Not sure how useful this is going to be but trialling at Special:AbuseFilter/679. Sam Walton (talk) 22:47, 7 April 2015 (UTC)
 * Not very useful apparently, so ❌. Sam Walton (talk) 21:57, 18 May 2015 (UTC)

Import filter from test wiki

 * Task: Tag all removal of references by editors who aren't autoconfirmed and have less than 10 edits.
 * Reason: Already seen this problem categorized with general vandalism, this is more specific. Often removal of references are done in good faith, so applying a different tag would subject it to a different kind of verification of authenticity. It would prevent majority of the good faith ref removal from being rapidly rollbacked by editors who do quick patrolling. Link at TestWiki  Ethically  Yours! 17:39, 28 February 2015 (UTC)
 * This seems like a sensible filter, can I ask what the use of "& (action == 'edit')" is? It seems redundant since- the user has to edit to remove lines, but I'm relatively new to edit filters so I could be mistaken. Sam Walton (talk) 23:19, 1 March 2015 (UTC)
 * It doesn't really hold much significance. I was testing in my own usual way, so typed in that.  Ethically  Yours! 07:46, 2 March 2015 (UTC)
 * Created at Special:AbuseFilter/670, log only for now. Sam Walton (talk) 13:25, 14 March 2015 (UTC)
 * It seems to have gathered 650+ hits, so it's working good. Just asking, but on your discretion, wouldn't it have been better to tag such edits?  Ethically  Yours! 06:08, 15 March 2015 (UTC)
 * From what I understand, all new edit filters are ran log only to check for issues. Phantom Tech  (talk) 19:07, 15 March 2015 (UTC)
 * Indeed. And so far I'm not convinced this is a filter worth continuing. A large number of edits are general edits by unconfirmed users, many uncontroversial, and many of the vandalism edits flagged by the filter were flagged by other filters (like general vandalism or BLP issues). Sam Walton (talk) 00:07, 16 March 2015 (UTC)
 * I don't have much time at the moment for this, but could you take a look through a good chunk of the filter log to see if the filter is worth it? That would be saying that more than 50% or so of edits are vandalism that isn't caught by Cluebot or another vandalism filter. Thanks, Sam Walton (talk) 15:30, 17 March 2015 (UTC)


 * Some random samples: 1, 2, 3, 4. If you need more samples ping me.  Ethically  Yours! 16:06, 17 March 2015 (UTC)
 * I think this is far too broad. The vandalism rate in the caught edits is comparatively small and the number of edits caught is huge. As such I don't think this is a useful filter, but I'm going to get some other opinions or see if we could narrow it. Sam Walton (talk) 17:47, 7 April 2015 (UTC)
 * As it turns out we have the much more useful Special:AbuseFilter/636. I think 670 would be an unnecessary duplication of efforts; the reference removals with an edit summary are less likely to be vandalism and it catches far too many edits to be useful. Sam Walton (talk) 17:53, 7 April 2015 (UTC)

DOI Citations
- Maximilianklein (talk) 19:20, 17 June 2014 (UTC)
 * Task: Tag when the doi= paramater changes in Templates Cite journal and Cite doi in the main namespace.
 * Reason: As part of a reimplementing User:Citation bot, for Sginalling Open Access Project, whenever an Open Access reference is cited, we want to import the article to Wikisource, and give the Citation a special badge. Right now that is done by polling these templates for changes, so the reaction time is about 30-60 minutes. With this tag, we could make it happen almost instantly.
 * Maximilianklein is this still needed? If so I'll look into making a filter. Sam Walton (talk) 20:10, 23 January 2015 (UTC)
 * Given the lack of response despite a ping and a talkback I'm marking this ❌. Sam Walton (talk) 22:18, 7 April 2015 (UTC)

Twin City vandalism
Thanks, - Controlling (talk) 16:30, 31 May 2014 (UTC)
 * Task: The filter should identify all edits by anonymous users form certain IP ranges in the main name space where the edit summary contains "Twin cities", "Sister cities" and the like. Eventually, I'd like these kinds of edits to be forbidden, but for starters, logging them would be OK. The most recently active IP ranges were 78.53.0.0/18, 85.176.0.0/14 and 92.225.0.0/16, for a full list see the documentation page below. FYI: A similar filter is in place in the German wikipedia as well as the French (private) and Italian ones.
 * Reason: See documentation page: meta:user:Controlling/Twin City Vandal.
 * Has this been a problem on English Wikipedia? עוד מישהו Od Mishehu 07:31, 3 September 2014 (UTC)
 * Yes, for examples the the contribs of this IP or this one or see my edits, which are almost exclusively rollbacks of this sort of vandalism. --Null Drei Nullformerly Controllingtalk 14:15, 3 September 2014 (UTC)
 * I checked it with my test filter; not one hit since I did it - and the current version dates back to Sep. 4th. עוד מישהו Od Mishehu 12:40, 7 September 2014 (UTC)
 * First, thanks for your help. While the vandalism has been quite persistent, it's not a daily occurrence and it has indeed become less frequent recently. Again, see my edits for an estimate on the frequency ('though I probably don't catch all of them). If that's not enough for an edit filter, then I guess I'll have to keep trying to ctach it manually. --Null Drei Nullformerly Controllingtalk 15:53, 7 September 2014 (UTC)
 * ❌ per the above. Sam Walton (talk) 13:31, 2 April 2015 (UTC)

Deny posting of "anonymous philippines"

 * Task: disallow posting of "LONG LIVE ANONYMOUS PHILIPPINES" or a variant.
 * Reason: Banned has taken to posting "LONG LIVE ANONYMOUS PHILIPPINES" in various places as an IP (, see here. . CambridgeBayWeather, Uqaqtuq (talk), Sunasuttuq 07:19, 10 November 2014 (UTC)
 * See (admin only unless you beat the delete) for today's example. Edit summary was "screw Wikipedia long live anonymous Philippines".  Crow <sup style="color:black;"> Caw  19:12, 30 November 2014 (UTC)
 * CambridgeBayWeather, Crow, is this still an issue? I'll look into creating a filter if so. Sam Walton (talk) 12:19, 18 January 2015 (UTC)
 * I don't think so but I can't be sure. CambridgeBayWeather, Uqaqtuq (talk), Sunasuttuq 12:42, 18 January 2015 (UTC)
 * Not at this time, though the sockmaster is still active. He's currently back to his original M.O. of posting questionable organized crime articles. Crow <sup style="color:black;"> Caw  16:15, 18 January 2015 (UTC)

Warn about accidentally pasting in code
-  It Is Me Here  t /  c  21:42, 18 July 2014 (UTC)
 * Task: Warn users when they try to submit an edit containing the addition of.
 * Reason: I've seen  appear in article references several times (e.g. [//en.wikipedia.org/w/index.php?title=Malaysia_Airlines_Flight_17&oldid=617504523#cite_note-145]); I guess it's caused by accidentally pasting in more than one meant to when filling out the title parameter of a reference.
 * ❌ I don't think this is the kind of thing that edit filters are for. This ends up as a slight inconvenience rather than anything serious. Sam Walton (talk) 22:56, 31 March 2015 (UTC)
 * To elaborate, if you want to find where this has been added just search for it, the pages currently containing the code are minimal. Sam Walton (talk) 13:32, 2 April 2015 (UTC)

Voobly

 * At Wikipedia_talk:WikiProject_Spam I'm told this site is already blacklisted, and I should come here. IP addresses are still spamming links to Voobly.com in articles it has been removed from over the months/years multiple times.  I listed some, but certainly nowhere near to all, of the cases of that happening at the Wikiproject for spam.  If its on the blacklist already, shouldn't it automatically be in the filter?   D r e a m Focus  22:07, 5 March 2013 (UTC)
 * The blacklist isn't stopping those edits because they're not creating external links. The blacklist will only prevent you from creating an external link to that particular site.  It won't, however, stop you from inserting the text "voobly.com" outside of a link.  For that you would need an edit filter, and in this case, I think it would probably be warranted.  If I have some time later, I'll try to add one.  (But if someone else has time before I get to it, feel free to jump in.)  <span style="font:small-caps 1.2em Garamond,Times,serif;color:#442244;letter-spacing:0.2em;">‑Scottywong <span style="font:0.75em Verdana,Geneva,sans-serif;color:#442244;">| squeal _  22:31, 5 March 2013 (UTC)
 * ✅ Special:AbuseFilter/535. King of &hearts;   &diams;   &clubs;  &spades; 08:25, 6 March 2013 (UTC)


 * What about the IP addresses that only post spam to other related sites? Like this guy  did to http://www.gameranger.com/ and http://www.e-warzone.com/ ?  For years now, GameRanger spam has been going on. Wikipedia_talk:WikiProject_Spam.  If its not on the blacklist yet, do I have to wait for someone to add it to it?  And does this only affect those who post it with a .com behind it, or does it stop IP addresses from adding the name to dozens of different articles every chance they get?   D r e a m Focus  11:59, 6 March 2013 (UTC)
 * Original filter received no hits and has been disabled. Above comment should be directed towards the blacklist or re-requested if still an issue. Sam Walton (talk) 13:27, 2 April 2015 (UTC)

Filter name
- Peter&#160;James (talk) 01:04, 18 January 2013 (UTC)
 * Task: Prevent specific vandalism, which appears to have started in June 2012 by User:125.239.195.150. Repeated vandalism by many meatpuppets on the 1272 article (see page history), and after that page was protected the vandalism has occurred on the 1372 article. Possibilities are prevent these phrases being used in year articles, and prevent all use of certain combinations of phrases.
 * Reason: Better than protection as it could prevent the bad edits, and on a wider range of articles.
 * This doesn't appear to have been an issue (at those pages anyway) for some time; can you confirm Peter James? Sam Walton (talk) 12:45, 18 January 2015 (UTC)
 * Notifying about above question via re.  Phantom Tech  (talk) 06:06, 20 March 2015 (UTC)
 * Stale request, requester no longer editing, so marking ❌ Sam Walton (talk) 13:25, 2 April 2015 (UTC)

Replacing interwikis with ?
- Make  cat  05:52, 13 January 2013 (UTC)
 * Task: Tag the edit when a user unintentionally replaced interwikis with ???, because their computer doesn't support Unicode well. example
 * Reason: The tag will make it easier to fix it.
 * The problem is more general than interwikis. I've got as far as Preview with a bunch of ?s replacing someone's carefully crafted CJK characters.  Unless it is already covered by another filter, I would warn about replacing anything a text editor might zap, perhaps [\U0100-\UFFFFFF]+, by \?+. Can we also trap the substitute character which looks like &#x25A1; U+25A1 White Square but may be some other code point? Certes (talk) 13:36, 15 August 2013 (UTC)

I'll try to create a filter for this. Unfortunately the Abuse Filter's regex match does not support \u. See.  Triplestop  x3  05:19, 4 September 2013 (UTC)
 * ❌; stale.  Mini  apolis  22:57, 18 April 2015 (UTC)

Link Smurf
–Fredddie™ 19:57, 25 February 2015 (UTC)
 * Task: Prevent "eolgi" and "tititateodoro" from being added to Interstate Highway System, Interstate 69 and its child articles, Puerto Rico highway articles, or any other page for that matter.
 * Reason: and his army of throwaway socks like to blank pages and replace the content with these words.  See Sockpuppet investigations/Link Smurf/Archive.
 * Created at Special:AbuseFilter/676, log only for now. Sam Walton (talk) 10:47, 31 March 2015 (UTC)
 * ❌ for now. Filter was in log-only for 3 weeks with only one hit. For this reason a dedicated filter may not be the best route, and because we have to restrain the filter to certain articles, we are unable to add any phrases to other generalized disallow filters. Consider page protection where necessary. Any edit filter manager is free to give this another shot, it's still at Special:AbuseFilter/676. &mdash; MusikAnimal  talk  15:07, 22 April 2015 (UTC)

Anti-semite edit filter

 * Task - Block any edits by new accounts or IPs that accuse people of being anti-Semites, or anything similar to that. Should mostly apply to User talk and User namespace. Triggering of this edit filter should probably cause a bot to immediately file an AIV report. Luke no 94  (tell Luke off here) 16:49, 24 December 2014 (UTC)
 * Reason: See Long-term abuse/JarlaxleArtemis - there is a freight train's worth of socks and the issue isn't stopping. A large amount of people get targeted by this guy. Luke no 94  (tell Luke off here) 16:48, 24 December 2014 (UTC)
 * Lukeno94, "anti-Semites, or anything similar to that" is a little broad and I can't find anything obvious about such terms on the LTA page, could you specify what kind of terms would be useful to track? Sam Walton (talk) 14:54, 20 January 2015 (UTC)
 * Not off the top of my head, because most of the examples have been revdelled, and I don't have access to those, I'm afraid. Luke no 94  (tell Luke off here) 15:02, 20 January 2015 (UTC)
 * ,, are typical. -- zzuuzz (talk) 22:03, 23 January 2015 (UTC)
 * Log only at Special:AbuseFilter/660 for now. Currently only searching for anti-semite related strings, will see how this goes. If there are too many false flags we can restrict the namespace. Sam Walton (talk) 21:31, 24 January 2015 (UTC)
 * Ping didn't work, but I'm watching this page anyway. It may be a little while before JA comes back and starts this abuse again, because it seems to come in bursts; however, when they do get going, it can happen at an extremely high rate of speed. Luke no 94  (tell Luke off here) 21:40, 24 January 2015 (UTC)


 * Examples: These edit summaries are typical of one particular moron who has fallen in love with me: Revert trolling by anti-Semitic vandal Revert anti-Semitic vandal Reverting content added by anti-Semitic propagandists For several days practically every edit I and a few others make, and often the associated talk page as well, are attacked by this guy. I block the IPs as they appear, but it isn't enough.  Can I suggest: catch all uses of the words "antisemitic", "antisemite", "anti-Semitic", "anti-Semite" in edit summaries by non-authconfirmed editors.  That would catch the majority of recent cases, though I fear he will adapt.  Thanks. Zerotalk 12:42, 25 January 2015 (UTC)
 * Yep, looks like they're back again, with the usual bollocks. This isn't JA's only MO, but it's the most blatant one, and the most disruptive one. Luke no 94  (tell Luke off here) 12:59, 25 January 2015 (UTC)
 * It may also be worth looking for things similar to "muslims control Wikipedia", like, but that sort of thing is a lot broader. Luke no 94  (tell Luke off here) 13:05, 25 January 2015 (UTC)
 * And possibly this as well (because that is never going to be appropriate). Luke no 94  (tell Luke off here) 13:06, 25 January 2015 (UTC)
 * And a bunch more: Special:Contributions/86.107.110.73 Zerotalk 13:08, 25 January 2015 (UTC)


 * Comment: I am almost certain this is not going to work. Filter 58 has been pretty much the filter targeting Grawp and that has had limited results. There are some other filters like Filter 294 that have been modified to include him but again they have limited results. Not going to get much into details per BEANS but there's a reason why he's been here for years. <b style="font-family:Calibri; font-size:14px; color:#4682B4;">Elockid</b>  ( Talk ) 13:57, 25 January 2015 (UTC)
 * Maybe not, but if it makes even a small dent in the harrassment, then IMO it's worth it. One does not surrender in the face of insurmountable odds without a fight, and all that stuff. Luke no 94  (tell Luke off here) 14:03, 25 January 2015 (UTC)
 * A filter could be made, but due to filter limitations, it would only be a short term solution. I would also suggest contacting NawlinWiki since he develops filters relating to him and other long-term abusers. <b style="font-family:Calibri; font-size:14px; color:#4682B4;">Elockid</b>  ( Talk ) 14:24, 25 January 2015 (UTC)
 * The filter (660) caught 86.107.110.73 with a suitable, now hidden, flag. Sam Walton (talk) 14:26, 25 January 2015 (UTC)
 * I suppose that could stop some of his edits. Though some of things like in my talk page I think will produce false positives considering the subject matter. <b style="font-family:Calibri; font-size:14px; color:#4682B4;">Elockid</b>  ( Talk ) 16:17, 25 January 2015 (UTC)
 * Hmm indeed. It's going to be hard to implement a warn or disallow filter for this editor I think. Sam Walton (talk) 21:06, 25 January 2015 (UTC)
 * Disabled the filter for now, definitely needs refinement; anti-semit* is too broad. Sam Walton (talk) 19:56, 28 January 2015 (UTC)
 * In the face of not having any better solutions I'm going to mark this ❌. If anyone has a better idea for how to narrow down this user's edits (IP ranges, more specific text), please re-request. Sam Walton (talk) 00:18, 21 March 2015 (UTC)

New CSD Article
action = "edit" & old_size = 0 (  user_age < 2629800 &   ( article_namespace == 0 | article_namespace == 2 & (      new_wikitext irlike "{{(db|delete|delbecause|d\||speedy|csd)"     ) ) ) Note the above filter might also block a new-ish editor from reverting a blanked page that was tagged or tagging a blanked page, not sure of a better way to check for page creation since docs don't give "create" as an action possibility. - Phantom Tech  (talk) 20:24, 28 March 2015 (UTC)
 * Task: Detect creation of pages if the creation text already has a CSD tag in it
 * Reason: Turns out people often recreated their deleted pages with a copy they have of the old page without first removing the tag. The filter should block the page creation, saying something along the lines of "this page can only be created as a draft," a friendly message would likely just result in them creating the page without the tag which just makes problematic pages harder to detect. A good number of the problematic recreates my bot detects have this and there isn't much that can be done since normally a problematic recreate is just tagged for deletion and my bot can't delete pages. I haven't been keeping a list of the diffs and I'm not an admin so I can't go through the deleted ones but if you want confirmation heres the log, UA-3 are the ones you'd be looking through and I recommend starting at the bottom since those are detections with the most false positives fixed.
 * I don't see any need for this. If a page is recreated with a csd tag a patrolling admin will soon see it. If it's recreated and they remove the csd tag then their edit is tagged as removing a csd tag. Sam Walton (talk) 21:02, 29 March 2015 (UTC)

Filter to stop IPs using ban templates

 * Task: To prevent IP accounts from being able to apply Template:Banned user and Template:Indefblocked-global, and any other similar ban templates
 * Reason: There is virtually no legitimate reason for IPs to ever use these templates (and especially not the one announcing a global ban), and they were recently used to harass an editor in good standing . I raised this at WP:VPT and it was suggested that it be raised here. Nick-D (talk) 09:52, 17 March 2015 (UTC)
 * This might be better handled in other ways since filters affect the time it takes to edit pages and an IP putting a ban template on a user page isn't too disruptive, or at least I assume it's not, could be wrong. Phantom Tech  (talk) 15:24, 17 March 2015 (UTC)
 * Can you provide more examples of this happening? I'm inclined to agree with PhantomTech in that I see no evidence of this being a large scale or long term issue worthy of an edit filter. Sam Walton (talk) 15:27, 17 March 2015 (UTC)
 * I'm not aware of it happening previously, but I don't see why it should be able to happen at all. If it doesn't meet the edit filter criteria, that's OK, and thanks for considering it. Regards, Nick-D (talk) 09:06, 30 March 2015 (UTC)

Mullingar libel
- Certes (talk) 18:18, 23 March 2013 (UTC)
 * Task: Deter certain libelous statements. Probably sufficient to apply to page Mullingar, IP editors only.
 * Reason: Repeated additions like from various IPs over a number of years, usually aimed at the same person.  Please see history of Mullingar for further instances (though some have been oversighted).  If you have a better way to achieve this than edit filtering, that's good too.
 * This doesn't seem like something that fits the scope of an edit filter. At least, in the sense that this is largely a one article issue, and can be solved with a watchlist; Saving that extra few milliseconds per edit that make the difference between robust and just meh server provisioning. -T.I.M(Contact) 22:23, 27 April 2013 (UTC)
 * Dear Certes: Would Wikipedia:Requests for page protection work? If not, why not? —Unforgettableid (talk) 06:46, 4 November 2013 (UTC)
 * Thanks for taking an interest. Page protection has worked temporarily in the past.  The problem is that it is short term, because other IPs occasionally make positive contributions to this page.  For several years, this vandal's pattern has been to reappear every few months after protection has lapsed.  This tiny quantity of vandalism is trivial by the scale of Wikipedia, but it does make serious allegations against a person who is real and has reported the matter.  An edit filter probably isn't the ideal solution either; better suggestions welcome!  Or maybe we should leave it as a watchlist item and just accept that, once in a while, a search for the person's name will come up with an unfortunate result. Certes (talk) 12:29, 4 November 2013 (UTC)


 * ❌ PC1 might be a more appropriate fix. Phantom Tech  (talk) 06:06, 20 March 2015 (UTC)

IPs breaking brackets

 * Task: Apply a filter to articles flagged by BracketBot which are made by IP editors.
 * Reason: I've noticed that 80-85% of these edits are done by vandals.

BracketBot just started up this week. The bot flags an article and notifies the editor that the edit caused a bracket to become unbalanced. An example would be a missing [] on a reference or wikilink. I've noticed that the cause was vandalism 80-85% of the time. - Bgwhite (talk) 20:29, 10 May 2013 (UTC)


 * I don't think this is technically feasible, because it's too late for an edit filter to apply once BracketBot sees the edit. --71.199.125.210 (talk) 04:04, 11 July 2013 (UTC)


 * Could you get BracketBot to add the words "Note: probably vandalism" to the history of the article in question? Cheers, —Unforgettableid (talk) 07:08, 4 November 2013 (UTC)


 * I agree with the addition but only in the case of anonymous IPs. -- Magioladitis (talk) 07:58, 4 November 2013 (UTC)


 * BracketBot doesn't edit the article, so it can't put anything there. If the filter can match non regular expressions (i.e. nested brackets) then it might be an idea to have the filter apply a tag to IP edits. As it stands, BracketBot uses the same headings as counter vandals, in the hope that they will notice the notifications and revert if also vandalism. 930913(Congratulate) 22:19, 5 November 2013 (UTC)


 * Okay. There are a few ways BracketBot could alert Wikipedians to the fact that the edit may be vandalism. It could make a dummy edit and add a note to the edit summary, "Note: the previous edit by IP 111.222.333.444 was probably vandalism." Or it could add some HTML comments (maybe about vandalism) to the article and a similar note to the edit summary. Or it could write on the talk page, "==Possible adverse edit by IP 11.22.33.44== Hello, I'm BracketBot. Unregistered users sometimes make edits which leave unpaired brackets on a page. About 80% of the time, such edits are adverse edits. I have automatically detected that JohnDoe's edit to Example article may have created unpaired brackets. Dear editors: Was this edit vandalism?" Cheers, —Unforgettableid (talk) 22:34, 5 November 2013 (UTC)
 * It already does this, albeit not so pointedly, by putting notifications under the same heading as that of vandalism warnings. 930913(Congratulate) 09:54, 13 December 2013 (UTC)


 * ❌ Outside of the scope of filters. Phantom Tech  (talk) 06:06, 20 March 2015 (UTC)

Draft Review by Non-Reviewer
- EoRdE6(Come Talk to Me!) 02:49, 1 February 2015 (UTC)
 * Task: This filter should prohibit any user who is not an AfC reviewer from reviewing or publishing draft articles in the Draft and Wikipedia talk:Articles for Creation/article name namespaces.
 * Reason: To prevent unauthorized users from publishing drafts that aren't ready or BLP issues. Wikipedia_talk:WikiProject_Articles_for_creation
 * Best to wait a while in case anyone objects. If it gets consensus, I'll do it. Jackmcbarn (talk) 02:52, 1 February 2015 (UTC)
 * ❌ There seems to be no consensus to implement this edit filter and the conversation has long died out. Sam Walton (talk) 13:35, 14 March 2015 (UTC)

Extend filter 554 to Draft

 * Task: In filter 554 change "article_namespace" to cover both 0 and 118 (draft)
 * Reason: Spam links are inserted indirectly to mainspace after page is moved. It's also a security issue: Move article to draft, add spam links, move back. - Magioladitis (talk) 12:00, 5 September 2014 (UTC)
 * I would like also to ping for this one. pi -- Magioladitis (talk) 13:04, 5 September 2014 (UTC)
 * I'm currently testing for namespace 118 hits with my test filter. עוד מישהו Od Mishehu 12:42, 7 September 2014 (UTC)
 * Od Mishehu, did you get anywhere with this? Sam Walton (talk) 12:21, 18 January 2015 (UTC)
 * I'm getting no hits. עוד מישהו Od Mishehu 17:27, 25 January 2015 (UTC)
 * In that case I'll mark this ❌. Sam Walton (talk) 20:31, 2 February 2015 (UTC)

Bold headings
==Some heading== - 71.199.125.210 (talk) 19:08, 12 July 2013 (UTC)
 * Task: Tag edits that contain new bold headings, like this:
 * Reason: For some reason, I've noticed spam pages tend to do this a lot.
 * ❌ I'd want to see some proof that this was correlated with spam pages, that aside this is a MOS issue and not suitable for an edit filter. Sam Walton (talk) 21:48, 24 January 2015 (UTC)

Hijacking

 * Task: Tag edits where all or most page content is removed and replaced by different content.
 * Reason: To flag up possible cases of "hijacking", where genuine articles are replaced by unrelated promotional material, such as [//en.wikipedia.org/w/index.php?title=Pangyo_Techno_Valley&diff=616755310&oldid=616200717 this] or [//en.wikipedia.org/w/index.php?title=Siempre_te_amar%C3%A9&diff=603281399&oldid=597943389 this] Noyster  (talk),  22:22, 20 July 2014 (UTC)
 * Agree, and this should operate in all namespaces - . -- Red rose64 (talk) 13:10, 21 July 2014 (UTC)
 * It seems impractical - it's possible to filter for the c\total length of all modified lines; however, as far as can tell, there's no way to chjeck if the line was changed completely, or just a typo fix occured. עוד מישהו Od Mishehu 07:30, 31 August 2014 (UTC)
 * ❌ Musik Animal and I discussed this briefly on IRC and couldn't figure any way to check this reliably without a ton of false flags either. Sam Walton (talk) 21:44, 24 January 2015 (UTC)

Preventing example text
- 2001:18E8:2:1020:14CA:926D:7D1C:85A5 (talk) 19:39, 27 July 2012 (UTC)
 * Task: Make it so that an edit to an article space page that includes the text Bold text, [[File:Example.jpg]], and the other default text for various markups will be flagged by the filter. I suppose there are situations in which these things should be added, so please make it give the editor an "Are you sure you meant to do this?" message but please don't make it prevent them from making the edit if they say "Yes"
 * Reason: It's easy to leave stray text by accident. I often see these pieces of text in articles, and while they're occasionally vandalism, they're normally left by people who probably clicked the button and didn't notice that they'd done anything.  Example.  These aren't "Trivial formatting mistakes and edits that at first glance look fine but go against some obscure style guideline" — except for vandals and occasional editors who might find a good reason to add them to articles, nobody will intend to add them to articles, since in at least 99% of cases, they're pretty obviously against good English usage.


 * When we tried filtering out all of these the hit rate wound up being far too high and kept out too many otherwise constructive edits. There is currently a bot that watches for such edits and reverts them if only such content is present. Otherwise it logs the edits here, and the backlog on clearing that page out is usually less than a month. If you have any suggestions for improving that bot, you might want to ask 28bytes. Someguy1221 (talk) 23:49, 27 July 2012 (UTC)

Large IP talk page creation
Task Log under the following conditions:
 * 1) creation of a page of more than 100,000 bytes, or adding more than 100,000 bytes to a page
 * 2) Editor: IP
 * 3) Namespace: User talk (presently IP talk pages and subpages, but he may go on to work with inactive editors.)

Reason There is a problem with a certain blocked editor, the "Michigan Kid", editing as IPs, creating large "notes" pages recording what he has done, usually on the IP talk page, or subpages, or talk pages of other incarnations, or subpages. — Arthur Rubin (talk) 19:29, 28 October 2013 (UTC)
 * How frequent is this? If it occurs relatively infrequently, I can't really justify creating an edit filter for it. Reaper Eternal (talk) 13:06, 16 November 2013 (UTC)
 * It seems to be at most 2-3 times a day. It's only one person, and he only does it once per IP, for the most part, although an incarnation on November 19 (PST) did it twice.  Perhaps an edit filter isn't the correct approach, but those are things the edit filter can look for.  User talk space is unGooglable, so I can't just search for relevant strings (which I am not going to name here).  — Arthur Rubin  (talk) 09:24, 21 November 2013 (UTC)
 * Wikipedia's built-in search engine (Lucene) has many features which Google lacks. If you know how to use the fancy parts of Lucene's syntax, then IIRC it can do proximity search, stemming, and all sorts of other things. (But I'm not sure if there's any way to make Lucene rank pages according to how many inbound links they have.) What is it about Lucene which doesn't meet your needs? All the best, —Unforgettableid (talk) 07:53, 27 November 2013 (UTC)
 * The particular search (IP Talk page or subpage over 100000 bytes) doesn't seem likely to be available. How about an IP talk page or subpage containing certain strings?  (I'm not going to name the strings here, per WP:BEANS.)  — Arthur Rubin  (talk) 05:56, 12 December 2013 (UTC)
 * I'm no expert on Wikipedia's search engine. But it might work to search for those strings, and to add  or   to the very end of your Wikipedia search query string. Does this solve your problem? Cheers, —Unforgettableid (talk) 21:06, 31 December 2013 (UTC)
 * It's "intitle" rather than "prefix", and there were some in 68., 99., 108., and 141. I've had some success by choosing unique search strings and restricting to user talk.  (Again, WP:BEANS in regard the unique search strings.)  — Arthur Rubin  (talk) 01:16, 1 January 2014 (UTC)
 * is this still an issue? I'll look into creating a filter if so. Sam Walton (talk) 17:50, 22 January 2015 (UTC)
 * I haven't noticed it lately. That doesn't mean it isn't happening, as I'm not catching all the incarnations.  I'll check some of the strings and get back to you in a few hours.  — Arthur Rubin  (talk) 06:10, 23 January 2015 (UTC)
 * I can't find the strings. I think I kept them on-Wiki and they were deleted.  In any case, according to Wikipedia (Advanced) search, no anon talk pages have all of the indications, so I think we can call this request inactive, unless someone else is stamping them out.  — Arthur Rubin  (talk) 17:58, 23 January 2015 (UTC)
 * Alrighty then, I'll mark this ❌ and place it here for now then. Feel free to dig it out of the archives if you notice it being an issue again. Sam Walton (talk) 19:15, 23 January 2015 (UTC)

ServicesCleans filter

 * Task: Prevent frequent vandalism related to "www.servicescleans.com‎" and "www.nicolascleans.com"
 * Reason: The domains "www.servicescleans.com‎" and "www.nicolascleans.com" have been consistently spammed on Wikipedia every couple of days since 2009, by a large set of IP addresses. I have attempted to compile a list of the problem which can be found in one of my sandboxes. Note that the IP addresses tend to have been abused on more than one day, and that the list was retroactively compiled and is thus extremely likely to be incomplete due to the difficulty of finding these edits after a couple of years (Or even months).


 * Other measures against these edits have had little effect. Both domains are present on the spam blacklist, but since the added content is plaintext the blacklist does not prevent the edits. IP blocks have been used throughout the problem's history but due to dynamic IP address and the editors persistence, these measures tend to be stopgaps at the very best. Due to several (somewhat active) ranges being used a set of longterm range blocks is not a feasible solution either. Excirial ( Contact me, Contribs ) 21:17, 4 February 2014 (UTC)


 * Excirial@undefined is this still a problem? All the best: Rich Farmbrough, 01:26, 3 July 2014 (UTC).


 * I'm going to assume this spam has died down and mark this ❌. Sam Walton (talk) 22:05, 21 January 2015 (UTC)

Oversight
- S Philbrick  (Talk)  17:46, 16 May 2014 (UTC)
 * Task: Identify an edit containing the word "oversight" and pop up a warning that if they are requesting an oversight, that they should be at Requests for oversight, not posting onwiki. It should apply to the WP space, and user talk, but not article space. If this idea gains some traction, we can discuss the other spaces. It should initially apply to all (optionally, remove admins), but have a check box opt-out option,so if they have seen it once, it won't show up again (allows them to discuss the concept without getting the warning).
 * Reason: Many editors identify a need for an oversight, but request it on wiki-either at the talk page of an oversighter, or ANI, which makes the request overly prominent, exactly the opposite of the goal. I saw two such requests today, more than usual, but see one every few weeks or so.
 * I think that would have way too many false positives to be useful. Jackmcbarn (talk) 19:47, 16 May 2014 (UTC)
 * Agreed, if nothing else, if someone asks for oversight another editor will likely point them in the right direction. Sam Walton (talk) 21:49, 21 January 2015 (UTC)

Log use of .onion links

 * Task: The filter should tag edits that add links to Tor hidden sites, identified by .onion addresses.
 * Reason: Due to recent events involving these sites, such as security and validity (see the discussion on Talk:The_Hidden_Wiki), plus many hidden services may contain or otherwise host content in violation of Wikipedia guidelines, policies, and laws of the United States (such as copyright infringing material and child pornography—I had to have revisions deleted on articles related to Celebgate that contained URLs to hidden services distributing the images). Wikipedia should not assist in the dissemination of such content, so we should monitor the use of these URLs. ViperSnake151   Talk  06:21, 23 September 2014 (UTC)
 * It's possible for any external link to go to sites that "contain or otherwise host content in violation of Wikipedia guidelines, policies, and laws of the United States". Why should .onion links be treated specially? Also, it appears that only 2 of the 7 revdel'ed edits at 2014 celebrity photo leaks contained .onion links. Jackmcbarn (talk) 15:24, 10 November 2014 (UTC)
 * There are very few links to .onions services on en:WP, a list can be found here. Of those 197 links all but 39 are bot archives of 404 errors (since the bots don't know to use TOR).  Here are the remaining links, I have replaced onion with turnip.


 * 1) http://3xyjlvhbxc42gpy6.turnip/ is linked from User talk:129.138.35.215
 * 2) http://am4wuhz3zifexz5u.turnip/Library/ is linked from Talk:.onion
 * 3) http://anegvjpd77xuxo45.turnip/services/ is linked from Talk:Tor (anonymity network)/Archive 2
 * 4) http://anegvjpd77xuxo45.turnip/wiki/HiddenServices is linked from Talk:Tor (anonymity network)/Archive 1
 * 5) http://ayjkg6ombrsahbx2.turnip is linked from User talk:98.169.126.251
 * 6) http://c4wcxidkfhvmzhw6.turnip/femtotrader.msg is linked from User:FemtoTrader
 * 7) http://ccviesvicthfgfsn.turnip/ is linked from User talk:129.138.35.215
 * 8) http://ccviesvicthfgfsn.turnip/index.php/silkroad/home is linked from User talk:129.138.35.215
 * 9) http://ci3hn2uzjw2wby3z.turnip/ is linked from Talk:.onion
 * 10) http://ct7z23woq5y4jolo.turnip/ is linked from Talk:.onion
 * 11) http://dppmfxaacucguzpc.turnip is linked from User talk:77.116.96.186
 * 12) http://eqt5g4fuenphqinx.turnip/ is linked from User:Duncandozerconstruction/sandbox
 * 13) http://hq3hmoa4thdplmta.turnip/sheeple/MTRX_WordOrigins.php is linked from User talk:71.194.218.190
 * 14) http://iamxz6zefk72ulzz.turnip/ is linked from User talk:174.92.245.27
 * 15) http://ianxz6zefk71ulzz.turnip is linked from User talk:87.222.111.159
 * 16) http://iasnxz6zeerfk72ulzz.turnip/ is linked from User talk:24.19.212.20
 * 17) http://kpvz7ki2v5agwt35.turnip/wiki/index.php/Main_Page is linked from User talk:Lunixtorvalds
 * 18) http://kpvz7ki2v5agwt35.turnip/wiki/index.php/Main_Page is linked from Wikipedia talk:Requests for comment/Archive 11
 * 19) http://kpvz7ki2v5agwt35.turnip/wiki/index.php/Main_Page is linked from External links/Noticeboard/Archive 6
 * 20) http://l6nvqsqivhrunqvs.turnip/ is linked from Talk:Tor (anonymity network)/Archive 2
 * 21) http://l73fuoioj5hzznxc.turnip/ is linked from Talk:Tor (anonymity network)/Archive 2
 * 22) http://metaq3ayddzzcfzc.turnip/wiki/index.php?page=HiddenServices is linked from Talk:Tor (anonymity network)/Archive 1
 * 23) http://oldd6th4cr5spio4.turnip/index.php?title=Main_Page is linked from Talk:Tor (anonymity network)/Archive 2
 * 24) http://oqznfi3tdo6nwg3f.turnip/ is linked from Talk:.onion
 * 25) http://pdjfyv7v3pn34w4f.turnip/about.html is linked from Talk:.onion
 * 26) http://pjzb7qzbsmh5fjp4.turnip/ is linked from User talk:89.45.202.93
 * 27) http://rjgcfnw4sd2jaqfu.turnip/pantawiki/HiddenServices is linked from Talk:Tor (anonymity network)/Archive 1
 * 28) http://silkroa33dvb5piz3r.turnip is linked from User talk:173.61.31.227
 * 29) http://silkroadvb5piz2r.turnip is linked from User talk:175.110.249.114
 * 30) http://silkroadvb5piz3r.turnip/ is linked from File:Silk Road Logo.png
 * 31) http://silkroadvb5piz3r.turnip/ is linked from Talk:Silk Road (marketplace)/Archive 2
 * 32) http://silkroadvb5piz3r.turnip/index.php is linked from User talk:Benannett
 * 33) http://silkroadvb5piz3re.turnip is linked from User talk:91.233.178.46
 * 34) http://silkroadvb6piz3r.turnip is linked from User talk:149.135.146.89
 * 35) http://tdkhrvozivoez5ad.turnip/ is linked from Talk:Eli Lilly and Company
 * 36) http://www..turnip is linked from User:Berean Hunter/References
 * 37) http://xqz3u5drneuzhaeo.turnip/ is linked from Talk:Tor (anonymity network)/Archive 2
 * 38) http://xqz3u5drneuzhaeo.turnip/users/badtornodes/ is linked from Talk:.onion
 * 39) http://z3zo4z64wvgicu7j.turnip/ is linked from User talk:84.26.226.118

I believe from my attempts to save this page that .onion is blocked, making any edit filter work moot.

All the best: Rich Farmbrough, 19:34, 16 November 2014 (UTC).


 * .onion is blacklisted, with a very few officially recognised official homepages of certain subjects being whitelisted (per WP:ELOFFICIAL). Note that only primary official .onion homepages are whitelisted (i.e. websites that have their notability because they are on the .onion, not the secondary .onion homepages like the .onion access to facebook.  An edit filter is hence not needed - it is indeed blacklisted.  --Dirk Beetstra T  C 04:43, 10 December 2014 (UTC)

Obscenities in AFT5

 * Task:Prevent the posting of obscenities through the Article Feedback Tool.
 * Reason: at the moment we've got filters 460, 472, 474 and 475 working in conjunction to try and skim obscenities and vandalism out of AFT5. They were adapted from the similar filters from edits, and are working relatively well, but there's some stuff they don't get. As a first step, it would be really great if someone could meld them so we don't have multiple filters doing what is essentially the same task. As a second, we should look at expanding the obscenities it covers :). Okeyes (WMF) (talk) 08:48, 26 July 2012 (UTC)
 * Well, it looks like those 4 filters each do their thing in a different way, so merging them would take some work (and actually may not be ideal, I'm not sure). As for refining them to catch more vandalism, it would help to have as many examples as possible of vandalism that they're not currently catching.  Also, the users that have been working a lot on these filters include User:Fabrice Florin, User:Rsterbin, User:Wifione, and User:Someguy1221, so they might be better people to ask than me about these particular filters.  <span style="font:small-caps 1.3em Garamond,Times,serif;color:#224422;letter-spacing:0.2em;">-Scottywong <span style="font:0.75em Verdana,Geneva,sans-serif;color:#774477;">| gab _  18:25, 1 August 2012 (UTC)
 * They can all be merged and will probably work better because of it. I haven't looked deep into the hits, though. Is there much overlap? If they are catching distinct sets of vandalism, merging won't make a huge difference. Also, 474 is a resource-consuming beast and could use some work. Someguy1221 (talk) 04:44, 2 August 2012 (UTC)
 * They're basically the same thing (obscenities redux) - any help anyone can offer on this would be most appreciated. Okeyes (WMF) (talk) 10:47, 3 September 2012 (UTC)
 * ❌ as the feedback tool is now not in use. Sam Walton (talk) 14:44, 20 January 2015 (UTC)

Creating pages with speedy deletion tags

 * Task: Catch speedy deletion tags insrted while creating pages (at least in article space).
 * Reason: These are most likely recreations of speedy deleted pages (for example when the creator copies the page wikitext with the speedy tag on it when notified, and then pastes the same text after the page is deleted to recreate it) or are test pages where the creator wants them deleted as soon as possible after they are created. There are very few valid reasons, if any, for a speedy deletion tag to be applied on a page when it is created. jfd34  ( talk ) 14:01, 26 February 2013 (UTC)
 * ❌ Though I agree the addition of a speedy deletion tag at page creation is indicative of an issue, admins addressing CSDs will see these pages and address them anyway. Sam Walton (talk) 12:44, 18 January 2015 (UTC)

Edit Warring warning

 * Task: Warn before breach of 3rr.
 * Reason: Currently lots of people get blocked for breaching the three revert rule. Many of them are surprised and annoyed by this. If the edit filters gave them a reminder and required an extra click to breach 3rr then the amount of edit warring should fall. This would benefit the community, the edit warrers and assist us to cope with our declining number of admins  Ϣere  Spiel  Chequers  20:50, 6 December 2013 (UTC)
 * I think this proposal would require substantial discussion before it could be implemented, and I'm not sure we could even make it effective (it's not always easy to detect an edit as a revert) for all edits.--Jasper Deng (talk) 06:36, 19 December 2013 (UTC)
 * From a technical standpoint, this isn't hard at all. An edit filter could be set to warn when edit summaries begin with "Undid" or "Reverted", throttled by user and page. This would catch everything except manual undos or where the edit summary is deliberately changed. Jackmcbarn (talk) 15:41, 19 December 2013 (UTC)
 * That's the problem though. Also, it would be hard to distinguish between vandalism reverts and normal content reverts (or other reverts exempt from 3RR, such as blatant BLP violations).--Jasper Deng (talk) 00:59, 21 December 2013 (UTC)
 * If all the filter does is warn, does it matter if it catches 3RR-exempt reverts once in a while? Jackmcbarn (talk) 02:00, 21 December 2013 (UTC)
 * Not if these reverts are urgent (like reverting libel or fast-paced vandalism).--Jasper Deng (talk) 02:19, 21 December 2013 (UTC)
 * @Jasper Deng, a partially effective warning system would be better than nothing. The wording is of course important, it does need to say please ignore this warning and go ahead with your edit if you are reverting vandalism or a BLP violation. "Only click save if you are reverting vandalism or a BLP violation" might do the trick.  Ϣere Spiel  Chequers  09:51, 21 December 2013 (UTC)
 * WereSpielChequers, I'm going to mark this ❌ because I agree with Jasper Deng that a discussion should take place to decide if this is a good idea first. Sam Walton (talk) 12:38, 18 January 2015 (UTC)

Removal of HTML and extension tags
- Red rose64 (talk) 16:21, 16 December 2013 (UTC)
 * Task: Detect the removal of all HTML markip, including MediaWiki extension tags which resemble HTML.
 * Reason: Most weeks I come across edits : every markup tag has been removed, whether they be pure HTML like <small ></small> or or a MediaWiki extension, like <ref ></ref>. One way of easily distinguising these from simple removal of refs is that the text inside the <ref ></ref> is left alone. It seems to be accompanied by the alteration of entities like   and   to their character equivalents. I don't think it's wilful vandalism, but some browser bug. Usually, the only way of repairing the page is to revert, because finding the intended change amongst the mess is difficult - in this case all I could find were two changes: the insertion of the phrase "are used by Virgin Trains and" into the sentence "Platforms 1 and 2 were left without barriers, as they are mostly used by long distance express services with a high proportion of passengers carrying heavy luggage."; and the rewriting of "Operates an hourly service to London Euston and a two-hourly service to Birmingham New Street via Carlisle, Preston and Crewe" as "Operates 2 trains per hour to London Euston via Carlisle, Preston and Crewe and Birmingham New Street".
 * I reported that problem. Not willful on my part.  It means that I can't edit, as I REALLY don't want to trash the rest of the article.   <b style="color:#060">7&amp;6=thirteen</b> (<b style="color:#000">☎</b>) 18:12, 20 December 2013 (UTC)
 * is referring to Village pump (technical)/Archive 121, which was raised four days after I filed this request. -- Red rose64 (talk) 23:20, 20 December 2013 (UTC)
 * found this Process.Start and ShellExecute fails with URLs on Windows 8. Does that relate?  I'm using 8. <b style="color:#060">7&amp;6=thirteen</b> (<b style="color:#000">☎</b>) 18:42, 20 December 2013 (UTC)
 * However, did nothing but harm (see the table under ), so I reverted it as vandalism. -- Red rose64 (talk) 23:38, 20 December 2013 (UTC)
 * I used many forms of antivirus and malware removal. It did not solve the problem.
 * I upgraded to Windows 8.1 from Windows 8 which did not solve the problem.
 * I then switched from Firefox and Internet Explorer to Google Chrome, and the problem is resolved. I am back.  <b style="color:#060">7&amp;6=thirteen</b> (<b style="color:#000">☎</b>) 15:38, 21 December 2013 (UTC)
 * And the problem returned with Chrome. I am completely out of ideas. Other than to use another computer.   <b style="color:#060">7&amp;6=thirteen</b> (<b style="color:#000">☎</b>) 16:16, 21 December 2013 (UTC)

The problem was resolved by resetting my browser settings to factory specs. Here. <b style="color:#060">7&amp;6=thirteen</b> (<b style="color:#000">☎</b>) 00:31, 22 December 2013 (UTC)
 * Redrose64, have you noticed this as an issue that's still occurring or has the reason for it been fixed? Sam Walton (talk) 00:07, 17 January 2015 (UTC)
 * Is it really a year since? No, I've not seen anything like it for several months. -- Red rose64 (talk) 00:11, 17 January 2015 (UTC)
 * Alright, thanks, I'm going to mark this ❌ for now then. I'm sure something could be sorted if the issue occurs again, feel free to re-request. Sam Walton (talk) 00:19, 17 January 2015 (UTC)

"Magical Item" disallow
— Ryulong ( 琉竜 ) 18:12, 14 February 2013 (UTC)
 * Task: I would like a filter to disallow any edits to that insert the Japanese text "関連アイテム" and the romanization of "Mahō Aitemu".
 * Reason: I recently dealt with someone who was edit warring on the previously stated article and during the edit war they inserted the aforementioned text into her edits. As the Japanese text and romanization are actually erroneously matched ("関連" is read as kanren) and the only person who would be inserting it into the article is this individual who has resorted to sockpuppeting, I do not believe there will be any issue with false positives.
 * Ryulong, is this still an issue? Sam Walton (talk) 23:47, 16 January 2015 (UTC)
 * I wasn't aware that this was still backlogged. No, this is over.— Ryūlóng ( 琉竜 ) 00:54, 17 January 2015 (UTC)
 * Alright thanks, in which case, ❌. Sam Walton (talk) 21:51, 17 January 2015 (UTC)

Strip invisible characters

 * Task: Strip certain unicode characters from every edit:
 * Unicode Character 'ZERO WIDTH NO-BREAK SPACE' (U+FEFF)
 * Unicode Character 'LEFT-TO-RIGHT MARK' (U+200E)
 * Unicode Character 'ZERO WIDTH SPACE' (U+200B)
 * Unicode Character 'LINE SEPARATOR' (U+2028)
 * A less preferable alternative is to block edits with those characters.
 * Reason: These characters add no visible change to the page but can make things (links etc) behave unexpectedly. A BRfA has come up to strip these characters, and it would be redundant if they never appeared in the first place. — Josh Parris 01:10, 9 November 2013 (UTC)
 * The abusefilter can't change the content of an edit, it can just reject them (or warn). Legoktm (talk) 01:25, 9 November 2013 (UTC)
 * I think Josh is requesting that these unicode characters not be allowed to be inserted. Wifione  Message 09:32, 10 November 2013 (UTC)
 * You both understand correctly; I want something I can't have, but I'm willing to accept edits with these characters being rejected outright. Josh Parris 09:19, 13 November 2013 (UTC)
 * I think these characters could be useful in rare cases (such as on pages describing them), so maybe a warn+tag would be better. Jackmcbarn (talk) 15:52, 13 November 2013 (UTC)
 * ❌ Users will not be able to see these marks, confusing them when they try to save their edits. Reaper Eternal (talk) 13:05, 16 November 2013 (UTC)
 * Would it be worthwhile to enhance the abusefilter to let it change the content of an edit before it is saved? —Unforgettableid (talk) 01:13, 28 November 2013 (UTC)
 * No. This would quickly create more problems (and drama) than it solves. Jackmcbarn (talk) 02:27, 28 November 2013 (UTC)
 * This is a job for the "post edit transform" if anything. All the best: Rich Farmbrough, 22:12, 2 July 2014 (UTC).


 * What is the "post edit transform" you speak of? Do you mean the pre-save transform? Jackmcbarn (talk) 22:29, 14 July 2014 (UTC)
 * That'll be the one! All the best: Rich Farmbrough, 23:18, 14 July 2014 (UTC).

Disambiguation links

 * Task: Inform editors when they are about to make an edit that creates a link to a disambiguation page in article, template, category, file or portal space, and ask them to either link to the correct target page, or (if the link is intended to point to the disambiguation page instead of an article) to pipe the link through a "Foo (disambiguation)" redirect.
 * Reason: Since July 4, 2013, there has been a sudden sharp increase in the number of new disambiguation links being created. This may be related to the rollout of VisualEditor, or it may have any of a number of other reasons or contributing factors, but whatever the cause, it needs to be stemmed. bd2412  T 14:54, 23 July 2013 (UTC)


 * Note: In the time since I posted this request, the number of disambiguation pages with links has increased by over 1,100, despite an extensive campaign to find and fix these links. This is a significant and widespread problem and should be addressed as soon as possible. bd2412  T 14:34, 30 August 2013 (UTC)

I note that another editor has now made a proposal similar to this at the Village pump. bd2412 T 00:12, 11 September 2013 (UTC)
 * This isn't possible to do with the edit filter. It doesn't know anything about where links point (it can't even differentiate between redlinks and bluelinks). A new extension would be required to do that. Jackmcbarn (talk) 01:58, 11 September 2013 (UTC)
 * Question, then. How does the edit filter know when blacklisted external links are being added? It has a list that it checks them against, right? Could something like that be done with, for example, a few thousand of the most problematic disambiguation pages? bd2412  T 02:47, 11 September 2013 (UTC)
 * That's not the edit filter. That's the spam blacklist, and it only works on external links. The closest thing that currently exists is probably MediaWiki:Bad image list. Instead of checking against a list and disallowing, the code could (relatively) easily be tweaked to check if a page is a disambiguation page and issue a warning (though it's still new code). Jackmcbarn (talk) 02:51, 11 September 2013 (UTC)


 * Surely it is better to accept such a goodfaith edit and subsequently improve the link? After all links to dab pages are not wrong, merely suboptimal. The problem with an edit filter warning on this is that it would come at the wrong point, much better to save the edit and then fix the link. If you try and do it before you save you risk losing the rest of your edit unless you know to open a new tab.  Ϣere Spiel  Chequers  10:03, 21 December 2013 (UTC)
 * ❌ per the above. Sam Walton (talk) 23:57, 16 January 2015 (UTC)

The Wikipedia Adventure, autopatrolled
Cheers! Ocaasit &#124; c 14:13, 26 January 2014 (UTC)
 * The Wikipedia Adventure, new page patrol
 * task: Mark only those userpages and userspace subpages created automatically through TWA, with the edit summary New Message (simulated automatically as part of The Wikipedia Adventure), as autopatrolled
 * reasons: For the past 18 months we've been building an interactive guided tour for new editors called The Wikipedia Adventure (TWA). We just finished our beta test (10,000 editors invited, 600 played) and had some very nice results, both quantitatively and qualitatively. One issue has come up and I'd like some guidance.  The TWA game takes place in an editor's userspace, at user and user talk subpages.  This allows a modicum of verisimilitude--it looks and feels like Wikipedia--without actually burdening articles with test edits and vandalism.  So that's good. The challenge is that these new userspace pages are still patrolled by some hardworking editors, and they have asked if it would be possible to mark those pages as autopatrolled. These pages are generally created using a mediawiki guided tour that pushes an edit through the mediawiki API.  In other words, it's the editor themselves making an edit, but the TWA guided tours engine actually puts it on Wikipedia (it shows up in the page history as though the editor made it themselves, but is edit-summary tagged as part of TWA). After these pages are created, the editor is asked to interact with and improve them, as part of the learning process.
 * The Wikipedia Adventure
 * Phase 1 impact metrics and results
 * Mission 1 (the mediawiki code including the API)
 * Edit filters can't mark pages as autopatrolled. You'd need a modification to MediaWiki to do that. Jackmcbarn (talk) 19:31, 29 January 2014 (UTC)

Change to Filter 479
Special:AbuseFilter/479, designed to help "noobs", should be changed to make an exception for image examples included inside infoboxes. As most know, commented-out image syntax is sometimes included in infoboxes because there is no consistent way that images are included in an infobox. Some infoboxes want the "File:" namespace prefix, others don't; some want square brackets, others don't, etc. 67.100.127.22 (talk) 03:58, 20 April 2013 (UTC)
 * Since it does not disallow such edits, but merely warns and tags, I don't think this is a frequent enough occurrence to be a big deal. -- King of &hearts;   &diams;   &clubs;  &spades; 05:02, 20 April 2013 (UTC)

Template vandalism

 * Task: Preventing such edits as this (admin only) from multiple templates earlier today. Black Kite (talk) 22:19, 31 July 2012 (UTC)
 * Reason: obvious when you see what the edit did (WP:BEANS). Black Kite (talk) 22:20, 31 July 2012 (UTC)
 * I've added filter 482 in an attempt to deal with this. It's currently in a log-only mode and won't prevent these types of edits yet, because I'd like to make sure there are no unintended consequences from the way the filter works.  If everything is ok in a day or two, I'll switch it on.  <span style="font:small-caps 1.3em Garamond,Times,serif;color:#222222;letter-spacing:0.2em;">-Scottywong <span style="font:0.75em Verdana,Geneva,sans-serif;color:#222222;">| yak _  19:02, 1 August 2012 (UTC)
 * Nevermind, there are too many false positives with the method I chose to find these types of edits. I've deactivated and deleted the filter.  We'll have to find some other way of ignoring comments.  This should really be a function that is built in to the abuse filter extension itself, rather than having to be coded into each individual filter.  <span style="font:small-caps 1.3em Garamond,Times,serif;color:#444444;letter-spacing:0.2em;">-Scottywong <span style="font:0.75em Verdana,Geneva,sans-serif;color:#224422;">| babble _  13:44, 2 August 2012 (UTC)
 * ✅ Reaper Eternal (talk) 12:50, 17 August 2012 (UTC)
 * Make that not done for now; the wiki exploded. Reaper Eternal (talk) 13:40, 17 August 2012 (UTC)

Richard Daft

 * Task: Refer Sockpuppet investigations/Richard Daft and Archive. Various keywords and categories of articles applicable which I am reluctant to post here right now.  Grateful if you can give feedback if this sort of this is within scope, and if so I can work on the specifics.
 * Reason: Long term harassment of User:BlackJack, various attempts at outings, and vandalism of articles frequently related to 18th century cricket. - Moondyne (talk) 13:58, 26 June 2012 (UTC)
 * Request removed. Moondyne (talk) 01:46, 10 September 2012 (UTC)

Long-term subtle vandalism

 * Task: Block addition of the following names to any artilce.
 * James Couch
 * Al "Oatmeal" Edwards, Al Edwards Oatmeal
 * Mike Geselbracht
 * Adams Hambüger-Hatt, Adam Hambüger-Hatt
 * Adams Madrid, Adam Madrid, Adam Gama-Madrid
 * Reason: Long-term subtle vandalism by IP hopping vandal (mostly from CitiCorp IPs) as reported by at the village pump here. Thanks. 64.40.54.97 (talk) 11:29, 29 April 2012 (UTC)
 * An alternate would be to tag edits with these names as possible vadalism so that RCPers could have a closer look. 64.40.57.126 (talk) 18:09, 1 May 2012 (UTC)
 * An admin could just perform a rangeblock on the IPs. Hghyux (talk to me)(talk to others) 22:36, 6 May 2012 (UTC)
 * A rangeblock really wouldn't be feasible for an IP hopper. You'd have to nail so many unrelated users that the collateral probably won't be worth it. Reaper Eternal (talk) 00:45, 11 May 2012 (UTC)
 * Agree with RE, a rangeblock is inapproriate here. I've gone throught the range contribs (links here) and I'd guess about 90% of them are helpful, useful additions. An edit filter is a much better tool for this problem. 64.40.57.189 (talk) 05:03, 18 May 2012 (UTC)
 * Just out of curiosity: Is anyone having a look at this? It seems no such vandalism has occurred in the meantime, but as I had demonstrated, it had gone on for years. Btw, it would be totally sufficient to block just any addition of the name "Hambüger-Hatt", as there quite likely is no-one of that name. On the other hand, I'm not so sure about blocking additions of "James Couch", the vandal had added that name only three times or so, and some valid contributions might be blocked that way. --Axolotl Nr.733 (talk) 09:44, 6 June 2012 (UTC)
 * "Is anyone having a look at this?" Yep, the edit filter managers look at all the requests but often don't comment. There are several things to weigh before enabling a new edit filter. Such as; how big is the problem, how often does it happen, etc.. That's because the edit filters work on all edits. A few hundred edit filters on thousands of edit per hour takes up a lot of computer time, so they have to determine if the processor time is worth the problem it solves. Best regards. 64.40.54.81 (talk) 18:23, 12 June 2012 (UTC)

I'm withdrawing the request as it no longer seems to be a problem. 64.40.54.83 (talk) 10:49, 22 December 2012 (UTC)

Disable page creation throttle filter
- S/s/a/z-1/2 (talk) 12:54, 27 July 2014 (UTC)
 * Task: Disable the filter which throttles page creation by new users.
 * Reason: There are lots of reasons to create more then 8 pages in a minute.
 * MediaWiki software does that, not abuse filter. It can be changed by a configuration variable (wgRateLimits). You'll need community consensus for that to be changed and it limits all edits (and that includes page creations), not only page creations.--Glaisher (talk) 13:19, 27 July 2014 (UTC)
 * Also, from what I see of [//en.wikipedia.org/w/index.php?title=Special%3AContributions&target=Ssaz_12&newOnly=1 your 35 page creations], there have been only two occasions where you're created two or more pages in the span of two minutes or less: User:Ssaz 12/Draft, User:Ssaz 12/Draft/Draft 1, User:Ssaz 12/sandbox between 06:07 and 06:09, 1 July 2014; and User:Ssaz 12/PROD log, User talk:Somya Ranjan Mahapatra at 08:42, 4 July 2014. That's well short of hitting the page creation throttle. -- Red rose64 (talk) 13:51, 27 July 2014 (UTC)

not an edit filter issue.--Salix alba (talk): 09:01, 15 August 2014 (UTC)

Indian URLs added by new or IP editors
- ViperSnake151   Talk  18:39, 1 March 2014 (UTC)
 * Task: Mark edits that add links with Indian top-level domains
 * Reason: I've noticed, particularly on articles on electronics and the like, that IP editors sometimes linkspam non-reliable Indian websites as citations in articles, often to gleefully tell us that its now available in India as long as you have enough rupees (a violation of the recently expanded WP:NOTCATALOG). I'm not saying all Indian sites are unreliable or spam, but I've just seen it quite a bit.

These sites should be added to the WP:Blacklist. All the best: Rich Farmbrough, 21:08, 1 July 2014 (UTC).

Villegas filter
- Yunshui 雲 &zwj; 水  14:33, 6 February 2014 (UTC)
 * Task: Prevent the creation of pages where the title contains the string "Villegas" or "Vilagas" AND the content contains the phrase "Filipina child actress".
 * Reason: See Sockpuppet investigations/Katrina Villegas. Whilst this filter won't completely prevent abuse from this user, it should take care of their most common practice.

❌ seems to have died down. All the best: Rich Farmbrough, 01:20, 3 July 2014 (UTC).

Titleblacklist override

 * Task: Require confirmation when an admin attempts to create a page that's subject to the title blacklist.
 * Reason: See the "Corbet's Couloir" section of the current revision of WP:AN. We admins can create pages with blacklisted titles, but sometimes we create such a page when we shouldn't; I can't remember what it was, but I know I've done this and had to go back and delete the titles in question.  I came here after reading a related Bugzilla thread, at which someone suggested using the Abuse Filter for this purpose.  The thread originally consisted of a request to add an "Are you sure?" clickthrough whenever an admin attempted to create a blacklisted title, although it never got implemented because of inactivity.  As someone there said, "This would be a particularly useful feature to have, as it should hopefully result in faster response times when administrators screw up the title blacklist and block creation of all pages with spaces in their titles, and are blissfully unaware of the situation themselves."  When offering advice to non-admins, especially newbies, I'm always frustrated by the fact that my userrights make it harder to remember what other users can't do.  If I had to click through in order to create a title, I'd have an easier time remembering non-admins' limitations and less likely to suggest that they do things they're unable to do.  Nyttend (talk) 21:44, 27 October 2013 (UTC)
 * The edit filter and title blacklist are totally unrelated. Using it for that purpose might work, but it's a bad idea. I'll try to throw a proper fix together in gerrit. Jackmcbarn (talk) 23:48, 27 October 2013 (UTC)
 * This is simply . Reaper Eternal (talk) 13:07, 16 November 2013 (UTC)

Filter 30: Large deletion from article by new editors

 * Task: Make filter 30: Large deletion from article by new editors not apply to mobile edits.
 * Reason: Exceptionally high rate of FPs. Example: Special:AbuseLog/9062564 appears as blanking, but the diff corresponding to that edit isn't. There are many more examples of this in filter 30's log. It looks like this happens because of a bug somewhere makes mobile edits only show the filter the new wikitext from the edited portion of the page. Jackmcbarn (talk) 03:03, 29 July 2013 (UTC)
 * Withdrawn. The bug causing this has long since been fixed. Jackmcbarn (talk) 04:21, 4 January 2014 (UTC)

Not
- The Anonymouse (talk &#124; contribs) 06:47, 5 February 2013 (UTC)
 * Task: This filter would warn tag edits by all non-autoconfirmed users that are simply inserting the word "not". It would also tag all edits that fit the criteria so that users can identify them and take action if necessary.
 * Reason: Many IP and new users simply add "not" to an article as sneaky vandalism.
 * There is probably too much potential for collateral damage, and it might get in the way of non-autoconfirmed users reverting vandalism that removes "not".--Jasper Deng (talk) 06:53, 5 February 2013 (UTC)
 * Are you saying that warning is too much? If so, than how about just tagging and not warning? The Anonymouse (talk &#124; contribs) 07:00, 5 February 2013 (UTC)
 * A warning probably will cause too much collateral; I'll leave it to a more experienced edit filter manager to see about tagging, although I don't know about its effectiveness because again it may be part of a vandalism revert.--Jasper Deng (talk) 07:07, 5 February 2013 (UTC)
 * ❌ Many also remove "not" as another form of sneaky vandalism, and this filter would stop the reversion of that. There also would likely be many false positives associated with this. Reaper Eternal (talk) 11:37, 5 March 2013 (UTC)

Adding QuickiWiki

 * Task: Check for addition of "QuickiWiki Look Up" and give a warning explaining the cause and how to avoid it.
 * Reason: Users have problems identifying the cause and keep inadvertently making edits adding "QuickiWiki Look Up". Special:AbuseFilter/345 checks for addition of this and other strings, but only displays a generic message at MediaWiki:Abusefilter-warning-codespill. After discussion at Village pump (technical)/Archive 103 I suggest a filter specific to "QuickiWiki Look Up" with a message saying something like this:


 * If this filter is made then QuickiWiki should be removed from Special:AbuseFilter/345. All posts I have seen identify the cause of adding QuickiWiki say it was WikiTweak. I don't know whether external links are used in edit filters but WikiTweak might link to https://addons.mozilla.org/en-us/firefox/addon/wikitweak-wikipedia-enhancer/ and "disable" to http://support.mozilla.org/en-US/kb/disable-or-remove-add-ons. PrimeHunter (talk) 00:38, 1 October 2012 (UTC)
 * I don't see why we should split it out. That just creates more work and more server load. Reaper Eternal (talk) 20:06, 11 October 2012 (UTC)


 * The filter log shows Geez-oz triggered the filter 72 times before being told the cause at Village pump (technical)/Archive_103 and disabling WikiTweak. Other users might give up editing if they only see the generic message MediaWiki:Abusefilter-warning-codespill with no mention of WikiTweak. But the filter is triggered rarely and I don't know how costly an extra filter is. Maybe MediaWiki:Abusefilter-warning-codespill should just mention that if the added text is "QuickiWiki" then the browser extension WikiTweak is probably responsible. Can an edit filter pass a parameter to MediaWiki:Abusefilter-warning-codespill to indicate whether "QuickiWiki" was found? PrimeHunter (talk) 21:37, 11 October 2012 (UTC)

Checked for by Special:AbuseFilter/345. Logs show this is no longer a frequent term so does not need a special filter.--Salix alba (talk): 09:01, 15 August 2014 (UTC)

Change some filters to public

 * Task: Change the following filters to public visibility:
 * 34 	New or unregistered user blanking someone else's user or user talk page
 * 68 	Pagemove throttle for new users
 * 242 	Redirecting a substantial existing page - new user throttle
 * 247 	Adding emails in articles
 * 261 	Page creation throttle for new users
 * 320 	"Your mom" Vandalism
 * 364 	Changing the name in a BLP infobox
 * 463 	Feedback: Adding email addresses
 * 483 	Users creating own talk
 * Also, possibly these, but I'm not totally sure if they do anything that's private for a reason:
 * 354 	Promotional text added by user to own user(-talk) page
 * 527 	bug 32234: log/throttle possible sleeper account creations

- 71.199.125.210 (talk) 03:32, 11 July 2013 (UTC)
 * Reason: It's obvious how these filters work based on their descriptions, so keeping them private only serves to make it more difficult to patrol the edit filter log.
 * These are private for reasons such as long-term abuse, spammers/spambots, and similar reasons. (Except for 247 and 463: the reason why these are private is "to protect logs from being crawled by spambots". And I think the same goes for 527: to keep the log private.) I am pretty sure none of these filters will be made public. — This, that and the other (talk)  11:32, 18 July 2013 (UTC)
 * What's being hidden by keeping them private? That's what I don't see. --24.131.230.174 (talk) 01:58, 22 July 2013 (UTC)
 * After reviewing them, I can tell you that each of them is private for some reason, such as hiding the log from spambots, containing tunable parameters that could be exploited if made public, and/or targeting some malicious behavior which is not obvious from the title. -- King of &hearts;   &diams;   &clubs;  &spades; 03:23, 22 July 2013 (UTC)


 * ❌ Per above Triplestop (talk) 03:56, 21 September 2013 (UTC)

I've checked them and IMHO there's no benefit in keeping 68, 242, 261, 483 private; for the first three the benefits of transparency are particularly high as they are of the "disallow" kind. --Nemo 12:01, 5 September 2014 (UTC)

Common misspellings
- 84.127.80.114 (talk) 05:39, 15 August 2014 (UTC)
 * Task: The filter should flag, warn or prevent an edit containing common misspellings. This list could be used. It applies to the article namespace and to all editors.
 * Reason: I came across this epic struggle and discussed how to ease that task. Although it would be trivial to detect "comprised of", there seems to be quite an effort to correct misspellings. Google engine may be better than Wikipedia's to search for misspelled words; however, searching is not enough and those human resources should be devoted to more creative contributions.
 * I see a very long list. While it could be made into a regular expression for warn and/or tag (there may be legitimate reasons to use the misspellings, so no preventing), I don 't think that it would be worth the use of the condition limit. עוד מישהו Od Mishehu 19:11, 27 August 2014 (UTC)


 * Preventing is an option, since legitimate misspellings can be marked: e.g., and  . I propose this:
 * Assume there is a list with the 100 most common misspellings.
 * Prevent or warn.
 * After some time (e.g., one week) evaluate if the filter has reduced the load on spell-checking users.
 * Would this be acceptable? 84.127.80.114 (talk) 23:33, 27 August 2014 (UTC)
 * We don't allow bots to fix typos without human supervision, so I don't think we should allow them to disallow edits that probably contain typos. Remember with AWB there is very little effort needed to correct those of the typos that need correction, and without losing the rest of the edit they are part of. A typo is not a typo if it is a genuine quote or a file name - several of the words I patrol for are in multiple urls used on this site. Many "typos" are real names, for example try searching for Thrity. I would be OK with an opt in feature that spell checked your edit before you made it, but then I have that as part of the Firefox browser. But a warning that didn't highlight the word that needed changing would be an irritant to editors.  Ϣere  Spiel  Chequers  12:15, 1 September 2014 (UTC)
 * Filters are not bots; bots correct, filters prevent. This filter is targeted at good faith mistakes. I am not talking about every possible typo, but the 100 most common misspellings. Is "Thrity" in that category?
 * Has this solution ever been tried and failed? 84.127.80.114 (talk) 04:41, 2 September 2014 (UTC)
 * I do not see any way to pass the matched word to the warning message. Let us try something easier: the one most common misspelling. That would indicate whether this filter is useful. 84.127.80.114 (talk) 05:37, 2 September 2014 (UTC)
 * ❌ Lack of support. 84.127.82.127 (talk) 17:48, 30 October 2014 (UTC)