Content filtering.
Install the complete review experience, choose an interface, and configure customer and team workflows.
← All Pro topicsContent moderation
Redact your configured words/phrases and require human approval, even if core auto-approval is enabled:
php artisan vendor:publish --tag=review-rateable-pro-content-moderation-migrations
php artisan migrate
'content_moderation' => [
'enabled' => true,
'words' => [
'your blocked word',
'your blocked phrase',
],
'replacement' => '[redacted]',
],
No profanity dictionary is bundled. Terms are literal UTF-8, case-insensitive, whole-word matches; phrase whitespace is flexible. Substrings in unrelated words are not matched. Supply up to 1,000 terms of 200 characters each. Empty terms are ignored, and an empty list changes nothing.
The replacement must be non-empty plain text, at most 255 characters, and must not contain a blocked term. Redacted output must still fit configured field lengths. Invalid configuration fails closed.
Pro filters bodies, enabled titles, and new dated updates automatically. New matches force the entire review pending even when approved_review=true or editing.require_reapproval=false.
Moderators can inspect encrypted originals and matched wording in the private moderation dashboard. Approval publishes redacted text, not the original. Public/author views do not load this private history.
Custom core/API writers
Core does not invoke Pro filtering automatically. Authorize and validate first, then filter inside the same write transaction:
use Codebyray\ReviewRateablePro\Services\ReviewContentModerationManager;
$review = $product->getConnection()->transaction(
function () use ($product, $validated, $author) {
$review = $product->addReview([
'review' => $validated['review'],
'ratings' => $validated['ratings'],
], $author->getKey());
return app(ReviewContentModerationManager::class)
->moderateReview($review);
}
);
moderateUpdate($update) is available for custom dated-update writers. These are trusted persistence integrations, not authentication or input-validation boundaries.
Existing reviews are not automatically rescanned when your dictionary changes. This is not semantic/AI moderation, regex matching, OCR, image moderation, leetspeak detection, or official-reply filtering.
Keep APP_KEY stable or use Laravel's supported key-rotation process so private snapshots stay decryptable. Define retention for originals; never log or publicly serialize them.