Honestly, the dev could just change the main page to be only allowing threads instead of comments, because the hackers only want attention from the main page. And even if they went the effort of spamming on thread posts, they technically unable, because its by script they following to spam that kind of scam