
Comments Security & Risk Analysis
wordpress.org/plugins/advanced-commentsCustomize and optimize comments in WordPress
Is Comments Safe to Use in 2026?
Generally Safe
Score 85/100Comments has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "advanced-comments" plugin v1.0.0 exhibits a generally strong security posture in terms of its attack surface and known vulnerability history. The absence of any recorded CVEs, coupled with the static analysis showing zero entry points and no dangerous functions, suggests a cautious development approach. Furthermore, all SQL queries are correctly utilizing prepared statements, which is a significant strength.
However, a critical concern arises from the static analysis revealing that 100% of outputs are not properly escaped. This presents a significant risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data could be injected into the output without sanitization, potentially leading to malicious script execution. The lack of nonce checks and capability checks, while not directly exploitable due to the limited attack surface shown, is a missed opportunity for robust security practices.
The plugin's vulnerability history is clean, which is positive. This could indicate diligent development or simply a short history without significant security testing. The overall conclusion is that while the plugin avoids common pitfalls like direct SQL injection and has a clean CVE record, the widespread lack of output escaping is a serious oversight that needs immediate attention.
Key Concerns
- 100% of outputs are not properly escaped
- No nonce checks implemented
- No capability checks implemented
Comments Security Vulnerabilities
Comments Release Timeline
Comments Code Analysis
Output Escaping
Comments Attack Surface
WordPress Hooks 4
Maintenance & Trust
Comments Maintenance & Trust
Maintenance Signals
Community Trust
Comments Alternatives
Comments – wpDiscuz
wpdiscuz
AJAX powered realtime comments. Designed to extend WordPress native comments. Custom comment forms/fields. Making comments has never been so awesome!
Advanced Comment Form
comment-form
Advanced Comment Form lets you customize plenty of things on the default comment forms in WordPress.
Comments Form Star Rating Plugin for WordPress
comments-form-star-rating
Allow your customers to add star rattings in comment form.
Fancy Comments WordPress
fancy-facebook-comments
Integrate Facebook Comments with your WordPress website easiest possible way
Social Comments by Heateor
heateor-social-comments
Integrate Facebook Comments, Vkontakte Comments and/or Disqus Comments along with default comment form at your website
Comments Developer Profile
7 plugins · 16K total installs
How We Detect Comments
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/advanced-comments/admin/css/admin.css/wp-content/plugins/advanced-comments/admin/js/admin.js/wp-content/plugins/advanced-comments/frontend/css/frontend.css/wp-content/plugins/advanced-comments/frontend/js/frontend.js/wp-content/plugins/advanced-comments/admin/js/admin.js/wp-content/plugins/advanced-comments/frontend/js/frontend.jsadvanced-comments/admin/css/admin.css?ver=advanced-comments/admin/js/admin.js?ver=advanced-comments/frontend/css/frontend.css?ver=advanced-comments/frontend/js/frontend.js?ver=HTML / DOM Fingerprints
comments-admin-wrapcomments-frontend-wrap