
Advanced Comments Widget Security & Risk Analysis
wordpress.org/plugins/advanced-comments-widgetA highly customizable recent comments widget with avatars and excerpts.
Is Advanced Comments Widget Safe to Use in 2026?
Generally Safe
Score 85/100Advanced Comments Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'advanced-comments-widget' v1.1.2 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits its attack surface, and critically, all identified SQL queries utilize prepared statements, mitigating the risk of SQL injection. The plugin also reports no known vulnerabilities in its history, suggesting a history of secure development or minimal previous exposure. However, a significant concern arises from the low percentage of properly escaped output. With only 31% of 86 outputs being properly escaped, there is a considerable risk of Cross-Site Scripting (XSS) vulnerabilities, especially if user-provided data is involved in these unescaped outputs. The lack of nonce checks is also a notable weakness, particularly if any administrative functionalities were to be introduced later without proper checks.
Key Concerns
- Low percentage of properly escaped output
- No nonce checks
Advanced Comments Widget Security Vulnerabilities
Advanced Comments Widget Code Analysis
Output Escaping
Advanced Comments Widget Attack Surface
WordPress Hooks 6
Maintenance & Trust
Advanced Comments Widget Maintenance & Trust
Maintenance Signals
Community Trust
Advanced Comments Widget Alternatives
Recent Comments Widget Plus
comments-widget-plus
Provides custom recent comments widget with extra features such as display avatar, comment excerpt and much more!
Better WordPress Recent Comments
bwp-recent-comments
This plugin displays recent comment lists at assigned locations, with comprehensive support for widgets.
GraphComment Comment system
graphcomment-comment-system
Transform your site's engagement with GraphComment—an advanced, interactive commenting system featuring live discussions and real-time notifications.
Customized Recent Comments
customized-recent-comments
Display recent comments on your blog with complete control over the layout and format of comments.
Init Recent Comments – Templated, Modern, Minimal
init-recent-comments
Display recent comments with customizable templates and clean CSS. Lightweight, flexible, and built for modern WordPress sites.
Advanced Comments Widget Developer Profile
13 plugins · 2K total installs
How We Detect Advanced Comments Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/advanced-comments-widget/js/admin.jsHTML / DOM Fingerprints
acw-avatarid="acw-scripts"