
After Comment Prompts Security & Risk Analysis
wordpress.org/plugins/after-comment-promptsDisplay a modal message/prompt to a user after they leave a post comment.
Is After Comment Prompts Safe to Use in 2026?
Generally Safe
Score 85/100After Comment Prompts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "after-comment-prompts" v1.0 plugin presents a generally positive security posture due to the absence of known vulnerabilities and a clean record of past security incidents. The static analysis reveals no identified attack surface points such as AJAX handlers, REST API routes, or shortcodes, and a complete lack of dangerous functions, file operations, or external HTTP requests. All SQL queries are prepared, which is a strong security practice. However, the analysis does raise some concerns. Notably, 50% of output operations are not properly escaped, indicating a potential for cross-site scripting (XSS) vulnerabilities. Furthermore, the taint analysis identified two flows with unsanitized paths, which, while not classified as critical or high severity in this instance, warrant attention as they represent pathways where data might be handled insecurely. The lack of nonce and capability checks on any potential entry points, though currently there are none detected, leaves a theoretical vulnerability if new entry points were introduced without these security measures. Overall, the plugin has strengths in its lack of known exploits and secure SQL handling, but requires attention to output escaping and careful monitoring of taint flows.
Key Concerns
- Output escaping not properly handled
- Unsanitized paths in taint flows
- No nonce checks implemented
- No capability checks implemented
After Comment Prompts Security Vulnerabilities
After Comment Prompts Code Analysis
Output Escaping
Data Flow Analysis
After Comment Prompts Attack Surface
WordPress Hooks 6
Maintenance & Trust
After Comment Prompts Maintenance & Trust
Maintenance Signals
Community Trust
After Comment Prompts Alternatives
Social Share, Social Login and Social Comments Plugin – Super Socializer
super-socializer
The unique Social Plugin to let you integrate Social Login, Social Share, Social Comments and Social Media follow at your website
Social comments by WpDevArt
comments-from-facebook
This plugin will help you display Facebook Comments on your website. You can use it on your pages/posts.
Fancy Comments WordPress
fancy-facebook-comments
Integrate Facebook Comments with your WordPress website easiest possible way
VKontakte
vkontakte
The plugin adds a wide range of VKontakte functionality to your site.
코스모스팜 소셜댓글
cosmosfarm-comments
사용 할 수록 홈페이지가 자연적으로 홍보되는 차세대 소셜댓글 서비스 입니다.
After Comment Prompts Developer Profile
6 plugins · 2K total installs
How We Detect After Comment Prompts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/after-comment-prompts/assets/css/style.min.css/wp-content/plugins/after-comment-prompts/assets/js/popup-overlay.min.js/wp-content/plugins/after-comment-prompts/assets/js/popup-overlay-init.min.js/wp-content/plugins/after-comment-prompts/assets/js/popup-overlay.min.js/wp-content/plugins/after-comment-prompts/assets/js/popup-overlay-init.min.jsafter-comment-prompts/assets/css/style.min.css?ver=after-comment-prompts/assets/js/popup-overlay.min.js?ver=after-comment-prompts/assets/js/popup-overlay-init.min.js?ver=HTML / DOM Fingerprints
popup_backgroundcomment-prompt-modal-wrappopupoverlay-close