
AJAX Comment Loading Security & Risk Analysis
wordpress.org/plugins/ajax-comment-loadingLoads comments with a secondary AJAX request, including comment paging. Speeds initial loading of the page.
Is AJAX Comment Loading Safe to Use in 2026?
Generally Safe
Score 85/100AJAX Comment Loading has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'ajax-comment-loading' plugin, in version 1.0, presents a concerning security posture primarily due to its unprotected AJAX handlers. While the plugin demonstrates good practices by utilizing prepared statements for SQL queries and a high percentage of properly escaped output, the presence of two AJAX handlers without any authentication or capability checks creates a significant attack surface. This lack of security checks means that any user, including unauthenticated ones, could potentially trigger these AJAX actions, leading to unintended consequences or exploitation if the handlers perform sensitive operations. The absence of any recorded vulnerabilities in its history is a positive indicator, suggesting that past development might have been more secure or that the plugin hasn't been a target. However, the current static analysis reveals a critical oversight that outweighs the positive aspects of its vulnerability history and internal code practices, demanding immediate attention.
Key Concerns
- AJAX handlers without auth checks
- No nonce checks on AJAX handlers
- High percentage of unescaped output
AJAX Comment Loading Security Vulnerabilities
AJAX Comment Loading Code Analysis
Output Escaping
AJAX Comment Loading Attack Surface
AJAX Handlers 2
WordPress Hooks 6
Maintenance & Trust
AJAX Comment Loading Maintenance & Trust
Maintenance Signals
Community Trust
AJAX Comment Loading Alternatives
Comments – wpDiscuz
wpdiscuz
AJAX powered realtime comments. Designed to extend WordPress native comments. Custom comment forms/fields. Making comments has never been so awesome!
AnyComment
anycomment
AnyComment is blazing-fast commenting plugin based on React for WordPress.
Ajaxify Comments – Ajax and Lazy Loading Comments
wp-ajaxify-comments
Ajaxify Comments hooks into native WordPress comments and allows comment posting without reloading the page.
Comment Edit Core – Simple Comment Editing
simple-comment-editing
Allow your users to edit their comments for a period of time. Adjust the comment timer and save some admin headaches.
Dynamic Front-End Heartbeat Control
dynamic-front-end-heartbeat-control
An enhanced solution to optimize the performance of your WordPress website and automatically achieve the best Heartbeat API values.
AJAX Comment Loading Developer Profile
29 plugins · 176K total installs
How We Detect AJAX Comment Loading
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ajax-comment-loading/js/google-acl.js/wp-content/plugins/ajax-comment-loading/js/google-acl.jsajax-comment-loading/js/google-acl.js?ver=1HTML / DOM Fingerprints
<!-- Neuter the comments query, to prevent doing double work. Yes, this is super janky. Ergo, the comment about what is neutering it, so someone doesn't lose their mind trying to debug this. -->ajaxurlgpidcpage