
Allow Comments to Old Posts Security & Risk Analysis
wordpress.org/plugins/allowcommentsAllow comments to posts with custom field "allow_comments" even if option 'close comments to old posts' is on.
Is Allow Comments to Old Posts Safe to Use in 2026?
Generally Safe
Score 100/100Allow Comments to Old Posts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'allowcomments' plugin v1.6 exhibits a strong security posture based on the provided static analysis. The absence of any identified dangerous functions, direct SQL queries, unescaped output, file operations, external HTTP requests, or taint flows with unsanitized paths is highly commendable. The plugin also demonstrates good practice by not bundling external libraries. Furthermore, the vulnerability history shows no known CVEs, indicating a consistent track record of security. However, a significant concern arises from the complete lack of nonce and capability checks across all entry points, including AJAX handlers, REST API routes, shortcodes, and cron events. While the current analysis shows 0 unprotected entry points due to the absence of these entry points altogether, any future addition or modification that introduces such entry points without proper authentication and authorization mechanisms would represent a critical security gap. The plugin's current minimal attack surface is a strength, but its lack of security checks is a potential weakness should the attack surface grow.
Key Concerns
- No nonce checks on entry points
- No capability checks on entry points
Allow Comments to Old Posts Security Vulnerabilities
Allow Comments to Old Posts Code Analysis
Allow Comments to Old Posts Attack Surface
WordPress Hooks 6
Maintenance & Trust
Allow Comments to Old Posts Maintenance & Trust
Maintenance Signals
Community Trust
Allow Comments to Old Posts Alternatives
WP Typograph Lite
wp-russian-typograph
Russian typography for Wordpress. Lite version.
WP Typograph Full
wp-typograph-full
Russian typography for Wordpress. Full version with settings.
AJAXify FAQ-Tastic
ajaxify-faqtastic
Used to add AJAX open/close effects to the FAQ-Tastic WordPress plugin.
Duplicate Page
duplicate-page
Duplicate Posts, Pages and Custom Posts easily using single click
Duplicate Post
copy-delete-posts
Duplicate post
Allow Comments to Old Posts Developer Profile
6 plugins · 8K total installs
How We Detect Allow Comments to Old Posts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
allowcommentsdivid="allow_comments"