Amir Social Comments WordPress Security & Risk Analysis

wordpress.org/plugins/amir-social-comments

Allow your website visitors to post comment via their Facebook account

0 active installs v1.0 PHP 5.4+ WP 2.5.0+ Updated May 2, 2020
facebook-commentingfacebook-comments
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Amir Social Comments WordPress Safe to Use in 2026?

Generally Safe

Score 85/100

Amir Social Comments WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The 'amir-social-comments' plugin v1.0 exhibits a generally good security posture based on the provided static analysis. There are no identified dangerous functions, SQL injection vulnerabilities through prepared statements, file operations, or external HTTP requests. The absence of known CVEs also suggests a history of good security practices or low visibility. However, a significant concern arises from the complete lack of output escaping. With 8 total outputs analyzed and 0% properly escaped, this presents a high risk for cross-site scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the user interface. Additionally, the absence of nonce and capability checks on what appear to be potentially entry points, even if none were explicitly identified in the attack surface analysis, is a notable weakness that could be exploited if the attack surface expands or if internal functionality is inadvertently exposed. While the plugin has no known vulnerabilities, the critical unescaped output is a serious flaw that needs immediate attention.

Key Concerns

  • No output escaping
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Amir Social Comments WordPress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Amir Social Comments WordPress Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

Amir Social Comments WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
8
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

0% escaped8 total outputs
Attack Surface

Amir Social Comments WordPress Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
filterthe_contentamir-social-comments.php:131
actionadmin_menuamir-social-comments.php:141
actionadmin_initamir-social-comments.php:365
Maintenance & Trust

Amir Social Comments WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedMay 2, 2020
PHP min version5.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Amir Social Comments WordPress Developer Profile

kamirkhan

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Amir Social Comments WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Script Paths
https://connect.facebook.net/

HTML / DOM Fingerprints

CSS Classes
fb-comments
Data Attributes
data-hrefdata-widthdata-order-bydata-mobiledata-colorschemedata-numposts
JS Globals
FB
FAQ

Frequently Asked Questions about Amir Social Comments WordPress