
Amir Social Comments WordPress Security & Risk Analysis
wordpress.org/plugins/amir-social-commentsAllow your website visitors to post comment via their Facebook account
Is Amir Social Comments WordPress Safe to Use in 2026?
Generally Safe
Score 85/100Amir Social Comments WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'amir-social-comments' plugin v1.0 exhibits a generally good security posture based on the provided static analysis. There are no identified dangerous functions, SQL injection vulnerabilities through prepared statements, file operations, or external HTTP requests. The absence of known CVEs also suggests a history of good security practices or low visibility. However, a significant concern arises from the complete lack of output escaping. With 8 total outputs analyzed and 0% properly escaped, this presents a high risk for cross-site scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the user interface. Additionally, the absence of nonce and capability checks on what appear to be potentially entry points, even if none were explicitly identified in the attack surface analysis, is a notable weakness that could be exploited if the attack surface expands or if internal functionality is inadvertently exposed. While the plugin has no known vulnerabilities, the critical unescaped output is a serious flaw that needs immediate attention.
Key Concerns
- No output escaping
- Missing nonce checks
- Missing capability checks
Amir Social Comments WordPress Security Vulnerabilities
Amir Social Comments WordPress Release Timeline
Amir Social Comments WordPress Code Analysis
SQL Query Safety
Output Escaping
Amir Social Comments WordPress Attack Surface
WordPress Hooks 3
Maintenance & Trust
Amir Social Comments WordPress Maintenance & Trust
Maintenance Signals
Community Trust
Amir Social Comments WordPress Alternatives
Fancy Comments WordPress
fancy-facebook-comments
Integrate Facebook Comments with your WordPress website easiest possible way
Social Share, Social Login and Social Comments Plugin – Super Socializer
super-socializer
The unique Social Plugin to let you integrate Social Login, Social Share, Social Comments and Social Media follow at your website
Social comments by WpDevArt
comments-from-facebook
This plugin will help you display Facebook Comments on your website. You can use it on your pages/posts.
Lazy Social Comments
lazy-facebook-comments
Use Facebook Comments with lazy loading feature. Load FB comments after button click or scroll down.
Social Comments by Heateor
heateor-social-comments
Integrate Facebook Comments, Vkontakte Comments and/or Disqus Comments along with default comment form at your website
Amir Social Comments WordPress Developer Profile
1 plugin · 0 total installs
How We Detect Amir Social Comments WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
https://connect.facebook.net/HTML / DOM Fingerprints
fb-commentsdata-hrefdata-widthdata-order-bydata-mobiledata-colorschemedata-numpostsFB