
Another Comments Cleaner Security & Risk Analysis
wordpress.org/plugins/another-comments-cleanerDelete or trash automatically comments based on status using WP_Cron
Is Another Comments Cleaner Safe to Use in 2026?
Generally Safe
Score 85/100Another Comments Cleaner has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'another-comments-cleaner' plugin v0.8 exhibits a generally positive security posture based on the provided static analysis. It has a limited attack surface with all identified entry points (3 AJAX handlers) appearing to have nonce and capability checks. The absence of dangerous functions, file operations, and external HTTP requests further strengthens its security. The plugin also benefits from a clean vulnerability history with no recorded CVEs, suggesting a history of responsible development and maintenance.
However, a significant concern arises from the handling of SQL queries. All 8 SQL queries are executed without prepared statements, which exposes the plugin to potential SQL injection vulnerabilities. While no taint flows were detected in this analysis, the direct use of unescaped input in SQL queries is a critical risk. Additionally, the output escaping is only properly implemented in 47% of cases, leaving room for potential cross-site scripting (XSS) vulnerabilities if user-supplied data is directly outputted without adequate sanitization. The lack of taint analysis results is noted, but the presence of raw SQL and insufficient output escaping are strong indicators of risk.
In conclusion, the plugin's strengths lie in its minimal attack surface and clean vulnerability history. However, the significant risk of SQL injection due to the lack of prepared statements and the potential for XSS due to insufficient output escaping are serious drawbacks that require immediate attention. Addressing these specific code-level risks would substantially improve the plugin's overall security.
Key Concerns
- All SQL queries use raw SQL, no prepared statements
- Less than 50% of output is properly escaped
Another Comments Cleaner Security Vulnerabilities
Another Comments Cleaner Code Analysis
SQL Query Safety
Output Escaping
Another Comments Cleaner Attack Surface
AJAX Handlers 3
WordPress Hooks 5
Maintenance & Trust
Another Comments Cleaner Maintenance & Trust
Maintenance Signals
Community Trust
Another Comments Cleaner Alternatives
Spam Comments Cleaner
spam-comments-cleaner
Delete all the SPAM comments of your WordPress site in a regular time interval. To start the scheduled script this plugin using wp_cron hook.
Akismet Anti-spam: Spam Protection
akismet
The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam solution for WordPress and WooCommerce.
Disable Comments – Remove Comments & Stop Spam [Multi-Site Support]
disable-comments
Allows administrators to globally disable comments on their site. Comments can be disabled according to post type. Multisite friendly.
Antispam Bee
antispam-bee
Sophisticated antispam plugin for effective daily comment and trackback spam-fighting. Built with data protection and privacy in mind.
Spam protection, Honeypot, Anti-Spam by CleanTalk
cleantalk-spam-protect
Blocks spam comments, fake users, contact form spam and more. No impact on SEO. Privacy focused. CAPTCHA free, premium Antispam plugin.
Another Comments Cleaner Developer Profile
3 plugins · 80 total installs
How We Detect Another Comments Cleaner
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/another-comments-cleaner/assets/css/admin.css/wp-content/plugins/another-comments-cleaner/assets/js/admin.js/wp-content/plugins/another-comments-cleaner/assets/js/admin.jsanother-comments-cleaner/assets/css/admin.css?ver=another-comments-cleaner/assets/js/admin.js?ver=HTML / DOM Fingerprints
ancc-settings-pageancc-map-settingsancc-sched-settingsancc-immediate-cleandata-action="ancc-immediate-clean"data-action="ancc-save-map"data-action="ancc-sched"ancc_vars