Antispam Collateral Condolences Security & Risk Analysis

wordpress.org/plugins/antispam-collateral-condolences

Notifies people when their comment is moderated or caught as spam, so they aren't left wondering.

10 active installs v0.3 PHP + WP 2.8+ Updated Sep 8, 2009
commentsnotificationspam
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Antispam Collateral Condolences Safe to Use in 2026?

Generally Safe

Score 85/100

Antispam Collateral Condolences has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 16yr ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the 'antispam-collateral-condolences' plugin version 0.3 exhibits a generally strong security posture, particularly regarding common web vulnerabilities. The absence of any known CVEs and a clean vulnerability history indicate a well-maintained and secure codebase. Furthermore, the code analysis shows excellent practices such as 100% of SQL queries using prepared statements and 100% of output being properly escaped. The plugin also has zero external HTTP requests and no file operations, significantly reducing its potential attack surface in these areas. The low attack surface with zero entry points, especially those without authentication, is a major strength.

However, a significant concern is the presence of the `create_function` dangerous function. While the taint analysis shows no unsanitized paths, the use of `create_function` is a well-known security anti-pattern in PHP. It allows for the dynamic creation of functions from strings, which can be exploited if user-supplied data is incorporated into these strings without proper sanitization, potentially leading to arbitrary code execution. Although no vulnerabilities have been recorded historically, this specific code signal warrants attention and should be addressed to eliminate this potential risk. The lack of capability checks also means that any potential vulnerabilities within the entry points (though none are currently identified) might not be adequately protected by WordPress's role-based access control.

Key Concerns

  • Presence of create_function dangerous function
  • Zero capability checks found
Vulnerabilities
None known

Antispam Collateral Condolences Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Antispam Collateral Condolences Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
0 prepared
Unescaped Output
0
2 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

create_functionadd_action( 'admin_menu', create_function( '', "add_options_page( 'Antispam Collateral Condolences',antispam-collateral-condolences.php:134

Output Escaping

100% escaped2 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
cws_acc_save_options (antispam-collateral-condolences.php:105)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Antispam Collateral Condolences Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actioncomment_formantispam-collateral-condolences.php:129
actionwp_headantispam-collateral-condolences.php:131
filtercomment_post_redirectantispam-collateral-condolences.php:133
actionadmin_menuantispam-collateral-condolences.php:134
actionadmin_initantispam-collateral-condolences.php:135
Maintenance & Trust

Antispam Collateral Condolences Maintenance & Trust

Maintenance Signals

WordPress version tested2.8.4
Last updatedSep 8, 2009
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Antispam Collateral Condolences Developer Profile

Mark Jaquith

29 plugins · 176K total installs

69
trust score
Avg Security Score
86/100
Avg Patch Time
3337 days
View full developer profile
Detection Fingerprints

How We Detect Antispam Collateral Condolences

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
cws-acc-comment-caught
FAQ

Frequently Asked Questions about Antispam Collateral Condolences