
Antispam Collateral Condolences Security & Risk Analysis
wordpress.org/plugins/antispam-collateral-condolencesNotifies people when their comment is moderated or caught as spam, so they aren't left wondering.
Is Antispam Collateral Condolences Safe to Use in 2026?
Generally Safe
Score 85/100Antispam Collateral Condolences has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the provided static analysis and vulnerability history, the 'antispam-collateral-condolences' plugin version 0.3 exhibits a generally strong security posture, particularly regarding common web vulnerabilities. The absence of any known CVEs and a clean vulnerability history indicate a well-maintained and secure codebase. Furthermore, the code analysis shows excellent practices such as 100% of SQL queries using prepared statements and 100% of output being properly escaped. The plugin also has zero external HTTP requests and no file operations, significantly reducing its potential attack surface in these areas. The low attack surface with zero entry points, especially those without authentication, is a major strength.
However, a significant concern is the presence of the `create_function` dangerous function. While the taint analysis shows no unsanitized paths, the use of `create_function` is a well-known security anti-pattern in PHP. It allows for the dynamic creation of functions from strings, which can be exploited if user-supplied data is incorporated into these strings without proper sanitization, potentially leading to arbitrary code execution. Although no vulnerabilities have been recorded historically, this specific code signal warrants attention and should be addressed to eliminate this potential risk. The lack of capability checks also means that any potential vulnerabilities within the entry points (though none are currently identified) might not be adequately protected by WordPress's role-based access control.
Key Concerns
- Presence of create_function dangerous function
- Zero capability checks found
Antispam Collateral Condolences Security Vulnerabilities
Antispam Collateral Condolences Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
Antispam Collateral Condolences Attack Surface
WordPress Hooks 5
Maintenance & Trust
Antispam Collateral Condolences Maintenance & Trust
Maintenance Signals
Community Trust
Antispam Collateral Condolences Alternatives
AJAX Report Comments
report-comments
AJAX Report Comments is a simple yet powerful add-on for any Wordpress blog, particularly larger blogs with a higher volume of user comments.
Tolstoy Comments
tolstoy-comments
Tolstoy Comments – Быстрая real-time система комментирования с геймификацией и авторизацией через соцсети.
Yappa Widget
yappa-widget
Yappa is the web's most popular comment system. Use Yappa to increase engagement, retain readers, and grow your audience.
Akismet Anti-spam: Spam Protection
akismet
The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam solution for WordPress and WooCommerce.
Disable Comments – Remove Comments & Stop Spam [Multi-Site Support]
disable-comments
Allows administrators to globally disable comments on their site. Comments can be disabled according to post type. Multisite friendly.
Antispam Collateral Condolences Developer Profile
29 plugins · 176K total installs
How We Detect Antispam Collateral Condolences
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
cws-acc-comment-caught