
AnyComment Security & Risk Analysis
wordpress.org/plugins/anycommentAnyComment is blazing-fast commenting plugin based on React for WordPress.
Is AnyComment Safe to Use in 2026?
Critical Risk — Avoid
Score 17/100AnyComment is critically unsafe with 7 known CVEs, 3 still unpatched. Avoid in production.
The "anycomment" plugin v0.3.6 exhibits a mixed security posture. While the static analysis indicates a relatively small attack surface with no directly unprotected entry points, several concerning patterns emerge from the code signals and vulnerability history. The high percentage of SQL queries using prepared statements (91%) and a decent proportion of properly escaped output (74%) are positive indicators of some security awareness in development. However, the presence of unsanitized paths in taint analysis (3 flows) is a significant red flag, suggesting potential vulnerabilities related to file operations or external requests where input is not properly validated. The extensive vulnerability history, with 7 known CVEs and 3 currently unpatched, is particularly alarming. The variety of past vulnerability types, including SQL Injection, PHP Remote File Inclusion, and Cross-Site Scripting, highlights a history of critical security flaws. The recent vulnerability in 2025 further underscores that this is not a static issue but an ongoing concern. The combination of unpatched vulnerabilities and potential taint analysis issues suggests a high risk for systems running this plugin.
Key Concerns
- 3 unpatched CVEs
- 3 flows with unsanitized paths
- Bundled library: Guzzle
- Only 2 nonce checks for 2 shortcodes
- 74% output escaping (26% not properly escaped)
AnyComment Security Vulnerabilities
CVEs by Year
Severity Breakdown
7 total CVEs
AnyComment <= 0.3.6 - Missing Authorization
AnyComment <= 0.3.6 - Authenticated (Subscriber+) SQL Injection
AnyComment <= 0.3.6 - Unauthenticated Local File Inclusion
AnyComment <= 0.2.17 - Race Condition
AnyComment <= 0.2.17 - Cross-Site Request Forgery
AnyComment <= 0.3.4 - Open Redirect via redirect parameter
AnyComment <= 0.0.32 - Cross-Site Scripting
AnyComment Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
AnyComment Attack Surface
Shortcodes 2
WordPress Hooks 54
Scheduled Events 3
Maintenance & Trust
AnyComment Maintenance & Trust
Maintenance Signals
Community Trust
AnyComment Alternatives
Comment Edit Core – Simple Comment Editing
simple-comment-editing
Allow your users to edit their comments for a period of time. Adjust the comment timer and save some admin headaches.
Comments – wpDiscuz
wpdiscuz
AJAX powered realtime comments. Designed to extend WordPress native comments. Custom comment forms/fields. Making comments has never been so awesome!
Comment Moderation/Notification Recipients
comment-moderation-e-mail-to-post-author
Control who will receive new comment and moderation notifications. Light weight, simple, safe and effective.
FluentComments – Spam protection, AntiSpam, Ajax Enhanced Comments
fluent-comments
AJAX powered realtime comments. Designed to prevent spams, performance and make comments beautiful again 🚀
Comment Moderation Role by WPBeginner
comment-moderation-role
Add a new comment moderator user role to your site.
AnyComment Developer Profile
2 plugins · 3K total installs
How We Detect AnyComment
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/anycomment/assets/css/admin.min.css/wp-content/plugins/anycomment/assets/js/admin.min.js/wp-content/plugins/anycomment/assets/js/Chart.min.js/wp-content/plugins/anycomment/assets/js/Chart.min.js/wp-content/plugins/anycomment/assets/js/admin.min.jsanycomment/assets/css/admin.min.css?ver=anycomment/assets/js/admin.min.js?ver=anycomment/assets/js/Chart.min.js?ver=HTML / DOM Fingerprints
anycomment-dashboarddata-anycomment-admin-localeanycomment[anycomment]