
Approved Comments Only Security & Risk Analysis
wordpress.org/plugins/approved-comments-onlyRestrict user to view the unapproved comments in dashboard.
Is Approved Comments Only Safe to Use in 2026?
Generally Safe
Score 85/100Approved Comments Only has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'approved-comments-only' plugin v1.2 exhibits a strong security posture based on the provided static analysis results. The absence of AJAX handlers, REST API routes, shortcodes, cron events, and file operations significantly limits the attack surface. Furthermore, the code demonstrates good practices by utilizing prepared statements for all SQL queries and having a high percentage of properly escaped output. The lack of dangerous functions and external HTTP requests further reinforces its secure design. The vulnerability history shows no recorded CVEs, indicating a lack of publicly disclosed security flaws. This suggests that the plugin has historically been maintained with security in mind or has not yet attracted significant security scrutiny.
However, a notable concern arises from the complete absence of nonce checks and capability checks. While the current analysis shows no direct entry points without authentication, this lack of checks creates a potential weakness. If future updates introduce new functionalities, especially AJAX handlers or REST API endpoints, without implementing proper nonce and capability verification, it could lead to vulnerabilities such as Cross-Site Request Forgery (CSRF) or unauthorized access. The taint analysis showing no identified flows is positive, but it's crucial to recognize that static analysis has limitations and might not catch all complex or context-dependent vulnerabilities. The overall conclusion is that the plugin is currently secure, but the absence of nonce and capability checks represents a significant technical debt that could introduce risks if not addressed in future development.
Key Concerns
- Missing nonce checks
- Missing capability checks
Approved Comments Only Security Vulnerabilities
Approved Comments Only Release Timeline
Approved Comments Only Code Analysis
Output Escaping
Approved Comments Only Attack Surface
WordPress Hooks 7
Maintenance & Trust
Approved Comments Only Maintenance & Trust
Maintenance Signals
Community Trust
Approved Comments Only Alternatives
Comments Counter
comments-counter
Display the count of all types of comments.
No External Links
mihdan-no-external-links
Convert external links into internal links, site wide or post/page specific. Add NoFollow, Click logging, and more...
Disqus Conditional Load
disqus-conditional-load
Use Disqus comments with advanced features like lazy load, shortcode, widgets etc. Don't let Disqus to slow your site down.
Conditional Blocks – Advanced Content Visibility Control for WordPress
conditional-blocks
Easily show/hide WordPress blocks & widgets with powerful, no-code display logic. Perfect for restricting content. Explore advanced scheduling, Ge …
Anonymous Restricted Content
anonymous-restricted-content
Simple but yet effective plugin to hide selected posts and pages from anonymous users.
Approved Comments Only Developer Profile
1 plugin · 10 total installs
How We Detect Approved Comments Only
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/approved-comments-only/assets/css/approved-comments-only.cssapproved-comments-only/assets/css/approved-comments-only.css?ver=HTML / DOM Fingerprints
tablenav-pagesdisplaying-numpaging-inputtablenav-pages-navspanfirst-pageprev-pagenext-pagelast-page+1 moreid="current-page-selector"