
AtMention in Comments Security & Risk Analysis
wordpress.org/plugins/atmention-in-commentsA plugin that enables you to mention @comment__author in comments.
Is AtMention in Comments Safe to Use in 2026?
Generally Safe
Score 92/100AtMention in Comments has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'atmention-in-comments' v2.0.1 plugin exhibits a strong security posture based on the provided static analysis. The absence of any detected dangerous functions, file operations, external HTTP requests, and the exclusive use of prepared statements for SQL queries are excellent indicators of secure coding practices. Furthermore, the comprehensive output escaping across all identified outputs and the lack of reported vulnerabilities in its history suggest a well-maintained and secure plugin.
However, a notable concern arises from the complete absence of nonce checks and capability checks. While no immediate vulnerabilities are evident from the static analysis or vulnerability history, this lack of authorization and integrity checks means that if any future functionality is added that modifies data or performs sensitive actions, it would be inherently vulnerable to CSRF (Cross-Site Request Forgery) attacks and unauthorized access. The analysis also shows zero AJAX handlers and REST API routes, meaning there are no entry points to even test for these protections, which is a double-edged sword: no attack surface currently, but no built-in safeguards for potential future expansion.
In conclusion, the plugin's current implementation is remarkably secure. The development team has demonstrated a commitment to safe coding by avoiding known dangerous patterns and properly sanitizing output. The primary weakness is the lack of fundamental security checks that would protect against potential future threats should the plugin's functionality evolve. This is a significant oversight that, while not currently exploitable, presents a latent risk.
Key Concerns
- Missing nonce checks
- Missing capability checks
AtMention in Comments Security Vulnerabilities
AtMention in Comments Code Analysis
SQL Query Safety
Output Escaping
AtMention in Comments Attack Surface
WordPress Hooks 5
Maintenance & Trust
AtMention in Comments Maintenance & Trust
Maintenance Signals
Community Trust
AtMention in Comments Alternatives
Twitter Mentions As Comments
twitter-mentions-as-comments
Twitter Mentions as Comments scours Twitter for people talking about your site & silently inserts their Tweets alongside your existing comments.
Comments Users Mentions
comments-users-mentions
Allows to mention Wordpress users in a comment. The mentioned users will receive a notification email.
Email Mentioned
email-mentioned
Email Mentioned is a lightweight customizable -no coding needed- plugin to send an email to each user mentioned in comments.
Twitter mentions in posts
twitter-mentions-in-posts
Show tweets about your posts right under them.
Akismet Anti-spam: Spam Protection
akismet
The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam solution for WordPress and WooCommerce.
AtMention in Comments Developer Profile
3 plugins · 10K total installs
How We Detect AtMention in Comments
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/atmention-in-comments/assets/css/atmention-in-comments.css/wp-content/plugins/atmention-in-comments/assets/js/atmention-in-comments.js/wp-content/plugins/atmention-in-comments/assets/js/atmention-in-comments.jsatmention-in-comments/assets/css/atmention-in-comments.css?ver=atmention-in-comments/assets/js/atmention-in-comments.js?ver=HTML / DOM Fingerprints
atmention-in-comments-userdata-atmention-user-idatmention_vars