Attachment Page Comment Control Security & Risk Analysis

wordpress.org/plugins/attachment-page-comment-control

Gives you the ability to turn comments and pings on or off for individual attachment pages within your media library.

30 active installs v1.0.2 PHP + WP 2.5+ Updated Jun 3, 2010
attachmentscommentsmedia-librarypings
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Attachment Page Comment Control Safe to Use in 2026?

Generally Safe

Score 85/100

Attachment Page Comment Control has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 15yr ago
Risk Assessment

The static analysis of the 'attachment-page-comment-control' plugin v1.0.2 reveals an exceptionally clean codebase with no identified dangerous functions, SQL injection vulnerabilities, or unescaped output. The absence of file operations and external HTTP requests further strengthens its security profile. Crucially, the plugin demonstrates excellent security practices by utilizing prepared statements for all its SQL queries, and the reported lack of any CVEs in its vulnerability history suggests a strong track record of security.

However, the complete absence of nonces and capability checks across all entry points presents a significant concern. While the static analysis found no direct entry points that are unprotected, the lack of these fundamental security mechanisms means that even if future functionality is added or existing functionality is modified, it could be inadvertently exposed to unauthorized access or manipulation. This indicates a potential for security weaknesses in the broader implementation context, particularly if the plugin interacts with sensitive data or actions without proper authorization controls.

In conclusion, 'attachment-page-comment-control' v1.0.2 boasts a technically sound and clean codebase with no known vulnerabilities. Its strengths lie in its avoidance of common pitfalls like unescaped output and raw SQL. Nevertheless, the pervasive lack of nonces and capability checks is a notable weakness that could expose the plugin to security risks if not carefully managed or addressed in future updates.

Key Concerns

  • Missing nonce checks on entry points
  • Missing capability checks on entry points
Vulnerabilities
None known

Attachment Page Comment Control Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Attachment Page Comment Control Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Attachment Page Comment Control Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
filterattachment_fields_to_editAttachmentPageCommentControl.php:13
filterattachment_fields_to_saveAttachmentPageCommentControl.php:14
filterplugin_row_metaAttachmentPageCommentControl.php:15
Maintenance & Trust

Attachment Page Comment Control Maintenance & Trust

Maintenance Signals

WordPress version tested3.0.5
Last updatedJun 3, 2010
PHP min version
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs30
Developer Profile

Attachment Page Comment Control Developer Profile

laceous

3 plugins · 120 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Attachment Page Comment Control

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Data Attributes
attachments[*:comment_status]attachments[*:ping_status]
FAQ

Frequently Asked Questions about Attachment Page Comment Control