
Better WordPress Recent Comments Security & Risk Analysis
wordpress.org/plugins/bwp-recent-commentsThis plugin displays recent comment lists at assigned locations, with comprehensive support for widgets.
Is Better WordPress Recent Comments Safe to Use in 2026?
Generally Safe
Score 85/100Better WordPress Recent Comments has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The bwp-recent-comments plugin version 1.2.2 exhibits a mixed security posture. On the positive side, it has a very small attack surface, with only one entry point identified (a shortcode) and no AJAX handlers, REST API routes, or cron events. Furthermore, the plugin has no recorded vulnerability history, which suggests a history of good security practices or a lack of targeted attacks. However, the static analysis reveals significant concerns. The presence of the `create_function` function is a clear indicator of potential security risks, as it is highly discouraged due to its ability to execute arbitrary code. Additionally, a substantial portion of output (76%) is not properly escaped, increasing the risk of Cross-Site Scripting (XSS) vulnerabilities, especially if the shortcode handles user-supplied data. While the majority of SQL queries use prepared statements, the presence of any raw SQL could still be problematic if not carefully handled. The taint analysis showing two flows with unsanitized paths, despite having no critical or high severity findings, warrants attention as it indicates potential data leakage or manipulation possibilities.
Key Concerns
- Use of dangerous function create_function
- High percentage of unescaped output
- Flows with unsanitized paths found in taint analysis
Better WordPress Recent Comments Security Vulnerabilities
Better WordPress Recent Comments Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Better WordPress Recent Comments Attack Surface
Shortcodes 1
WordPress Hooks 22
Maintenance & Trust
Better WordPress Recent Comments Maintenance & Trust
Maintenance Signals
Community Trust
Better WordPress Recent Comments Alternatives
Recent Comments Widget Plus
comments-widget-plus
Provides custom recent comments widget with extra features such as display avatar, comment excerpt and much more!
Customized Recent Comments
customized-recent-comments
Display recent comments on your blog with complete control over the layout and format of comments.
Polygon Recent Comments With Avatar
polygon-recent-comments-with-avatar
Polygon Recent Comments With Avatar: Recent comments with avatar support, including Gravatar, date, username, user link, and scrollbar.
Recent Comments Widget with Comment Excerpts
recent-comments-widget-with-comment-excerpts
Changes the behavior of the built-in Recent Comments widget to display comment excerpts instead of post titles
Advanced Comments Widget
advanced-comments-widget
A highly customizable recent comments widget with avatars and excerpts.
Better WordPress Recent Comments Developer Profile
4 plugins · 9K total installs
How We Detect Better WordPress Recent Comments
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bwp-recent-comments/bwp-recent-comments.css/wp-content/plugins/bwp-recent-comments/js/bwp-recent-comments.js/wp-content/plugins/bwp-recent-comments/js/bwp-recent-comments.jsbwp-recent-comments/bwp-recent-comments.css?ver=bwp-recent-comments/js/bwp-recent-comments.js?ver=HTML / DOM Fingerprints
bwp-rc-widgetbwp_rc_widgetbwp-rc-no-avatarbwp-rc-show-avatar<!-- BEGIN BWP Recent Comments --><!-- END BWP Recent Comments --><!-- BEGIN BWP Recent Comments Widget --><!-- END BWP Recent Comments Widget -->data-show-avatardata-comment-countbwp_rc_configs[bwp_recent_comments