CellarWeb Instant Comment Management Security & Risk Analysis

wordpress.org/plugins/cellarweb-instant-comment-management

Easily moderate comments from the front end comment display with spam/trash/delete options for admins only.

0 active installs v1.01 PHP 7.3+ WP 4.9+ Updated Unknown
comment-manage-monitor-moderate
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is CellarWeb Instant Comment Management Safe to Use in 2026?

Generally Safe

Score 100/100

CellarWeb Instant Comment Management has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The cellarweb-instant-comment-management plugin version 1.01 exhibits a mixed security posture. On the positive side, the static analysis indicates a very small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, all detected SQL queries utilize prepared statements, and there are no direct file operations or external HTTP requests, which are generally good practices for minimizing risk. The plugin also includes one capability check, demonstrating some awareness of permission management.

However, a significant concern arises from the output escaping. With 5 total outputs and 0% properly escaped, this plugin presents a clear risk of cross-site scripting (XSS) vulnerabilities. Any data displayed to users that originates from user input or other sources without proper sanitization could be exploited. The absence of nonce checks on AJAX (though there are no AJAX handlers) and the lack of critical or high severity taint flows are positive signs, but the unescaped output remains a substantial threat.

The plugin's vulnerability history is clean, with no known CVEs. This suggests that either the plugin has not been a target, or its developers have maintained a good security record in the past. However, the lack of historical vulnerabilities should not be interpreted as a guarantee of future security, especially given the identified output escaping issues. The overall conclusion is that while the plugin has a limited attack surface and uses secure database practices, the critical failure in output escaping creates a significant security weakness that needs immediate attention.

Key Concerns

  • Unescaped output
Vulnerabilities
None known

CellarWeb Instant Comment Management Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

CellarWeb Instant Comment Management Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
0 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped5 total outputs
Attack Surface

CellarWeb Instant Comment Management Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionwp_enqueue_scriptscellarweb-instant-comment-management.php:28
actionadmin_menucellarweb-instant-comment-management.php:75
actioninitcellarweb-instant-comment-management.php:179
Maintenance & Trust

CellarWeb Instant Comment Management Maintenance & Trust

Maintenance Signals

WordPress version tested6.3.8
Last updatedUnknown
PHP min version7.3
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Alternatives

CellarWeb Instant Comment Management Alternatives

No alternatives data available yet.

Developer Profile

CellarWeb Instant Comment Management Developer Profile

Rick Hellewell

16 plugins · 1K total installs

88
trust score
Avg Security Score
91/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect CellarWeb Instant Comment Management

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cellarweb-instant-comment-management/assets/banner-1000x200.jpg/wp-content/plugins/cellarweb-instant-comment-management/assets/screenshot-1.jpg
Script Paths
/wp-content/plugins/cellarweb-instant-comment-management/js/cwicm_comment_ajax_actions.js
Version Parameters
cellarweb-instant-comment-management/js/cwicm_comment_ajax_actions.js?ver=

HTML / DOM Fingerprints

CSS Classes
CWICM_headerCWICM_shadowCWICM_optionsCWICM_sidebarCWICM_footerCWICM_list_disc
HTML Comments
not sure why this one is needed ...
Data Attributes
CWICM_settings
FAQ

Frequently Asked Questions about CellarWeb Instant Comment Management