CleanMod – AI Comment Moderation Security & Risk Analysis

wordpress.org/plugins/cleanmod

Uses CleanMod to detect toxic comments and automatically hold or block them.

0 active installs v0.1.0 PHP 7.4+ WP 5.0+ Updated Unknown
aicommentscontent-moderationmoderationspam
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is CleanMod – AI Comment Moderation Safe to Use in 2026?

Generally Safe

Score 100/100

CleanMod – AI Comment Moderation has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The plugin 'cleanmod' v0.1.0 demonstrates a generally strong security posture based on the provided static analysis. It exhibits excellent practices by having no known dangerous functions, all SQL queries using prepared statements, and all output properly escaped. The absence of file operations and external HTTP requests also reduces the potential attack surface. Furthermore, the plugin's vulnerability history is clean, with no recorded CVEs, indicating a low likelihood of previously identified weaknesses.

However, a few areas warrant attention. The complete lack of nonce checks and capability checks across its zero identified entry points is a significant concern. While the attack surface is currently zero, any future addition of AJAX handlers, REST API routes, or shortcodes without proper authentication and authorization mechanisms would immediately expose the plugin to significant risks. The single external HTTP request, although not inherently dangerous, is an area that requires careful monitoring as it represents a potential vector for introducing vulnerabilities if not handled with extreme caution.

In conclusion, 'cleanmod' v0.1.0 is built on a solid foundation of secure coding practices. Its zero-known vulnerabilities and robust internal handling of data are commendable. The primary weakness lies in the absence of any explicit security checks for potential future entry points, which, if not addressed proactively, could lead to critical vulnerabilities with even minor code additions. The single external HTTP request also deserves scrutiny.

Key Concerns

  • No nonce checks detected
  • No capability checks detected
  • External HTTP request without context
Vulnerabilities
None known

CleanMod – AI Comment Moderation Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

CleanMod – AI Comment Moderation Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
13 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

100% escaped13 total outputs
Attack Surface

CleanMod – AI Comment Moderation Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionplugins_loadedcleanmod.php:43
filterpre_comment_approvedincludes\class-cleanmod-moderation.php:24
actionadmin_menuincludes\class-cleanmod-settings.php:30
actionadmin_initincludes\class-cleanmod-settings.php:31
actionadmin_enqueue_scriptsincludes\class-cleanmod-settings.php:32
Maintenance & Trust

CleanMod – AI Comment Moderation Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedUnknown
PHP min version7.4
Downloads124

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

CleanMod – AI Comment Moderation Developer Profile

cleanmod

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect CleanMod – AI Comment Moderation

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cleanmod/admin/css/settings.css/wp-content/plugins/cleanmod/admin/js/settings.js
Script Paths
/wp-content/plugins/cleanmod/admin/js/settings.js
Version Parameters
cleanmod/admin/css/settings.css?ver=cleanmod/admin/js/settings.js?ver=

HTML / DOM Fingerprints

CSS Classes
cleanmod-help-section
Data Attributes
name="cleanmod_settings[api_key]"name="cleanmod_settings[behavior_block]"name="cleanmod_settings[behavior_flag]"name="cleanmod_settings[enabled]"
FAQ

Frequently Asked Questions about CleanMod – AI Comment Moderation