
Comment Controller Security & Risk Analysis
wordpress.org/plugins/comment-controllerAllow users to disable comments for their account, or disable comments site-wide per post type or role.
Is Comment Controller Safe to Use in 2026?
Generally Safe
Score 100/100Comment Controller has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of 'comment-controller' v1.1.5 reveals a generally strong security posture, with no identified vulnerabilities in the attack surface, dangerous functions, file operations, or external HTTP requests. The plugin demonstrates good practices by utilizing prepared statements for all SQL queries and incorporating nonce and capability checks. However, a significant concern arises from the output escaping analysis, which indicates that 100% of its outputs are not properly escaped. This presents a substantial risk of Cross-Site Scripting (XSS) vulnerabilities, as malicious scripts could be injected and executed within the WordPress environment through user-generated content or plugin output.
Key Concerns
- No proper output escaping
Comment Controller Security Vulnerabilities
Comment Controller Release Timeline
Comment Controller Code Analysis
Output Escaping
Comment Controller Attack Surface
WordPress Hooks 12
Maintenance & Trust
Comment Controller Maintenance & Trust
Maintenance Signals
Community Trust
Comment Controller Alternatives
Disable Comments – Remove Comments & Stop Spam [Multi-Site Support]
disable-comments
Allows administrators to globally disable comments on their site. Comments can be disabled according to post type. Multisite friendly.
Disable Comments
disable-comments-rb
Disable Comments - easy tool to disable comments for your blog posts, and pages. Admin can disable comments in just a few clicks.
Comment Cleaner — Bulk Delete & Disable Comments
delete-all-comments-of-website
Delete, export, import, and manage WordPress comments with bulk tools and comment-control settings.
Disable Comments
wpsimpletools-disable-comments
Completely disables comments functionality from backend and frontend. Just install it, nothing to configure!
Disable Comments & Delete All Comments
comments-plus
Disable comments globally on all posts or certain post types. Delete all comments at once, by post type or comment status. Manage links in comments.
Comment Controller Developer Profile
25 plugins · 150K total installs
How We Detect Comment Controller
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/comment-controller/vendor/widgitlabs/simple-settings/class-simple-settings.php/wp-content/plugins/comment-controller/includes/admin/settings/register-settings.php/wp-content/plugins/comment-controller/includes/misc-functions.php/wp-content/plugins/comment-controller/includes/profile.phpHTML / DOM Fingerprints
comment_controller_disallowcomment_controller_disable