
Comment Count Security & Risk Analysis
wordpress.org/plugins/comment-countCounts the number of comments.
Is Comment Count Safe to Use in 2026?
Generally Safe
Score 85/100Comment Count has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of the 'comment-count' plugin version 1.2 reveals a generally strong security posture with no identified attack vectors such as AJAX handlers, REST API routes, shortcodes, or cron events. The absence of dangerous functions, file operations, external HTTP requests, and taint flows with unsanitized paths further strengthens this positive outlook. However, significant concerns arise from the handling of SQL queries and output. The single SQL query is not using prepared statements, introducing a potential SQL injection risk. Furthermore, none of the total outputs are properly escaped, creating a risk of Cross-Site Scripting (XSS) vulnerabilities. The lack of any recorded vulnerabilities in its history is a positive sign, suggesting the plugin has historically been maintained securely. Despite the lack of active exploitation paths, the identified SQL and output handling issues represent tangible risks that require immediate attention.
Key Concerns
- SQL query not using prepared statements
- No output escaping found
Comment Count Security Vulnerabilities
Comment Count Release Timeline
Comment Count Code Analysis
SQL Query Safety
Output Escaping
Comment Count Attack Surface
Maintenance & Trust
Comment Count Maintenance & Trust
Maintenance Signals
Community Trust
Comment Count Alternatives
Admin Commenters Comments Count
admin-commenters-comments-count
Displays a count of each commenter's total number of comments (linked to those comments) next to their name on any admin page.
Simple Top Commenters
simple-top-commenters
A sidebar widget that displays a list of top commenters across a site, showing the number of comments for each.
DX2 Post Hit Counter
dx2-post-hit-counter
A lightweight counter to track the number of hits on all posts on the website.
Comment Count Admin (by URL)
comment-count-admin
Displays a count of each comment authors total number of comments next to their name on the admin pages.
Aquiline Comment Country Flags for GeneratePress
aquiline-comment-country-flags
Affords a commenter on a GeneratePress blog the option to affix a country flag to the right of their name in the comment header.
Comment Count Developer Profile
12 plugins · 3K total installs
How We Detect Comment Count
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
<p dir="ltr">