Comment Count Admin (by URL) Security & Risk Analysis

wordpress.org/plugins/comment-count-admin

Displays a count of each comment authors total number of comments next to their name on the admin pages.

10 active installs v1.5 PHP + WP 3.9+ Updated Jul 18, 2014
admincomment-authorcomment-countcomment-urlcomments
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Comment Count Admin (by URL) Safe to Use in 2026?

Generally Safe

Score 85/100

Comment Count Admin (by URL) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The "comment-count-admin" plugin v1.5 exhibits a strong security posture based on the provided static analysis and vulnerability history. The code analysis reveals no dangerous functions, all SQL queries utilize prepared statements, and output is consistently escaped. Furthermore, the absence of file operations and external HTTP requests minimizes potential attack vectors. The plugin also has no known CVEs, indicating a clean history.

However, the complete lack of any entry points analyzed (AJAX handlers, REST API routes, shortcodes, cron events) is unusual. While this might indicate a very simple plugin that doesn't require user interaction or scheduled tasks, it's also possible that the static analysis tools did not detect or were unable to analyze these components. The absence of nonce and capability checks, while not a direct issue given the lack of entry points, represents a potential future risk if new features are added that introduce such points without proper security controls.

In conclusion, "comment-count-admin" v1.5 appears to be a secure plugin with no immediate vulnerabilities detected. Its strengths lie in its clean code and lack of historical issues. The primary concern is the lack of observable entry points in the analysis, which could mask potential issues or indicate a very limited scope. It is recommended to ensure any future development adheres to the secure coding practices already demonstrated.

Key Concerns

  • No observable entry points analyzed
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Comment Count Admin (by URL) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Comment Count Admin (by URL) Release Timeline

vVersion_1.5
vVersion_1.4
vVersion_1.3
vVersion_1.2
vVersion_1.1
Code Analysis
Analyzed Mar 17, 2026

Comment Count Admin (by URL) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared4 total queries
Attack Surface

Comment Count Admin (by URL) Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
filterget_comment_authorcomment-count-admin.php:58
Maintenance & Trust

Comment Count Admin (by URL) Maintenance & Trust

Maintenance Signals

WordPress version tested3.9.40
Last updatedJul 18, 2014
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Comment Count Admin (by URL) Developer Profile

Jan Teriete

3 plugins · 1K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Comment Count Admin (by URL)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Comment Count Admin (by URL)