
Advanced Comment Form Security & Risk Analysis
wordpress.org/plugins/comment-formAdvanced Comment Form lets you customize plenty of things on the default comment forms in WordPress.
Is Advanced Comment Form Safe to Use in 2026?
Generally Safe
Score 92/100Advanced Comment Form has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "comment-form" plugin v1.2.3 exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and having no identified dangerous functions, file operations, or external HTTP requests. The attack surface appears limited with no unprotected entry points detected in the static analysis. However, a significant concern is the extremely low percentage (6%) of properly escaped output, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. The absence of nonce and capability checks on its single shortcode entry point is also a notable weakness.
The vulnerability history reveals a past medium-severity XSS vulnerability, which aligns with the static analysis findings regarding poor output escaping. While there are no currently unpatched vulnerabilities, the past incident underscores the plugin's susceptibility to this type of attack. The limited number of flows analyzed in the taint analysis might mean that deeper vulnerabilities could exist but were not detected by the current analysis.
In conclusion, while the plugin has strengths in database interaction and avoiding common risky behaviors like raw SQL, the widespread lack of output escaping presents a substantial risk of XSS. The absence of security checks on its shortcode further exacerbates this. The past XSS vulnerability reinforces the need for immediate attention to output sanitation.
Key Concerns
- Low percentage of properly escaped output (6%)
- Missing nonce checks on shortcode
- Missing capability checks on shortcode
- Past medium severity XSS vulnerability (2022-09-15)
Advanced Comment Form Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Advanced Comment Form <= 1.2.0 - Authenticated (Administrator+) Stored Cross-Site Scripting
Advanced Comment Form Release Timeline
Advanced Comment Form Code Analysis
Output Escaping
Advanced Comment Form Attack Surface
Shortcodes 1
WordPress Hooks 10
Maintenance & Trust
Advanced Comment Form Maintenance & Trust
Maintenance Signals
Community Trust
Advanced Comment Form Alternatives
Comments – wpDiscuz
wpdiscuz
AJAX powered realtime comments. Designed to extend WordPress native comments. Custom comment forms/fields. Making comments has never been so awesome!
Comments Form Star Rating Plugin for WordPress
comments-form-star-rating
Allow your customers to add star rattings in comment form.
Comments Extra Fields For Post,Pages and CPT
wp-comment-fields
This plugin allow admin to add extra fields in comment area. These fields are saved as comment meta and is displayed under comment text.
Custom Comment Form Title
custom-comment-form-title
Engage your visitors and initiate discussion with more meaningful comment form titles, created on a post-by-post basis!
Hide-n-Disable-comment-url-field
hide-n-disable-comment-url-field
This plugin will hide and disable the URL field from wordpress default comment form.Just Activate the plugin and start using.
Advanced Comment Form Developer Profile
7 plugins · 16K total installs
How We Detect Advanced Comment Form
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/comment-form/frontend/comment_form_frontend.php/wp-content/plugins/comment-form/admin/comment_form_admin.php/wp-content/plugins/comment-form/inc/comment_form_main.phpHTML / DOM Fingerprints
comment-form-leftcomment-form-rightcomment_notescomment_text_after[comment-form]