
Comment Hierarchy Adjust Security & Risk Analysis
wordpress.org/plugins/comment-hierarchy-adjustAdds a comment hierarchy to the edit comment screen to re-thread comments due to user error.
Is Comment Hierarchy Adjust Safe to Use in 2026?
Generally Safe
Score 100/100Comment Hierarchy Adjust has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The comment-hierarchy-adjust plugin version 1.0 exhibits a mixed security posture. On the positive side, it avoids dangerous functions, has no file operations or external HTTP requests, and all its SQL queries utilize prepared statements, indicating good practices in database interaction. The absence of any recorded vulnerabilities in its history is also a strong indicator of careful development. However, significant concerns arise from the static analysis. The plugin has a small attack surface, but critically, one of its AJAX handlers lacks any authentication checks. Furthermore, none of the identified outputs are properly escaped, which is a widespread issue. The complete absence of nonce checks on its entry points, combined with the unauthenticated AJAX handler, creates a clear pathway for potential exploitation.
Key Concerns
- AJAX handler without auth checks
- Unescaped output (4/5 outputs)
- No nonce checks on entry points
Comment Hierarchy Adjust Security Vulnerabilities
Comment Hierarchy Adjust Code Analysis
Output Escaping
Comment Hierarchy Adjust Attack Surface
AJAX Handlers 1
WordPress Hooks 3
Maintenance & Trust
Comment Hierarchy Adjust Maintenance & Trust
Maintenance Signals
Community Trust
Comment Hierarchy Adjust Alternatives
Akismet Anti-spam: Spam Protection
akismet
The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam solution for WordPress and WooCommerce.
Disable Comments – Remove Comments & Stop Spam [Multi-Site Support]
disable-comments
Allows administrators to globally disable comments on their site. Comments can be disabled according to post type. Multisite friendly.
Antispam Bee
antispam-bee
Sophisticated antispam plugin for effective daily comment and trackback spam-fighting. Built with data protection and privacy in mind.
WP Armour – Honeypot Anti Spam
honeypot
Fastest growing Anti Spam plugin. No API calls, subscriptions, captcha or puzzle. Full GDPR complaint. For comments, contact form, login, registration
Advanced Google reCAPTCHA
advanced-google-recaptcha
Captcha protection against spam comments & brute force login attacks using Google reCAPTCHA.
Comment Hierarchy Adjust Developer Profile
18 plugins · 2K total installs
How We Detect Comment Hierarchy Adjust
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/comment-hierarchy-adjust/js/cha.ajax.js/wp-content/plugins/comment-hierarchy-adjust/js/cha.ajax.jsHTML / DOM Fingerprints
comment_xtraid="comment_parent"chaL10n