
Comment Mail Security & Risk Analysis
wordpress.org/plugins/comment-mailLicense: GPLv3 or later License URI: http://www.gnu.org/licenses/gpl-3.0.html Author: WP Sharks Author URI: http://comment-mail.
Is Comment Mail Safe to Use in 2026?
Generally Safe
Score 85/100Comment Mail has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'comment-mail' plugin v161213 exhibits a generally good security posture with a robust implementation of prepared statements for SQL queries and a high percentage of properly escaped output. The absence of known CVEs and a clean vulnerability history further contribute to its positive security profile. However, the presence of two dangerous functions, `unserialize` and `create_function`, presents a significant concern. These functions, if mishandled or exposed to untrusted input, can lead to serious security vulnerabilities like remote code execution. While the static analysis did not reveal any critical or high-severity taint flows, the potential for exploitation with these functions cannot be ignored. The plugin's attack surface appears minimal, with no exposed AJAX handlers, REST API routes, or shortcodes without authentication checks, which is a strong mitigating factor.
Key Concerns
- Use of unserialize()
- Use of create_function()
- 5 unsanitized path flows in taint analysis
- 31% output not properly escaped
Comment Mail Security Vulnerabilities
Comment Mail Release Timeline
Comment Mail Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Comment Mail Attack Surface
WordPress Hooks 40
Maintenance & Trust
Comment Mail Maintenance & Trust
Maintenance Signals
Community Trust
Comment Mail Alternatives
No alternatives data available yet.
Comment Mail Developer Profile
3 plugins · 29K total installs
How We Detect Comment Mail
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/comment-mail/assets/css/admin.css/wp-content/plugins/comment-mail/assets/css/comment-mail.css/wp-content/plugins/comment-mail/assets/js/admin.js/wp-content/plugins/comment-mail/assets/js/comment-mail.js/wp-content/plugins/comment-mail/assets/js/admin.js/wp-content/plugins/comment-mail/assets/js/comment-mail.jscomment-mail/assets/css/admin.css?ver=comment-mail/assets/css/comment-mail.css?ver=comment-mail/assets/js/admin.js?ver=comment-mail/assets/js/comment-mail.js?ver=HTML / DOM Fingerprints
comment-mail-admin-pagecomment-mail-admin-settingscomment-mail-admin-settings-section<!-- Start: Comment Mail --><!-- End: Comment Mail --><!-- Comment Mail Login Form SSO Scripts --><!-- Comment Mail Comment Form SSO Scripts -->+1 moredata-comment-mail-plugin-optionsdata-comment-mail-plugin-versionCommentMail