
Comment Mention Security & Risk Analysis
wordpress.org/plugins/comment-mentionMention users in WordPress comments without needing BuddyPress! Automatically notify mentioned users via email. Also supports bbPress.
Is Comment Mention Safe to Use in 2026?
Generally Safe
Score 100/100Comment Mention has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "comment-mention" plugin version 1.7.20 exhibits a generally good security posture with notable strengths in its handling of SQL queries and output escaping. The fact that 100% of SQL queries use prepared statements and 98% of outputs are properly escaped indicates a developer aware of common web security pitfalls. Furthermore, the absence of any known vulnerabilities (CVEs) or recorded past issues is a positive sign. However, a significant concern arises from the presence of a single AJAX handler that lacks any authentication checks. This creates a potential entry point for unauthenticated users to interact with the plugin's functionality in unintended ways, which could lead to various security issues depending on the specific actions performed by that AJAX handler. The lack of any taint analysis results, while not inherently negative, suggests that complex data flows involving user input were not deeply scrutinized or are minimal. Overall, while the plugin benefits from solid core development practices, the unprotected AJAX endpoint is a clear vulnerability that needs immediate attention.
Key Concerns
- Unprotected AJAX handler
Comment Mention Security Vulnerabilities
Comment Mention Code Analysis
SQL Query Safety
Output Escaping
Comment Mention Attack Surface
AJAX Handlers 1
WordPress Hooks 19
Maintenance & Trust
Comment Mention Maintenance & Trust
Maintenance Signals
Community Trust
Comment Mention Alternatives
WP Notification Bell
wp-notification-bell
On-site bell notifications. Display notifications custom or triggered (new posts/cpts, WooCommerce order updates, new comment replies, bbPress...)
CIO Custom Fields Importer
custom-fields-csv-xml-importer
Simple, easy, fast and flexible, this add-on to WP All Import processes large data sets from any XML or CSV files to any contents.
Post Comments as bbPress Topics
bbpress-post-topics
Replace the comments on your WordPress blog posts with topics from an integrated bbPress install
CleanTalk bbPress spam scanner
cleantalk-bbpress-spam-scanner
Check existing bbPress topics for spam and move to trash all found spam.
DemoPress: Demo Content Generator
demopress
Generate demo content for newly created websites used during the website development and testing, before real content is created and added.
Comment Mention Developer Profile
12 plugins · 250 total installs
How We Detect Comment Mention
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/comment-mention/app/assets/css/comment-mention.css/wp-content/plugins/comment-mention/app/assets/js/comment-mention.js/wp-content/plugins/comment-mention/app/assets/js/comment-mention.jscomment-mention/app/assets/css/comment-mention.css?ver=comment-mention/app/assets/js/comment-mention.js?ver=HTML / DOM Fingerprints
comment-mention-wrapperdata-user-iddata-user-logindata-comment-idcommentMentionAjaxUrlcommentMentionParams/wp-json/comment-mention/v1/users