
Comment Meta Display Security & Risk Analysis
wordpress.org/plugins/comment-meta-displayView comment meta beneath the comment on the admin edit screen.
Is Comment Meta Display Safe to Use in 2026?
Generally Safe
Score 85/100Comment Meta Display has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "comment-meta-display" v1.1 plugin exhibits a strong security posture based on the provided static analysis. The absence of any identified attack surface points, dangerous functions, or taint flows indicates diligent coding practices and a focus on security. The use of prepared statements for its single SQL query is a significant positive, mitigating the risk of SQL injection. However, the low percentage of properly escaped output (33%) is a notable concern. This suggests that some user-provided data might be displayed without adequate sanitization, potentially leading to cross-site scripting (XSS) vulnerabilities if malicious content is injected and rendered directly. The plugin also has no recorded vulnerability history, which is excellent, but it's important to note that a clean history doesn't guarantee future immunity, especially when combined with output escaping issues. Overall, while the plugin is built on a secure foundation with no apparent critical flaws, the unescaped output presents a tangible risk that should be addressed to further harden its security.
Key Concerns
- Only 33% of output properly escaped
Comment Meta Display Security Vulnerabilities
Comment Meta Display Release Timeline
Comment Meta Display Code Analysis
SQL Query Safety
Output Escaping
Comment Meta Display Attack Surface
WordPress Hooks 1
Maintenance & Trust
Comment Meta Display Maintenance & Trust
Maintenance Signals
Community Trust
Comment Meta Display Alternatives
JSM Show Comment Metadata
jsm-show-comment-meta
Show comment metadata in a metabox when editing comments - a great tool for debugging issues with comment metadata.
MB Comment Meta
mb-comment-meta
Add custom fields for comments. Support 40+ field types with easy config.
Advanced Custom Fields (ACF®)
advanced-custom-fields
ACF helps customize WordPress with powerful, professional and intuitive fields. Proudly powering over 2 million sites, WordPress developers love ACF.
Meta Box
meta-box
Meta Box plugin is a powerful, professional developer toolkit to create custom meta boxes and custom fields for your custom post types in WordPress.
Advanced Custom Fields: Extended
acf-extended
All-in-one enhancement suite that improves WordPress & Advanced Custom Fields.
Comment Meta Display Developer Profile
2 plugins · 120 total installs
How We Detect Comment Meta Display
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/comment-meta-display/comment-meta.phpHTML / DOM Fingerprints
cme-details