
Comment Moderation Highlighter Security & Risk Analysis
wordpress.org/plugins/comment-moderation-highlighterThis plugin will highlight keywords you specify on the admin moderation page, making it easier to spot manual spam and/or troll comments.
Is Comment Moderation Highlighter Safe to Use in 2026?
Generally Safe
Score 100/100Comment Moderation Highlighter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'comment-moderation-highlighter' v0.2 exhibits a generally good security posture, with no known vulnerabilities or common attack vectors identified in its history. The static analysis also shows no dangerous functions, raw SQL queries, or external HTTP requests. However, there are areas of concern. The lack of output escaping on all identified output points is a significant weakness, potentially leading to cross-site scripting (XSS) vulnerabilities if the outputs are user-controllable. Additionally, the presence of one unsanitized path in the taint analysis, even without critical or high severity, warrants attention as it could be a precursor to more severe issues. While the plugin boasts a minimal attack surface, the absence of nonce checks on AJAX handlers (though none exist in this version) and potential for unescaped output indicate a need for more robust security practices.
Key Concerns
- All outputs are unescaped
- Unsanitized path in taint analysis
Comment Moderation Highlighter Security Vulnerabilities
Comment Moderation Highlighter Code Analysis
Output Escaping
Data Flow Analysis
Comment Moderation Highlighter Attack Surface
WordPress Hooks 7
Maintenance & Trust
Comment Moderation Highlighter Maintenance & Trust
Maintenance Signals
Community Trust
Comment Moderation Highlighter Alternatives
Do Not Allow Comments Everywhere
do-not-allow-comments-everywhere
A lightweight plugin that globally disables comments and pings across all WordPress content - past and future.
One Click Close Comments
one-click-close-comments
Conveniently close or open comments for a post or page with one click from the admin listing of posts.
AnyComment
anycomment
AnyComment is blazing-fast commenting plugin based on React for WordPress.
Relative URL
relative-url
Relative URL applies wp_make_link_relative function to links to convert them to relative URLs.
Comment Edit Core – Simple Comment Editing
simple-comment-editing
Allow your users to edit their comments for a period of time. Adjust the comment timer and save some admin headaches.
Comment Moderation Highlighter Developer Profile
2 plugins · 810 total installs
How We Detect Comment Moderation Highlighter
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/comment-moderation-highlighter/comment-moderation-highlighter.cssHTML / DOM Fingerprints
cmh