Comments Moderation Info Security & Risk Analysis

wordpress.org/plugins/comment-moderation-info

Display comments moderation infos such as last modified date, author of the edition. These informations are displayed in both the back-end and the fro …

0 active installs v0.1 PHP + WP 4.9+ Updated Nov 27, 2025
comment-authorcomment-datecommentscomments-moderationcomments-revision
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Comments Moderation Info Safe to Use in 2026?

Generally Safe

Score 100/100

Comments Moderation Info has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The "comment-moderation-info" plugin, in version 0.1, presents a seemingly strong security posture based on the static analysis. It reports zero AJAX handlers, REST API routes, shortcodes, or cron events, which significantly limits its attack surface. Furthermore, the code signals indicate a clean codebase with no dangerous functions, all SQL queries using prepared statements, and all output properly escaped. There are also no file operations, external HTTP requests, or bundled libraries to consider, and crucially, no known vulnerabilities recorded in its history.

However, the complete absence of nonce checks and capability checks is a significant concern. While the current attack surface might be zero, this lack of basic security measures means that if any new functionality were to be added, especially involving user input or actions, it would inherently be insecure without these fundamental checks in place. The taint analysis showing zero flows is positive, but this is likely due to the limited attack surface. The absence of any vulnerabilities to date is a positive indicator, but it is important to remember that this is a very early version of the plugin, and a lack of history does not guarantee future security.

In conclusion, version 0.1 of "comment-moderation-info" demonstrates good practices in its current limited scope regarding SQL and output escaping. However, the complete omission of nonce and capability checks represents a critical weakness that could easily lead to vulnerabilities if the plugin evolves or if functionality is added without addressing these fundamental security requirements. Its current lack of vulnerabilities is a positive but potentially misleading indicator given its nascent stage.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Comments Moderation Info Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Comments Moderation Info Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
10 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped10 total outputs
Attack Surface

Comments Moderation Info Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
filtermanage_edit-comments_columnscomment-moderation-info.php:22
actionmanage_comments_custom_columncomment-moderation-info.php:87
actionedit_commentcomment-moderation-info.php:114
filtercomment_textcomment-moderation-info.php:147
filteradmin_initcomment-moderation-info.php:177
Maintenance & Trust

Comments Moderation Info Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedNov 27, 2025
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Comments Moderation Info Developer Profile

Jb Audras

24 plugins · 64K total installs

78
trust score
Avg Security Score
98/100
Avg Patch Time
661 days
View full developer profile
Detection Fingerprints

How We Detect Comments Moderation Info

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
cmda-last-modified
FAQ

Frequently Asked Questions about Comments Moderation Info