
Comments Moderation Info Security & Risk Analysis
wordpress.org/plugins/comment-moderation-infoDisplay comments moderation infos such as last modified date, author of the edition. These informations are displayed in both the back-end and the fro …
Is Comments Moderation Info Safe to Use in 2026?
Generally Safe
Score 100/100Comments Moderation Info has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "comment-moderation-info" plugin, in version 0.1, presents a seemingly strong security posture based on the static analysis. It reports zero AJAX handlers, REST API routes, shortcodes, or cron events, which significantly limits its attack surface. Furthermore, the code signals indicate a clean codebase with no dangerous functions, all SQL queries using prepared statements, and all output properly escaped. There are also no file operations, external HTTP requests, or bundled libraries to consider, and crucially, no known vulnerabilities recorded in its history.
However, the complete absence of nonce checks and capability checks is a significant concern. While the current attack surface might be zero, this lack of basic security measures means that if any new functionality were to be added, especially involving user input or actions, it would inherently be insecure without these fundamental checks in place. The taint analysis showing zero flows is positive, but this is likely due to the limited attack surface. The absence of any vulnerabilities to date is a positive indicator, but it is important to remember that this is a very early version of the plugin, and a lack of history does not guarantee future security.
In conclusion, version 0.1 of "comment-moderation-info" demonstrates good practices in its current limited scope regarding SQL and output escaping. However, the complete omission of nonce and capability checks represents a critical weakness that could easily lead to vulnerabilities if the plugin evolves or if functionality is added without addressing these fundamental security requirements. Its current lack of vulnerabilities is a positive but potentially misleading indicator given its nascent stage.
Key Concerns
- Missing nonce checks
- Missing capability checks
Comments Moderation Info Security Vulnerabilities
Comments Moderation Info Code Analysis
Output Escaping
Comments Moderation Info Attack Surface
WordPress Hooks 5
Maintenance & Trust
Comments Moderation Info Maintenance & Trust
Maintenance Signals
Community Trust
Comments Moderation Info Alternatives
Admin Commenters Comments Count
admin-commenters-comments-count
Displays a count of each commenter's total number of comments (linked to those comments) next to their name on any admin page.
Comment Count Admin (by URL)
comment-count-admin
Displays a count of each comment authors total number of comments next to their name on the admin pages.
Export Comment Author Emails – Build email list
export-comment-author-emails
Export email address list from existing comments on your website. Export comment authors' name, email address and website url as CSV or Text file …
Akismet Anti-spam: Spam Protection
akismet
The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam solution for WordPress and WooCommerce.
Disable Comments – Remove Comments & Stop Spam [Multi-Site Support]
disable-comments
Allows administrators to globally disable comments on their site. Comments can be disabled according to post type. Multisite friendly.
Comments Moderation Info Developer Profile
24 plugins · 64K total installs
How We Detect Comments Moderation Info
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
cmda-last-modified