
Comment Move Security & Risk Analysis
wordpress.org/plugins/comment-moveAdds the ability to move comments between posts / pages to the comment edit page.
Is Comment Move Safe to Use in 2026?
Generally Safe
Score 85/100Comment Move has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "comment-move" v1.0 plugin presents a concerning security posture despite having no known vulnerabilities in its history. The static analysis reveals significant weaknesses. All SQL queries are executed without prepared statements, indicating a high risk of SQL injection vulnerabilities. Furthermore, none of the identified output operations are properly escaped, creating a significant risk of Cross-Site Scripting (XSS) attacks. The taint analysis also flagged two flows with unsanitized paths as high severity, directly pointing to potential injection vulnerabilities that could be exploited. The absence of any capability checks or nonce checks on entry points, while there are zero identified entry points, still highlights a lack of robust security controls that could become problematic if the plugin's functionality were to expand or change in future versions. The lack of vulnerability history, while seemingly positive, does not negate the evident security flaws within the current codebase.
Key Concerns
- All SQL queries unescaped
- High severity unsanitized taint flows
- No output escaping
- No capability checks
- No nonce checks
Comment Move Security Vulnerabilities
Comment Move Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Comment Move Attack Surface
WordPress Hooks 3
Maintenance & Trust
Comment Move Maintenance & Trust
Maintenance Signals
Community Trust
Comment Move Alternatives
Disable Comments – Remove Comments & Stop Spam [Multi-Site Support]
disable-comments
Allows administrators to globally disable comments on their site. Comments can be disabled according to post type. Multisite friendly.
WP Comment Cleaner – Delete All Comments, Disable Comments, Bulk Delete & Remove Comments
delete-all-comments-of-website
Delete comments, disable comments, and remove comments in one click. Bulk delete spam and all comments to optimize your WordPress database easily.
Remove Yoast SEO Comments
remove-yoast-seo-comments
Removes the Yoast SEO advertisement HTML comments from your front-end source code.
Disable Comments
wpsimpletools-disable-comments
Completely disables comments functionality from backend and frontend. Just install it, nothing to configure!
Disable Comments & Delete All Comments
comments-plus
Disable comments globally on all posts or certain post types. Delete all comments at once, by post type or comment status. Manage links in comments.
Comment Move Developer Profile
2 plugins · 80 total installs
How We Detect Comment Move
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/comment-move/comment_move.phpHTML / DOM Fingerprints
id="commentmovediv"id="comment_move_new_pid"id="cm_selPost_click"id="cm_selPost"cm_selectPost