
Comment Pub Security & Risk Analysis
wordpress.org/plugins/comment-pubCreate a guestbook or local avatars or unique comments. The images be will resized on upload and originals deleted.
Is Comment Pub Safe to Use in 2026?
Generally Safe
Score 85/100Comment Pub has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "comment-pub" v1.0.0 plugin demonstrates a generally good security posture with several strengths. Notably, all identified SQL queries utilize prepared statements, which is a crucial defense against SQL injection vulnerabilities. The absence of known CVEs and a clean vulnerability history further suggest a commitment to security or a lack of past exploitation. However, the static analysis reveals some areas for concern. A significant portion of output (67%) is not properly escaped, presenting a risk of Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the taint analysis indicates two flows with unsanitized paths, one of which is flagged as high severity. While the total attack surface is zero, these unsanitized flows could still be exploited if an attacker can control the input to these paths. The presence of file operations and a limited number of nonce and capability checks also warrants attention, as these can sometimes be entry points for further attacks if not implemented with utmost care. In conclusion, while the plugin avoids common pitfalls like raw SQL and a public attack surface, the unescaped output and the high-severity taint flow represent significant risks that need to be addressed.
Key Concerns
- High severity taint flow
- Unsanitized path flows
- Low output escaping percentage
Comment Pub Security Vulnerabilities
Comment Pub Release Timeline
Comment Pub Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Comment Pub Attack Surface
WordPress Hooks 15
Maintenance & Trust
Comment Pub Maintenance & Trust
Maintenance Signals
Community Trust
Comment Pub Alternatives
Reverse Order Comments
reverse-order-comments
Allows to display the comments in reverse order. Latest comment first, oldest last.
Simple Guestbook
simple-guestbook
A simple guestbook plugin based on WordPress page comments.
LIBRO DE VISITAS – GUESTBOOK
libro-de-visitas-guestbook
For live example click here!!!
WP CommentWidgetizer
wp-commentwidgetizer
WP CommentWidgetizer is a simple widget that takes one of the approved comments made on any page or post of your site and displays it in the sidebar.
Gwolle Guestbook
gwolle-gb
Gwolle Guestbook is the WordPress guestbook you've just been looking for. Beautiful and easy.
Comment Pub Developer Profile
1 plugin · 20 total installs
How We Detect Comment Pub
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/comment-pub/css/plugin.css/wp-content/plugins/comment-pub/css/admin.css/wp-content/plugins/comment-pub/js/plugin.min.jsHTML / DOM Fingerprints
nocomments<!-- /#comment-pub-notice -->