
Comment Recovery Security & Risk Analysis
wordpress.org/plugins/comment-recoveryRecovers lost comments by copy/pasteing your new comment notification emails
Is Comment Recovery Safe to Use in 2026?
Generally Safe
Score 85/100Comment Recovery has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "comment-recovery" plugin v1.1 presents a mixed security posture. On the positive side, the plugin has no known vulnerabilities (CVEs) and demonstrates good practices by exclusively using prepared statements for its SQL queries and not making external HTTP requests or performing file operations. It also boasts a small attack surface with no apparent AJAX handlers, REST API routes, shortcodes, or cron events exposed. However, significant concerns arise from the static analysis. A critical weakness is the complete lack of output escaping for all 12 identified output points. This could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is displayed without proper sanitization. Furthermore, the taint analysis reveals two flows with unsanitized paths, indicating potential vulnerabilities where data could be improperly handled or lead to unexpected behavior, although they are not categorized as critical or high severity by the provided data. The absence of nonce and capability checks, while not directly tied to an exposed attack surface in this version, leaves the door open for future vulnerabilities if new entry points are introduced without corresponding security measures. The lack of any recorded vulnerability history is a positive indicator, suggesting diligent maintenance or a lack of prior exploitation, but it does not negate the current code-level risks.
In conclusion, while "comment-recovery" v1.1 has strengths in its SQL handling and limited attack surface, the pervasive lack of output escaping and the presence of unsanitized taint flows are significant security concerns that require immediate attention. The absence of checks for nonces and capabilities, while not immediately exploitable, represents a potential future risk.
Key Concerns
- 0% output escaping
- 2 flows with unsanitized paths
- 0 nonce checks
- 0 capability checks
Comment Recovery Security Vulnerabilities
Comment Recovery Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Comment Recovery Attack Surface
WordPress Hooks 2
Maintenance & Trust
Comment Recovery Maintenance & Trust
Maintenance Signals
Community Trust
Comment Recovery Alternatives
Comment Admin Notifier
comment-admin-notifier
With this plugin, admin users get an email alert every time a new comment is posted on ANY post in the site.
Digest Notifications
digest
Get a daily, weekly, or monthly digest of what's happening on your site instead of receiving a single email each time.
Notify All Admins on Comment
notify-all-admins-on-comment
A simple plugin that ensures all site administrators are notified of new comments, not just the main site admin.
Change Admin Email
change-admin-email-setting-without-outbound-email
This plugin allows an administrator to change the "site admin email", without sending a confirmation email from the server.
Disqus Comment System
disqus-comment-system
Disqus is the web's most popular comment system. Use Disqus to increase engagement, retain readers, and grow your audience.
Comment Recovery Developer Profile
9 plugins · 180 total installs
How We Detect Comment Recovery
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
wrapname="dprx_comment_rec_save"id="dprx_comment_rec_save"name="dprx_comment_rec"id="dprx_comment_rec"name="dprx_comment_rec_postid"id="dprx_comment_rec_postid"+12 more