
CommentOff Security & Risk Analysis
wordpress.org/plugins/commentoffEasily disable all comments on your WordPress site: hide the form, block existing comments, and remove comment elements from the admin panel.
Is CommentOff Safe to Use in 2026?
Generally Safe
Score 100/100CommentOff has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "commentoff" v1.0.0 plugin exhibits a strong security posture based on the provided static analysis. It demonstrates excellent adherence to secure coding practices, with no identified dangerous functions, all SQL queries utilizing prepared statements, and 100% of output properly escaped. Furthermore, the absence of file operations, external HTTP requests, and a substantial attack surface through AJAX, REST API, shortcodes, and cron events is highly positive. The lack of any recorded vulnerabilities or CVEs in its history is also a significant strength, suggesting a history of secure development. However, the complete absence of nonce and capability checks across all entry points (even though the entry point count is zero) represents a notable concern. While there are currently no exploitable entry points, if any were to be introduced in future versions, they would be entirely unprotected, leaving the plugin vulnerable to various attacks if functionality is added without proper security measures.
Key Concerns
- No capability checks on entry points
- No nonce checks on entry points
CommentOff Security Vulnerabilities
CommentOff Release Timeline
CommentOff Code Analysis
Output Escaping
CommentOff Attack Surface
WordPress Hooks 14
Maintenance & Trust
CommentOff Maintenance & Trust
Maintenance Signals
Community Trust
CommentOff Alternatives
Turn Off Comments — Hide Comment Box and Stop Spam
turn-off-comments
Remove comments functionality from your website!
Daisy Comments — Disable Comments & Stop Spam
daisy-comments
Disables comment functionality and hides all existing comments from your WordPress website.
Do Not Allow Comments Everywhere
do-not-allow-comments-everywhere
A lightweight plugin that globally disables comments and pings across all WordPress content - past and future.
Commenti – Disable & Remove Comments, Stop Spam [Multi-Site Support]
yakura-commenti
Disable and remove comments site-wide or per post type. Control REST API, feeds, XML-RPC, admin UI, and avatars. Multisite ready
Disable Comments – Remove Comments & Stop Spam [Multi-Site Support]
disable-comments
Allows administrators to globally disable comments on their site. Comments can be disabled according to post type. Multisite friendly.
CommentOff Developer Profile
2 plugins · 0 total installs
How We Detect CommentOff
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/commentoff/assets/admin/css/style.csscommentoff/assets/admin/css/style.css?ver=HTML / DOM Fingerprints
commentoff-headercommentoff-contentcommentoff-tips-blockcommentoff-tips-msgname="commentoff_options[is_admin_hide]"name="commentoff_options[is_front_hide]"name="commentoff_options[is_hide_existed_comments]"