
Social comments by WpDevArt Security & Risk Analysis
wordpress.org/plugins/comments-from-facebookThis plugin will help you display Facebook Comments on your website. You can use it on your pages/posts.
Is Social comments by WpDevArt Safe to Use in 2026?
Generally Safe
Score 100/100Social comments by WpDevArt has a strong security track record. Known vulnerabilities have been patched promptly.
The 'comments-from-facebook' plugin version 2.6.9 exhibits a generally good security posture based on static analysis. The absence of dangerous functions, file operations, and external HTTP requests, combined with the consistent use of prepared statements for SQL queries and a high percentage of properly escaped output, are all positive indicators. The presence of nonce and capability checks on its entry points further strengthens its defenses, suggesting that the developers have implemented basic security best practices.
However, the vulnerability history introduces a notable concern. The plugin has a recorded CVE in its past, specifically a medium severity Cross-site Scripting (XSS) vulnerability. While this vulnerability is listed as unpatched, the fact that it's the only recorded issue and occurred in 2022 might suggest it was addressed in subsequent updates or is no longer present. The lack of critical or high severity vulnerabilities in its history is a positive sign, but the past XSS issue warrants careful consideration, especially if the plugin hasn't been updated recently or if the vulnerability was not fully remediated.
In conclusion, while the static analysis points towards a robust implementation with good coding practices, the historical vulnerability is a lingering concern. The plugin's relatively small attack surface and protected entry points are strengths. The key weakness lies in the past XSS vulnerability, which, despite being medium severity and potentially resolved, highlights the importance of continuous security vigilance and keeping plugins updated.
Key Concerns
- Past medium severity XSS vulnerability
Social comments by WpDevArt Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Social comments by WpDevArt <= 2.4.9 - Admin+ Stored Cross-Site Scripting
Social comments by WpDevArt Code Analysis
Output Escaping
Data Flow Analysis
Social comments by WpDevArt Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 8
Maintenance & Trust
Social comments by WpDevArt Maintenance & Trust
Maintenance Signals
Community Trust
Social comments by WpDevArt Alternatives
Fancy Comments WordPress
fancy-facebook-comments
Integrate Facebook Comments with your WordPress website easiest possible way
Social Share, Social Login and Social Comments Plugin – Super Socializer
super-socializer
The unique Social Plugin to let you integrate Social Login, Social Share, Social Comments and Social Media follow at your website
Lazy Social Comments
lazy-facebook-comments
Use Facebook Comments with lazy loading feature. Load FB comments after button click or scroll down.
Social Comments by Heateor
heateor-social-comments
Integrate Facebook Comments, Vkontakte Comments and/or Disqus Comments along with default comment form at your website
Comments Switcher
comments-switcher
Allows users to comment on your blog using the facebook credentials or the default wordpress guest credentials.
Social comments by WpDevArt Developer Profile
45 plugins · 52K total installs
How We Detect Social comments by WpDevArt
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/comments-from-facebook/includes/javascript/admin-wpdevart-comment.js/wp-content/plugins/comments-from-facebook/includes/style/admin-style.css/wp-content/plugins/comments-from-facebook/includes/javascript/admin-wpdevart-comment.jscomments-from-facebook/includes/javascript/admin-wpdevart-comment.js?ver=comments-from-facebook/includes/style/admin-style.css?ver=HTML / DOM Fingerprints
<!-- Add field that we can check later. --><!-- Use get_post_meta() to retrieve the existing value --><!-- From database, use the value for the form. -->name="wpdevart_facebook_meta_box_nonce"id="wpdevart_disable_field"name="wpdevart_disable_field"wpdevart_comment_support_urlwpdevart_comment_plugin_url