Social comments by WpDevArt Security & Risk Analysis

wordpress.org/plugins/comments-from-facebook

This plugin will help you display Facebook Comments on your website. You can use it on your pages/posts.

9K active installs v2.6.9 PHP + WP 2.9+ Updated Feb 2, 2026
commentsfacebookfacebook-commentssocial-commentswordpress-comments
100
A · Safe
CVEs total1
Unpatched0
Last CVEApr 9, 2022
Safety Verdict

Is Social comments by WpDevArt Safe to Use in 2026?

Generally Safe

Score 100/100

Social comments by WpDevArt has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Apr 9, 2022Updated 2mo ago
Risk Assessment

The 'comments-from-facebook' plugin version 2.6.9 exhibits a generally good security posture based on static analysis. The absence of dangerous functions, file operations, and external HTTP requests, combined with the consistent use of prepared statements for SQL queries and a high percentage of properly escaped output, are all positive indicators. The presence of nonce and capability checks on its entry points further strengthens its defenses, suggesting that the developers have implemented basic security best practices.

However, the vulnerability history introduces a notable concern. The plugin has a recorded CVE in its past, specifically a medium severity Cross-site Scripting (XSS) vulnerability. While this vulnerability is listed as unpatched, the fact that it's the only recorded issue and occurred in 2022 might suggest it was addressed in subsequent updates or is no longer present. The lack of critical or high severity vulnerabilities in its history is a positive sign, but the past XSS issue warrants careful consideration, especially if the plugin hasn't been updated recently or if the vulnerability was not fully remediated.

In conclusion, while the static analysis points towards a robust implementation with good coding practices, the historical vulnerability is a lingering concern. The plugin's relatively small attack surface and protected entry points are strengths. The key weakness lies in the past XSS vulnerability, which, despite being medium severity and potentially resolved, highlights the importance of continuous security vigilance and keeping plugins updated.

Key Concerns

  • Past medium severity XSS vulnerability
Vulnerabilities
1

Social comments by WpDevArt Security Vulnerabilities

CVEs by Year

1 CVE in 2022
2022
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2022-0876medium · 5.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Social comments by WpDevArt <= 2.4.9 - Admin+ Stored Cross-Site Scripting

Apr 9, 2022 Patched in 2.5.0 (654d)
Code Analysis
Analyzed Mar 16, 2026

Social comments by WpDevArt Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
79 escaped
Nonce Checks
2
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

94% escaped84 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
save_in_databese (includes\admin_menu.php:148)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Social comments by WpDevArt Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 1

authwp_ajax_wpdevart_comment_page_saveincludes\admin_menu.php:22

Shortcodes 1

[wpdevart_facebook_comment] includes\front_end.php:29
WordPress Hooks 8
actionadmin_menufacebook-comment.php:45
actioninitfacebook-comment.php:73
actionadmin_headfacebook-comment.php:74
actionadd_meta_boxesincludes\admin_menu.php:23
actionsave_postincludes\admin_menu.php:24
actionwp_headincludes\front_end.php:26
actionwp_footerincludes\front_end.php:27
actionthe_contentincludes\front_end.php:30
Maintenance & Trust

Social comments by WpDevArt Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 2, 2026
PHP min version
Downloads1.3M

Community Trust

Rating86/100
Number of ratings42
Active installs9K
Developer Profile

Social comments by WpDevArt Developer Profile

wpdevart

45 plugins · 52K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
581 days
View full developer profile
Detection Fingerprints

How We Detect Social comments by WpDevArt

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/comments-from-facebook/includes/javascript/admin-wpdevart-comment.js/wp-content/plugins/comments-from-facebook/includes/style/admin-style.css
Script Paths
/wp-content/plugins/comments-from-facebook/includes/javascript/admin-wpdevart-comment.js
Version Parameters
comments-from-facebook/includes/javascript/admin-wpdevart-comment.js?ver=comments-from-facebook/includes/style/admin-style.css?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- Add field that we can check later. --><!-- Use get_post_meta() to retrieve the existing value --><!-- From database, use the value for the form. -->
Data Attributes
name="wpdevart_facebook_meta_box_nonce"id="wpdevart_disable_field"name="wpdevart_disable_field"
JS Globals
wpdevart_comment_support_urlwpdevart_comment_plugin_url
FAQ

Frequently Asked Questions about Social comments by WpDevArt