
Comments Mover Security & Risk Analysis
wordpress.org/plugins/comments-moverUsing comments mover plugin you can move comments between posts and pages in a simple and easy way.
Is Comments Mover Safe to Use in 2026?
Generally Safe
Score 85/100Comments Mover has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "comments-mover" plugin v1.0 exhibits a seemingly strong security posture based on the provided static analysis. The absence of identified dangerous functions, raw SQL queries, file operations, and external HTTP requests is a positive indicator. Furthermore, the fact that all SQL queries utilize prepared statements and the presence of output escaping for a majority of outputs suggest adherence to good coding practices.
The limited attack surface with no exposed AJAX handlers, REST API routes, shortcodes, or cron events, particularly those lacking authentication checks, is a significant strength. This significantly reduces the potential avenues for external exploitation. The clean vulnerability history with no recorded CVEs further bolsters confidence in the plugin's current security state.
However, the complete absence of nonce checks and capability checks across all identified entry points (even though there are none listed) is a notable concern. If any entry points were to be added in the future without these crucial security mechanisms, it could lead to vulnerabilities. The fact that 25% of outputs are not properly escaped also presents a minor risk of Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is involved in those outputs. Overall, while the current state is very good, the lack of built-in authentication/authorization checks on potential future entry points and minor output escaping issues are areas for improvement.
Key Concerns
- Outputs not properly escaped (25%)
- Missing nonce checks on potential entry points
- Missing capability checks on potential entry points
Comments Mover Security Vulnerabilities
Comments Mover Code Analysis
SQL Query Safety
Output Escaping
Comments Mover Attack Surface
WordPress Hooks 2
Maintenance & Trust
Comments Mover Maintenance & Trust
Maintenance Signals
Community Trust
Comments Mover Alternatives
No Page Comment
no-page-comment
An admin interface to control the default comment and trackback settings on new posts, pages and custom post types.
Remove noreferrer
remove-noreferrer
"Remove noreferrer" automatically removes rel="noreferrer" attribute from links on your website on-the-fly.
No Comments On Pages
no-comments-on-pages
A tiny WordPress plugin which, when activated, disables posting of new comments to all pages and hides existing ones.
Page Comments Off Please
page-comments-off-please
Page Comments Off Please - Unchecks Discussion comment checkboxes by default on pages, posts or both! Plus a simple one-click toggle to turn off comme …
Pagebar2
pagebar
Pagebar adds a nice page bar to your blog posts, multipaged posts and paged comments.
Comments Mover Developer Profile
3 plugins · 300 total installs
How We Detect Comments Mover
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
column1column2column3column4name="move_comment_id