
Comments Not Replied To Security & Risk Analysis
wordpress.org/plugins/comments-not-replied-toEasily see which comments have not received a reply yet.
Is Comments Not Replied To Safe to Use in 2026?
Generally Safe
Score 92/100Comments Not Replied To has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "comments-not-replied-to" plugin v1.6.2 demonstrates a generally strong security posture based on the provided static analysis. The absence of any identified dangerous functions, unsanitized taint flows, raw SQL queries, or unescaped output is highly commendable. Furthermore, the plugin avoids common attack vectors like direct file operations and external HTTP requests, and it has no recorded vulnerability history, indicating a history of secure development and maintenance.
However, the analysis does highlight a potential area of concern: the complete lack of nonce checks across all entry points. While the static analysis shows no unprotected AJAX handlers or REST API routes, the absence of nonce verification means that even if capability checks are in place, there's a theoretical possibility of Cross-Site Request Forgery (CSRF) attacks if an attacker can trick a logged-in user into performing an action without their knowledge. This is a minor weakness given the overall strong security, but it's a notable omission in robust security practices.
In conclusion, this plugin appears to be very securely coded with excellent adherence to fundamental security principles. The lack of any identified vulnerabilities or exploit vectors is a significant strength. The only discernible weakness is the absence of nonce checks, which, while not currently exploited, represents a missed opportunity for an additional layer of protection against CSRF. The plugin's history of zero vulnerabilities further reinforces its trustworthiness.
Key Concerns
- Missing nonce checks on entry points
Comments Not Replied To Security Vulnerabilities
Comments Not Replied To Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Comments Not Replied To Attack Surface
WordPress Hooks 17
Maintenance & Trust
Comments Not Replied To Maintenance & Trust
Maintenance Signals
Community Trust
Comments Not Replied To Alternatives
Akismet Anti-spam: Spam Protection
akismet
The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam solution for WordPress and WooCommerce.
Disable Comments – Remove Comments & Stop Spam [Multi-Site Support]
disable-comments
Allows administrators to globally disable comments on their site. Comments can be disabled according to post type. Multisite friendly.
Antispam Bee
antispam-bee
Sophisticated antispam plugin for effective daily comment and trackback spam-fighting. Built with data protection and privacy in mind.
Spam protection, Honeypot, Anti-Spam by CleanTalk
cleantalk-spam-protect
Blocks spam comments, fake users, contact form spam and more. No impact on SEO. Privacy focused. CAPTCHA free, premium Antispam plugin.
Captcha Code
captcha-code-authentication
GDPR compatible captcha anti-spam protection for login form, comments form, registration form & lost password form. Eliminate spam with captcha.
Comments Not Replied To Developer Profile
2 plugins · 270 total installs
How We Detect Comments Not Replied To
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/comments-not-replied-to/css/cnrt-admin.css/wp-content/plugins/comments-not-replied-to/js/cnrt-admin.js/wp-content/plugins/comments-not-replied-to/js/cnrt-global.js/wp-content/plugins/comments-not-replied-to/js/cnrt-admin.js/wp-content/plugins/comments-not-replied-to/js/cnrt-global.jscomments-not-replied-to/css/cnrt-admin.css?ver=comments-not-replied-to/js/cnrt-admin.js?ver=comments-not-replied-to/js/cnrt-global.js?ver=HTML / DOM Fingerprints
cnrt-admin-table<!-- this add a link under the plugin name, must be in the main plugin file --><!--this define must triggered after the active theme's functions.php file is loaded --><!-- Exit if accessed directly --><!-- This is required to use wp_add_inline_script without dependency -->+51 moredata-commentiddata-postidcnrt_global_data