
Comments On Security & Risk Analysis
wordpress.org/plugins/comments-onComments On adds a column to the "All Posts"/"All Pages" view in the Admin dashboard showing the status of comments.
Is Comments On Safe to Use in 2026?
Generally Safe
Score 100/100Comments On has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "comments-on" v0.1 plugin exhibits a generally good security posture based on the static analysis. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the plugin's attack surface. Furthermore, the code does not utilize dangerous functions, conduct file operations, or make external HTTP requests. All detected SQL queries are properly prepared, which is a strong indicator of secure database interaction.
However, a critical concern arises from the output escaping. With one total output identified and 0% properly escaped, this presents a significant risk of Cross-Site Scripting (XSS) vulnerabilities. Any data displayed to users that originates from or passes through this plugin could potentially be injected with malicious scripts. The lack of nonce and capability checks also means that any potential entry points, though currently none are identified, would not have these crucial security measures in place.
The vulnerability history being entirely clear is a positive sign, suggesting the developer may be diligent in security. However, given the unescaped output and missing checks, this can also be interpreted as a lucky absence of exploitable issues rather than a proactive security stance. The plugin needs immediate attention to address the output escaping and implement appropriate checks for any future development.
Key Concerns
- Output not properly escaped
- Missing nonce checks
- Missing capability checks
Comments On Security Vulnerabilities
Comments On Code Analysis
Output Escaping
Comments On Attack Surface
WordPress Hooks 5
Maintenance & Trust
Comments On Maintenance & Trust
Maintenance Signals
Community Trust
Comments On Alternatives
One Click Close Comments
one-click-close-comments
Conveniently close or open comments for a post or page with one click from the admin listing of posts.
Relative URL
relative-url
Relative URL applies wp_make_link_relative function to links to convert them to relative URLs.
Quotmarks Replacer
quotmarks-replacer
Quotmarks Replacer disables wptexturize function that keeps all quotation marks and suspension points in half-width form.
Nofollow Case by Case
nofollow-case-by-case
"Dofollow" but Nofollow Case by Case allows you to selectively apply nofollow to your comments as well.
PowerUp – Admin Tools (Login/Logout Redirects, Scripts & Comments Control)
powerup
Simplify site management with Login/Logout Redirect, Hide Admin Bar, Disable Comments, Header Footer Scripts and Remove Footer Credit.
Comments On Developer Profile
3 plugins · 20K total installs
How We Detect Comments On
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
<th>Comments On</th>