
Display Comments Statistics Security & Risk Analysis
wordpress.org/plugins/comments-statisticsThis plugin shows the total number of articles and comments as well as statistics about which platforms and browsers were used in comment writing.
Is Display Comments Statistics Safe to Use in 2026?
Generally Safe
Score 100/100Display Comments Statistics has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "comments-statistics" plugin v1.6.0 presents a concerning security posture due to significant code quality issues, despite the absence of known vulnerabilities and a seemingly small attack surface. The static analysis reveals a complete lack of output escaping and the use of raw SQL queries without prepared statements. This means that any data processed or displayed by the plugin is susceptible to injection attacks, including cross-site scripting (XSS) and SQL injection, as the input is not properly sanitized or validated before being outputted or used in database queries. The absence of capability checks and nonce checks also raises alarms, as it implies that sensitive operations, if present, might be accessible to unauthenticated or low-privileged users.
The lack of any recorded vulnerabilities in its history is a positive sign, but it does not negate the severe coding flaws identified. It's possible that the plugin's functionality is limited, or that its usage is confined to environments where these vulnerabilities haven't been exploited. However, relying solely on this historical pattern would be imprudent given the identified code quality issues. The plugin exhibits a concerning disregard for fundamental security practices, making it a high-risk component, especially if it handles any user-provided data or interacts with sensitive WordPress functionalities.
Key Concerns
- SQL queries not using prepared statements
- Output not properly escaped
- No capability checks implemented
- No nonce checks implemented
Display Comments Statistics Security Vulnerabilities
Display Comments Statistics Code Analysis
SQL Query Safety
Output Escaping
Display Comments Statistics Attack Surface
WordPress Hooks 1
Maintenance & Trust
Display Comments Statistics Maintenance & Trust
Maintenance Signals
Community Trust
Display Comments Statistics Alternatives
Most Popular Posts
most-popular-posts
This is a very simple widget that displays a link to the top commented posts on your blog.
Top Commentators Widget
top-commentators-widget
Adds a sidebar widget to show the top commentators in your WP site. Demo: http://demo.webgrrrl.net
Disqus Recent Comments Widget
disqus-recent-comments-widget
Disqus has dropped support for their recent comments widget. This plugin creates a configurable widget that will display your latest Disqus comments.
EMI Calculator
os-emi-calculator
Use EMI calculator as shortcode in post content or widget area without editing your theme files
FF Tab Widget
ff-tab-widget
Display popular posts, recent posts, recent commets, and tags in an animated tabs in a single widget.
Display Comments Statistics Developer Profile
1 plugin · 10 total installs
How We Detect Display Comments Statistics
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/comments-statistics/windows.png/wp-content/plugins/comments-statistics/linux.png/wp-content/plugins/comments-statistics/macos.png/wp-content/plugins/comments-statistics/wp.png/wp-content/plugins/comments-statistics/sun.png/wp-content/plugins/comments-statistics/firefox.png/wp-content/plugins/comments-statistics/ie.png/wp-content/plugins/comments-statistics/safari.png+9 moreHTML / DOM Fingerprints
<h2>Writing</h2><h2>Comments</h2>