Recent Comments Widget Plus Security & Risk Analysis

wordpress.org/plugins/comments-widget-plus

Provides custom recent comments widget with extra features such as display avatar, comment excerpt and much more!

2K active installs v1.3 PHP 7.2+ WP 5.8+ Updated Oct 26, 2022
avatarexcerptrecent-commentsrecent-comments-widgetwidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Recent Comments Widget Plus Safe to Use in 2026?

Generally Safe

Score 85/100

Recent Comments Widget Plus has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "comments-widget-plus" v1.3 plugin exhibits a strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the plugin's attack surface. Furthermore, the code analysis reveals excellent practices regarding SQL queries, which are all prepared, and a high percentage of properly escaped output, minimizing the risk of cross-site scripting (XSS) vulnerabilities. The lack of file operations and external HTTP requests also contributes to a more secure design.

Concerns are minimal, primarily stemming from the complete lack of explicit nonce and capability checks on the identified entry points. While there are currently no entry points to protect, this suggests a potential oversight in the plugin's design if functionality were to be added in the future without implementing these crucial security mechanisms. The vulnerability history is clean, with no recorded CVEs, which is a positive indicator of the plugin's current security. Overall, the plugin appears to be well-developed from a security perspective, with a very small attack surface and good coding practices in place for the existing code.

Key Concerns

  • No nonce checks found
  • No capability checks found
Vulnerabilities
None known

Recent Comments Widget Plus Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Recent Comments Widget Plus Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
100 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

95% escaped105 total outputs
Attack Surface

Recent Comments Widget Plus Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actionplugins_loadedcomments-widget-plus.php:36
actionwidgets_initcomments-widget-plus.php:45
actionadmin_enqueue_scriptscomments-widget-plus.php:53
actioncustomize_controls_enqueue_scriptscomments-widget-plus.php:54
actionenqueue_block_editor_assetscomments-widget-plus.php:55
actionwp_enqueue_scriptscomments-widget-plus.php:63
actionwp_headincludes\class-comments-widget-plus-widget.php:46
actioncomment_postincludes\class-comments-widget-plus-widget.php:50
actionedit_commentincludes\class-comments-widget-plus-widget.php:51
actiontransition_comment_statusincludes\class-comments-widget-plus-widget.php:52
Maintenance & Trust

Recent Comments Widget Plus Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedOct 26, 2022
PHP min version7.2
Downloads49K

Community Trust

Rating94/100
Number of ratings20
Active installs2K
Developer Profile

Recent Comments Widget Plus Developer Profile

Ga Satrya

6 plugins · 41K total installs

71
trust score
Avg Security Score
88/100
Avg Patch Time
524 days
View full developer profile
Detection Fingerprints

How We Detect Recent Comments Widget Plus

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/comments-widget-plus/assets/css/cwp-admin.css/wp-content/plugins/comments-widget-plus/assets/css/cwp.css
Version Parameters
comments-widget-plus/assets/css/cwp-admin.css?ver=comments-widget-plus/assets/css/cwp.css?ver=

HTML / DOM Fingerprints

CSS Classes
widget_recent_commentscomments_widget_pluscwp-licwp-avatarcwp-avatar.roundedcwp-avatar.squarecwp-comment-excerptcwp-options+2 more
Data Attributes
data-widget-id
FAQ

Frequently Asked Questions about Recent Comments Widget Plus