
Comments Analytics – Dashboard & Commenter Profiles Security & Risk Analysis
wordpress.org/plugins/commentswpAnalyze WordPress comments in one dashboard. Track comment stats, identify top commenters, and gain engagement insights.
Is Comments Analytics – Dashboard & Commenter Profiles Safe to Use in 2026?
Generally Safe
Score 100/100Comments Analytics – Dashboard & Commenter Profiles has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "commentswp" plugin v1.3.1 demonstrates a strong security posture based on the provided static analysis. All identified entry points (2 AJAX handlers) appear to have authentication checks, and there are no exposed REST API routes or shortcodes. The plugin effectively utilizes prepared statements for all its SQL queries, and all output is properly escaped, indicating good practices for preventing common web vulnerabilities like SQL injection and XSS. The presence of nonce and capability checks further strengthens its defenses.
However, a concerning finding is the "Flows with unsanitized paths" identified in the taint analysis. While classified as not critical or high severity, any unsanitized path is a potential entry point for path traversal or other file system-related vulnerabilities. The single file operation identified needs careful scrutiny in conjunction with this taint flow. The lack of any recorded vulnerability history is positive, suggesting a history of secure development or effective patching by users.
In conclusion, "commentswp" v1.3.1 exhibits many good security practices. The primary area of concern stems from the identified unsanitized path flow, which, despite its low severity classification in the taint analysis, warrants attention due to its nature. The absence of known CVEs and the robust use of prepared statements and output escaping are significant strengths.
Key Concerns
- Flows with unsanitized paths found
- Single file operation identified
Comments Analytics – Dashboard & Commenter Profiles Security Vulnerabilities
Comments Analytics – Dashboard & Commenter Profiles Release Timeline
Comments Analytics – Dashboard & Commenter Profiles Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Comments Analytics – Dashboard & Commenter Profiles Attack Surface
AJAX Handlers 2
WordPress Hooks 22
Maintenance & Trust
Comments Analytics – Dashboard & Commenter Profiles Maintenance & Trust
Maintenance Signals
Community Trust
Comments Analytics – Dashboard & Commenter Profiles Alternatives
Gossiped Comments
gossiped-comments
Universal commenting system with cross-site profiles, reputation scores, and real-time analytics.
SceneChat – Socially Ignite the Videos on Your Website
scenechat-video-sharing-and-commenting-tool
SceneChat adds an interactive social toolbar to the videos on your site. It helps engage your audience, grow your traffic, and drive conversion.
Simple Toolkit
simple-toolkit
Simple Toolkit is a plugin that provides simple and useful tools for WordPress websites. With this plugin, you can easily disable comments, duplicate …
Akismet Anti-spam: Spam Protection
akismet
The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam solution for WordPress and WooCommerce.
Site Kit by Google – Analytics, Search Console, AdSense, Speed
google-site-kit
Site Kit is a one-stop solution for WordPress users to use everything Google has to offer to make them successful on the web.
Comments Analytics – Dashboard & Commenter Profiles Developer Profile
10 plugins · 3K total installs
How We Detect Comments Analytics – Dashboard & Commenter Profiles
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/commentswp/assets/css/admin.css/wp-content/plugins/commentswp/assets/js/admin.js/wp-content/plugins/commentswp/assets/js/vendor/alpine.js/wp-content/plugins/commentswp/assets/js/admin.js/wp-content/plugins/commentswp/assets/js/vendor/alpine.jscommentswp/assets/css/admin.css?ver=commentswp/assets/js/admin.js?ver=commentswp/assets/js/vendor/alpine.js?ver=HTML / DOM Fingerprints
commentswptitle-logotitle-maintitle-separatortitle-secondarydata-commentswp-admin-urlAlpine