Commentwitter Security & Risk Analysis

wordpress.org/plugins/commentwitter

Gives commenters the option of Tweeting their comment with a link to your post.

10 active installs v2.1 PHP + WP 3.0+ Updated Nov 16, 2010
commentscommentwittertweettwitter
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Commentwitter Safe to Use in 2026?

Generally Safe

Score 85/100

Commentwitter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 15yr ago
Risk Assessment

The "commentwitter" v2.1 plugin exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of identified dangerous functions, the exclusive use of prepared statements for SQL queries, and 100% output escaping indicate good development practices that mitigate common web vulnerabilities. Furthermore, the lack of any recorded CVEs or past vulnerabilities suggests a commitment to security or, at the very least, a history of not being a target for exploit development. The limited attack surface, with no AJAX handlers, REST API routes, shortcodes, or cron events, further reduces potential entry points for attackers. The single external HTTP request is a minor point of attention, but without further context, it's difficult to assess its risk. The primary concern is the complete absence of nonce and capability checks across all potential entry points. While the static analysis reports zero unprotected entry points, this likely means that the checks, if they exist, are not detectable by the tools used, or that there are indeed no entry points requiring such checks. However, relying on this absence without explicit verification of protective measures is a weakness. Overall, the plugin appears secure due to its clean code and lack of history, but the absence of explicit checks raises a red flag that warrants further investigation.

Key Concerns

  • Missing nonce checks on entry points
  • Missing capability checks on entry points
Vulnerabilities
None known

Commentwitter Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Commentwitter Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0
Attack Surface

Commentwitter Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
filtercomment_reply_linkcommentwitter.php:55
Maintenance & Trust

Commentwitter Maintenance & Trust

Maintenance Signals

WordPress version tested3.0.5
Last updatedNov 16, 2010
PHP min version
Downloads8K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Commentwitter Developer Profile

Jon Bishop

6 plugins · 4K total installs

85
trust score
Avg Security Score
95/100
Avg Patch Time
89 days
View full developer profile
Detection Fingerprints

How We Detect Commentwitter

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
comment-reply-link
FAQ

Frequently Asked Questions about Commentwitter