
CRUDLab Disable Comments Security & Risk Analysis
wordpress.org/plugins/crudlab-disable-commentsCRUDLab Disable Comments plugin allows you to disable comments for any page or post or for whole site.
Is CRUDLab Disable Comments Safe to Use in 2026?
Generally Safe
Score 85/100CRUDLab Disable Comments has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "crudlab-disable-comments" v1.0.5 plugin presents a mixed security posture. While it has no recorded vulnerability history, indicating a potentially stable and well-maintained codebase in the past, the static analysis reveals significant concerns. The plugin exposes two AJAX handlers, both of which lack authentication checks, creating a substantial attack surface for unauthorized actions. Furthermore, the presence of the `unserialize` function is a red flag, as it can lead to remote code execution vulnerabilities if used with untrusted input. The absence of any nonce checks on these AJAX endpoints exacerbates this risk, making it easier for attackers to craft malicious requests.
Key Concerns
- AJAX handlers without authentication
- Usage of 'unserialize' function
- No nonce checks on AJAX handlers
- No capability checks
CRUDLab Disable Comments Security Vulnerabilities
CRUDLab Disable Comments Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
CRUDLab Disable Comments Attack Surface
AJAX Handlers 2
WordPress Hooks 17
Maintenance & Trust
CRUDLab Disable Comments Maintenance & Trust
Maintenance Signals
Community Trust
CRUDLab Disable Comments Alternatives
Disable Comments – Remove Comments & Stop Spam [Multi-Site Support]
disable-comments
Allows administrators to globally disable comments on their site. Comments can be disabled according to post type. Multisite friendly.
WP Comment Cleaner – Delete All Comments, Disable Comments, Bulk Delete & Remove Comments
delete-all-comments-of-website
Delete comments, disable comments, and remove comments in one click. Bulk delete spam and all comments to optimize your WordPress database easily.
Disable Comments & Delete All Comments
comments-plus
Disable comments globally on all posts or certain post types. Delete all comments at once, by post type or comment status. Manage links in comments.
Comments Shield – Disable Comments & Stop Spam, Bulk Delete & Remove Comments
comments-shield
Delete, disable, and clean all comments in one click. Easily manage, bulk delete, or completely disable comments across your entire WordPress site.
Habibur Comment Blocker
habibur-comment-blocker
Effortlessly disable comments and pingbacks sitewide to improve performance and security.
CRUDLab Disable Comments Developer Profile
1 plugin · 800 total installs
How We Detect CRUDLab Disable Comments
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/crudlab-disable-comments/crudlab-disable-comments.php/wp-content/plugins/crudlab-disable-comments/crudlab-disable-comments-settings.phpHTML / DOM Fingerprints
cldisablecomments-optionswindow.cldcb