Daisy Comments — Disable Comments & Stop Spam Security & Risk Analysis

wordpress.org/plugins/daisy-comments

Disables comment functionality and hides all existing comments from your WordPress website.

900 active installs v1.0.12 PHP 7.2+ WP 5.2+ Updated Jan 1, 2026
commentsdisable-commentshide-commentsremove-commentsturn-off-comments
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Daisy Comments — Disable Comments & Stop Spam Safe to Use in 2026?

Generally Safe

Score 100/100

Daisy Comments — Disable Comments & Stop Spam has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The daisy-comments plugin v1.0.12 demonstrates a generally strong security posture based on the provided static analysis and vulnerability history. The plugin has no known CVEs, indicating a history of good security practices or a lack of discovered vulnerabilities. Static analysis reveals a clean codebase with no dangerous functions, no SQL queries without prepared statements, and no file operations or external HTTP requests, which are common vectors for attacks. The absence of AJAX handlers, REST API routes, shortcodes, and cron events contributing to the attack surface is also a positive sign, as these are primary entry points for malicious activity. The plugin also implements nonce and capability checks, which are essential for WordPress security.

While the static analysis shows a robust codebase with excellent output escaping (92%), minimal taint flows analyzed (2), and no unsanitized paths or critical/high severity flows, it's worth noting that the total number of entry points is zero. This could indicate a very simple plugin or that the analysis did not identify specific WordPress-related entry points. The plugin also has only one nonce check and one capability check, which might be sufficient for its current functionality but could become a concern if the plugin's features expand without additional checks. The fact that 100% of SQL queries use prepared statements and a high percentage of output is escaped are significant strengths.

In conclusion, daisy-comments v1.0.12 appears to be a securely developed plugin with a clean record. The lack of known vulnerabilities and the strong adherence to secure coding practices in the static analysis are commendable. The primary areas to monitor would be the limited number of explicit security checks (nonce and capability) if the plugin's functionality were to increase, and ensuring continued diligence in maintaining this secure state.

Vulnerabilities
None known

Daisy Comments — Disable Comments & Stop Spam Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Daisy Comments — Disable Comments & Stop Spam Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
12 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

92% escaped13 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
daisy_comments_render_settings_page (daisy-comments.php:298)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Daisy Comments — Disable Comments & Stop Spam Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 25
actionadmin_initdaisy-comments.php:32
actionadmin_menudaisy-comments.php:35
actionadmin_enqueue_scriptsdaisy-comments.php:44
filtercomments_opendaisy-comments.php:67
filterpings_opendaisy-comments.php:68
filtercomments_arraydaisy-comments.php:71
filtercomments_arraydaisy-comments.php:73
actionwp_headdaisy-comments.php:74
actionpre_comment_on_postdaisy-comments.php:75
actionadmin_menudaisy-comments.php:78
actioninitdaisy-comments.php:81
actionadmin_initdaisy-comments.php:84
actionadmin_initdaisy-comments.php:87
actionadmin_initdaisy-comments.php:90
filtermanage_posts_columnsdaisy-comments.php:93
filtermanage_pages_columnsdaisy-comments.php:94
actionwp_loadeddaisy-comments.php:97
actiondo_feeddaisy-comments.php:204
actiondo_feed_rdfdaisy-comments.php:205
actiondo_feed_rssdaisy-comments.php:206
actiondo_feed_rss2daisy-comments.php:207
actiondo_feed_atomdaisy-comments.php:208
actiondo_feed_rss2_commentsdaisy-comments.php:209
actiondo_feed_atom_commentsdaisy-comments.php:210
actionadmin_noticesdaisy-comments.php:404
Maintenance & Trust

Daisy Comments — Disable Comments & Stop Spam Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 1, 2026
PHP min version7.2
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs900
Developer Profile

Daisy Comments — Disable Comments & Stop Spam Developer Profile

DaisyPlugins

7 plugins · 4K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Daisy Comments — Disable Comments & Stop Spam

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
nocommentsno-commentshas-commentspost-commentscomments-linkcomments-areacomment-respondcomments-closed+8 more
FAQ

Frequently Asked Questions about Daisy Comments — Disable Comments & Stop Spam