
Decent Comments Security & Risk Analysis
wordpress.org/plugins/decent-commentsDecent Comments shows what people say. A more engaging way to show comments.
Is Decent Comments Safe to Use in 2026?
Generally Safe
Score 100/100Decent Comments has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'decent-comments' v3.0.2 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by using prepared statements for all SQL queries and avoids dangerous functions, file operations, and external HTTP requests. The vulnerability history is clean, with no recorded CVEs, suggesting a history of responsible development or minimal previous exposure. However, there are notable concerns, particularly regarding the REST API. One REST API route is exposed without a permission callback, creating a potential entry point for unauthorized access or manipulation. While the static analysis shows a low number of total entry points, this unprotected REST API endpoint is a significant weakness. Furthermore, only 41% of output escaping is properly done, which could lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is outputted without sufficient sanitization. The single nonce check and capability check, while present, might not be sufficient to protect all critical functionalities given the unescaped output percentage.
Key Concerns
- REST API route without permission callback
- Low percentage of properly escaped output
Decent Comments Security Vulnerabilities
Decent Comments Code Analysis
SQL Query Safety
Output Escaping
Decent Comments Attack Surface
REST API Routes 1
Shortcodes 2
WordPress Hooks 11
Maintenance & Trust
Decent Comments Maintenance & Trust
Maintenance Signals
Community Trust
Decent Comments Alternatives
No Page Comment
no-page-comment
An admin interface to control the default comment and trackback settings on new posts, pages and custom post types.
Disable Comments
wpsimpletools-disable-comments
Completely disables comments functionality from backend and frontend. Just install it, nothing to configure!
Better Recent Comments
better-recent-comments
Provides an improved Recent Comments widget and a shortcode to display your recent comments on any post or page.
WP First Letter Avatar
wp-first-letter-avatar
Set custom avatars for users with no Gravatar. The avatar will be the first (or any other) letter of user's name on a colorful background.
Comments Shortcode
comments-shortcode
This plugin allows you to use a shortcode anywhere to display comments on WordPress pages and posts along with the comment form.
Decent Comments Developer Profile
27 plugins · 23K total installs
How We Detect Decent Comments
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/decent-comments/build/index.asset.php/wp-content/plugins/decent-comments/build/index.js/wp-content/plugins/decent-comments/build/editor.css/wp-content/plugins/decent-comments/build/view.js/wp-content/plugins/decent-comments/build/block.json/wp-content/plugins/decent-comments/build/index.js/wp-content/plugins/decent-comments/build/view.jsdecent-comments/build/index.js?ver=decent-comments/build/view.js?ver=decent-comments/build/editor.css?ver=HTML / DOM Fingerprints
wp-block-decent-comments-decent-commentsdata-post-typesdata-current-iddecentCommentsEditdecentCommentsView