WP Comment Cleaner – Delete All Comments, Disable Comments, Bulk Delete & Remove Comments Security & Risk Analysis

wordpress.org/plugins/delete-all-comments-of-website

Delete comments, disable comments, and remove comments in one click. Bulk delete spam and all comments to optimize your WordPress database easily.

20K active installs v6.8 PHP 7.2+ WP 5.0+ Updated Feb 20, 2026
bulk-deletedelete-all-commentsdelete-commentsdisable-commentsremove-comments
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP Comment Cleaner – Delete All Comments, Disable Comments, Bulk Delete & Remove Comments Safe to Use in 2026?

Generally Safe

Score 100/100

WP Comment Cleaner – Delete All Comments, Disable Comments, Bulk Delete & Remove Comments has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The 'delete-all-comments-of-website' plugin version 6.8 exhibits a generally strong security posture. All identified AJAX and REST API entry points appear to have authentication and permission checks, which is a significant strength. The absence of known CVEs, common vulnerability types, and any recorded vulnerabilities suggests a history of responsible development and patching, or a lack of targeted attacks. However, the code analysis reveals some areas for improvement. A notable concern is the proportion of SQL queries (24%) not using prepared statements, which could be susceptible to SQL injection if user input is not meticulously handled. Additionally, while most output is escaped, 28% of outputs are not properly escaped, potentially leading to cross-site scripting (XSS) vulnerabilities. The presence of unsanitized paths in taint analysis, though not critical, warrants attention as it can be an indicator of potential path traversal or file system vulnerabilities.

Key Concerns

  • SQL queries not using prepared statements
  • Output escaping is not fully robust
  • Unsanitized paths in taint analysis
Vulnerabilities
None known

WP Comment Cleaner – Delete All Comments, Disable Comments, Bulk Delete & Remove Comments Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WP Comment Cleaner – Delete All Comments, Disable Comments, Bulk Delete & Remove Comments Code Analysis

Dangerous Functions
0
Raw SQL Queries
22
7 prepared
Unescaped Output
26
67 escaped
Nonce Checks
7
Capability Checks
6
File Operations
3
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius1.0

SQL Query Safety

24% prepared29 total queries

Output Escaping

72% escaped93 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

6 flows2 with unsanitized paths
nav_delete_comment (delete-all-comments-of-wordpress-website.php:1237)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

WP Comment Cleaner – Delete All Comments, Disable Comments, Bulk Delete & Remove Comments Attack Surface

Entry Points5
Unprotected0

AJAX Handlers 5

authwp_ajax_nav_reset_comment_settingsdelete-all-comments-of-wordpress-website.php:255
authwp_ajax_nav_import_comments_ajaxdelete-all-comments-of-wordpress-website.php:1184
authwp_ajax_nav_export_comments_ajaxdelete-all-comments-of-wordpress-website.php:1185
authwp_ajax_nav_save_comment_settingsdelete-all-comments-of-wordpress-website.php:1186
authwp_ajax_nav_delete_comments_ajaxdelete-all-comments-of-wordpress-website.php:1187
WordPress Hooks 22
actionadmin_enqueue_scriptsdelete-all-comments-of-wordpress-website.php:52
actionadmin_menudelete-all-comments-of-wordpress-website.php:54
actioninitdelete-all-comments-of-wordpress-website.php:58
filterall_pluginsdelete-all-comments-of-wordpress-website.php:75
actionadmin_noticesdelete-all-comments-of-wordpress-website.php:129
filtercomments_opendelete-all-comments-of-wordpress-website.php:649
filterpings_opendelete-all-comments-of-wordpress-website.php:650
filtercomments_opendelete-all-comments-of-wordpress-website.php:666
filterpings_opendelete-all-comments-of-wordpress-website.php:667
filteravatar_defaultsdelete-all-comments-of-wordpress-website.php:675
filterxmlrpc_methodsdelete-all-comments-of-wordpress-website.php:683
filterrest_pre_dispatchdelete-all-comments-of-wordpress-website.php:693
filtercomments_opendelete-all-comments-of-wordpress-website.php:740
filterpings_opendelete-all-comments-of-wordpress-website.php:741
actionwpdelete-all-comments-of-wordpress-website.php:1756
filtercron_schedulesdelete-all-comments-of-wordpress-website.php:1770
actionnav_auto_delete_spam_eventdelete-all-comments-of-wordpress-website.php:1811
actionadmin_noticesdelete-all-comments-of-wordpress-website.php:1822
actionadmin_noticesdelete-all-comments-of-wordpress-website.php:1836
actionadmin_noticesdelete-all-comments-of-wordpress-website.php:1840
actionadmin_initdelete-all-comments-of-wordpress-website.php:1847
actionadmin_menudelete-all-comments-of-wordpress-website.php:1861

Scheduled Events 3

nav_auto_delete_spam_event
nav_auto_delete_spam_event
nav_auto_delete_spam_event
Maintenance & Trust

WP Comment Cleaner – Delete All Comments, Disable Comments, Bulk Delete & Remove Comments Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 20, 2026
PHP min version7.2
Downloads566K

Community Trust

Rating94/100
Number of ratings58
Active installs20K
Developer Profile

WP Comment Cleaner – Delete All Comments, Disable Comments, Bulk Delete & Remove Comments Developer Profile

royalnavneet

2 plugins · 20K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP Comment Cleaner – Delete All Comments, Disable Comments, Bulk Delete & Remove Comments

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/delete-all-comments-of-website/css/nav-comments-admin.css/wp-content/plugins/delete-all-comments-of-website/js/nav-comments-admin.js
Script Paths
https://cdn.jsdelivr.net/npm/bootstrap@5.1.3/dist/js/bootstrap.bundle.min.jshttps://cdn.jsdelivr.net/npm/sweetalert2@11.0.19/dist/sweetalert2.all.min.js
Version Parameters
nav-comments-admin?ver=

HTML / DOM Fingerprints

Data Attributes
data-nav_action
JS Globals
navCommentsSettings
FAQ

Frequently Asked Questions about WP Comment Cleaner – Delete All Comments, Disable Comments, Bulk Delete & Remove Comments