
Delete All Pending Comments Security & Risk Analysis
wordpress.org/plugins/delete-all-pending-commentsDelete all pending comments from your database easily.
Is Delete All Pending Comments Safe to Use in 2026?
Generally Safe
Score 85/100Delete All Pending Comments has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'delete-all-pending-comments' v1.0 demonstrates a mixed security posture. On the positive side, it has a very small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events, all of which are typically entry points for attackers. Furthermore, there are no recorded vulnerabilities (CVEs) in its history, suggesting a history of stable and potentially secure code. The presence of nonce checks, even if limited, is a good practice. However, significant concerns arise from the static analysis of its code. All SQL queries are performed without prepared statements, creating a high risk of SQL injection vulnerabilities. Additionally, none of the 12 output operations are properly escaped, opening the door to Cross-Site Scripting (XSS) attacks. The absence of capability checks is also a notable weakness, as it means that any logged-in user, regardless of their role, could potentially trigger plugin functionality if an entry point were discovered.
While the plugin's attack surface is minimal and it has no vulnerability history, the direct risks of SQL injection and XSS stemming from the unescaped output and raw SQL queries are substantial. The lack of capability checks further exacerbates this by not enforcing authorization. The plugin's strengths lie in its limited exposure and clean history, but its implementation flaws in handling data and queries present clear and present dangers that need immediate attention. A small attack surface is negated by critical vulnerabilities within the code itself.
Key Concerns
- Raw SQL queries without prepared statements
- Unescaped output operations
- Missing capability checks on entry points
Delete All Pending Comments Security Vulnerabilities
Delete All Pending Comments Code Analysis
SQL Query Safety
Output Escaping
Delete All Pending Comments Attack Surface
WordPress Hooks 2
Maintenance & Trust
Delete All Pending Comments Maintenance & Trust
Maintenance Signals
Community Trust
Delete All Pending Comments Alternatives
Delete Pending Comments
delete-pending-comments
A quick way to delete all pending and spam comments. Useful for victims of spammer attacks.
AI Disable Comments
ai-disable-comments
A quick way to disable or delete all approved, pending or spam comments and pings only with one click.
Akismet Anti-spam: Spam Protection
akismet
The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam solution for WordPress and WooCommerce.
Disable Comments – Remove Comments & Stop Spam [Multi-Site Support]
disable-comments
Allows administrators to globally disable comments on their site. Comments can be disabled according to post type. Multisite friendly.
Antispam Bee
antispam-bee
Sophisticated antispam plugin for effective daily comment and trackback spam-fighting. Built with data protection and privacy in mind.
Delete All Pending Comments Developer Profile
5 plugins · 150 total installs
How We Detect Delete All Pending Comments
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/delete-all-pending-comments/dapc.cssdelete-all-pending-comments/dapc.css?ver=HTML / DOM Fingerprints
small_dapcbutton-checkboxname="dapc_form"name="dapc"name="delete"