
Delete Comments on a Schedule Security & Risk Analysis
wordpress.org/plugins/delete-comments-on-a-scheduleCe plugin vous permet de nettoyer facilement votre base de données en supprimant les spams et les commentaires modérés qui encombrent votre site.
Is Delete Comments on a Schedule Safe to Use in 2026?
Generally Safe
Score 100/100Delete Comments on a Schedule has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'delete-comments-on-a-schedule' plugin v1.0.0 demonstrates a strong adherence to several security best practices, which is a positive indicator. The absence of dangerous functions, file operations, external HTTP requests, and the use of prepared statements for all SQL queries are commendable. Furthermore, the plugin has no recorded vulnerability history, suggesting a stable and well-maintained codebase.
However, significant concerns arise from the lack of capability checks and nonce checks, coupled with a low rate of output escaping (29%). While the attack surface is currently minimal (0 AJAX, 0 REST API, 0 shortcodes), the presence of a cron event, without any explicit authentication or authorization mechanisms tied to its execution, presents a potential risk. If this cron event were to be triggered or manipulated externally, it could lead to unintended actions without proper validation. The taint analysis showing no flows is good, but this is often a result of an extremely limited or non-existent attack surface for taint analysis to traverse.
In conclusion, while the plugin benefits from a clean vulnerability history and good practices in data handling (SQL prepared statements), the significant gaps in authentication, authorization, and output sanitization for its cron event are notable weaknesses. These vulnerabilities could potentially be exploited if the cron event's execution context is compromised or if its logic is indirectly influenced by user input that is not properly escaped.
Key Concerns
- No capability checks implemented
- No nonce checks implemented
- Low output escaping rate (29%)
- Cron event without authentication/authorization
Delete Comments on a Schedule Security Vulnerabilities
Delete Comments on a Schedule Code Analysis
SQL Query Safety
Output Escaping
Delete Comments on a Schedule Attack Surface
WordPress Hooks 3
Scheduled Events 1
Maintenance & Trust
Delete Comments on a Schedule Maintenance & Trust
Maintenance Signals
Community Trust
Delete Comments on a Schedule Alternatives
WP referrer spam blacklist (fight 2040+ Referrer Spammers in (Google/Matomo) Analytics)
wp-referrer-spam-blacklist
WordPress plugin to fight with 2040+ referrer spammers (like semalt, buttons-for-website and many more).
Auto Approve Comments
auto-approve-comments
Auto approve comments by Commenter (email, name, url), User and Role (Akismet and wpDiscuz compatible)
AI Comment Guard
ai-comment-guard
Protect your WordPress site from spam with AI-powered comment moderation. Supports OpenAI, Anthropic, and OpenRouter providers.
WP Link Analysis
wp-link-analysis
Ce plugin analyse les liens contenus dans un article et les affiche dans une metabox dans l'interface d'administration.
BuddyVerified
buddypress-verified
Allows admins to specify verified accounts. Adds a badge to verified usernames.
Delete Comments on a Schedule Developer Profile
2 plugins · 10 total installs
How We Detect Delete Comments on a Schedule
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.