
Disable Comments – Remove Comments & Stop Spam [Multi-Site Support] Security & Risk Analysis
wordpress.org/plugins/disable-commentsAllows administrators to globally disable comments on their site. Comments can be disabled according to post type. Multisite friendly.
Is Disable Comments – Remove Comments & Stop Spam [Multi-Site Support] Safe to Use in 2026?
Generally Safe
Score 99/100Disable Comments – Remove Comments & Stop Spam [Multi-Site Support] has a strong security track record. Known vulnerabilities have been patched promptly.
The disable-comments plugin v2.6.2 generally exhibits good security practices. The static analysis shows a well-protected attack surface with all identified AJAX handlers and no unprotected REST API routes, shortcodes, or cron events. The code also demonstrates strong adherence to security by using prepared statements for a high percentage of SQL queries and properly escaping most outputs. The absence of dangerous functions and file operations further contributes to a positive security posture. However, a notable concern arises from the presence of one flow with an unsanitized path, even though it did not register as a critical or high severity issue. The plugin's vulnerability history, while dated, indicates a past high-severity vulnerability of the Cross-Site Request Forgery (CSRF) type. The fact that the last vulnerability was in 2014 and is currently unpatched suggests a potential for older, unaddressed issues or a need for more frequent security audits. Despite the dated history, the presence of a past high-severity CSRF vulnerability warrants caution. In conclusion, the plugin is reasonably secure due to its robust implementation of fundamental security checks and input sanitization, but the historical CSRF vulnerability and the single unsanitized path flow suggest areas for potential improvement and vigilant monitoring.
Key Concerns
- Flow with unsanitized path
- Past high severity vulnerability (2014)
Disable Comments – Remove Comments & Stop Spam [Multi-Site Support] Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Disable Comments – Remove Comments & Stop Spam [Multi-Site Support] < 1.0.4 - Cross-Site Request Forgery
Disable Comments – Remove Comments & Stop Spam [Multi-Site Support] Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Disable Comments – Remove Comments & Stop Spam [Multi-Site Support] Attack Surface
AJAX Handlers 3
WordPress Hooks 47
Maintenance & Trust
Disable Comments – Remove Comments & Stop Spam [Multi-Site Support] Maintenance & Trust
Maintenance Signals
Community Trust
Disable Comments – Remove Comments & Stop Spam [Multi-Site Support] Alternatives
Habibur Comment Blocker
habibur-comment-blocker
Effortlessly disable comments and pingbacks sitewide to improve performance and security.
Yakura Commenti – Disable & Remove Comments
yakura-commenti
Disable and remove comments site-wide or per post type. Control REST API, feeds, XML-RPC, admin UI, and avatars. Multisite ready
WP Comment Cleaner – Delete All Comments, Disable Comments, Bulk Delete & Remove Comments
delete-all-comments-of-website
Delete comments, disable comments, and remove comments in one click. Bulk delete spam and all comments to optimize your WordPress database easily.
Disable Comments & Delete All Comments
comments-plus
Disable comments globally on all posts or certain post types. Delete all comments at once, by post type or comment status. Manage links in comments.
Turn Off Comments — Hide Comment Box and Stop Spam
turn-off-comments
Remove comments functionality from your website!
Disable Comments – Remove Comments & Stop Spam [Multi-Site Support] Developer Profile
46 plugins · 4.0M total installs
How We Detect Disable Comments – Remove Comments & Stop Spam [Multi-Site Support]
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/disable-comments/assets/css/admin.css/wp-content/plugins/disable-comments/assets/js/admin.js/wp-content/plugins/disable-comments/assets/css/disable-comments.css/wp-content/plugins/disable-comments/assets/js/disable-comments.js/wp-content/plugins/disable-comments/assets/js/disable-comments-admin.js/wp-content/plugins/disable-comments/assets/js/notice.js/wp-content/plugins/disable-comments/assets/js/admin.js/wp-content/plugins/disable-comments/assets/js/disable-comments.js/wp-content/plugins/disable-comments/assets/js/disable-comments-admin.js/wp-content/plugins/disable-comments/assets/js/notice.js/wp-content/plugins/disable-comments/assets/css/admin.css?ver=/wp-content/plugins/disable-comments/assets/js/admin.js?ver=/wp-content/plugins/disable-comments/assets/css/disable-comments.css?ver=/wp-content/plugins/disable-comments/assets/js/disable-comments.js?ver=/wp-content/plugins/disable-comments/assets/js/disable-comments-admin.js?ver=/wp-content/plugins/disable-comments/assets/js/notice.js?ver=HTML / DOM Fingerprints
disable-comments-settings-wrapdisable-comments-notice<!-- DC Settings --><!-- Disable Comments Admin Notice -->data-plugin-slug="disable_comments_settings"data-disable-comments-noncewindow.disable_comments_settingswindow.disable_comments_ajax_object/wp-json/disable-comments/v1/settings/wp-json/disable-comments/v1/delete-comments