
Disable Comments on Media Attachments Security & Risk Analysis
wordpress.org/plugins/disable-comments-on-attachmentsDisable Comments on Media Attachments Pages, Sitewide, Just Activate The Plugin.
Is Disable Comments on Media Attachments Safe to Use in 2026?
Generally Safe
Score 85/100Disable Comments on Media Attachments has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "disable-comments-on-attachments" v0.2.2 exhibits a generally strong security posture based on the provided static analysis. The absence of any recorded vulnerabilities, critical taint flows, or raw SQL queries is highly encouraging. Furthermore, the plugin demonstrates good practices by implementing nonce and capability checks, indicating an awareness of common WordPress security pitfalls. The limited attack surface, with no AJAX handlers, REST API routes, or shortcodes, further reduces its potential for exploitation.
However, there are a few areas that warrant attention. The fact that 63% of output is properly escaped, while not critically low, suggests that there is room for improvement to ensure all output is robustly sanitized, potentially mitigating risks of reflected cross-site scripting (XSS) if any user-controlled data were to be outputted. The presence of two external HTTP requests also introduces a minor risk, as these could be points of compromise if the external resource is malicious or compromised, or if the plugin handles the response insecurely. The taint analysis did reveal one flow with unsanitized paths, which, although not flagged as critical or high severity, should be investigated and remediated to prevent potential path traversal vulnerabilities.
Overall, this plugin appears to be developed with security in mind, with no historical vulnerabilities and a generally secure codebase. The identified minor concerns regarding output escaping and unsanitized paths are areas for enhancement rather than immediate critical threats, but addressing them would further solidify the plugin's security.
Key Concerns
- Unsanitized paths in taint analysis flow
- Not all outputs properly escaped
- External HTTP requests present
Disable Comments on Media Attachments Security Vulnerabilities
Disable Comments on Media Attachments Code Analysis
Output Escaping
Data Flow Analysis
Disable Comments on Media Attachments Attack Surface
WordPress Hooks 4
Maintenance & Trust
Disable Comments on Media Attachments Maintenance & Trust
Maintenance Signals
Community Trust
Disable Comments on Media Attachments Alternatives
Disable Comments – Remove Comments & Stop Spam [Multi-Site Support]
disable-comments
Allows administrators to globally disable comments on their site. Comments can be disabled according to post type. Multisite friendly.
Disable Comments
disable-comments-rb
Disable Comments - easy tool to disable comments for your blog posts, and pages. Admin can disable comments in just a few clicks.
WP Comment Cleaner – Delete All Comments, Disable Comments, Bulk Delete & Remove Comments
delete-all-comments-of-website
Delete comments, disable comments, and remove comments in one click. Bulk delete spam and all comments to optimize your WordPress database easily.
Disable Comments
wpsimpletools-disable-comments
Completely disables comments functionality from backend and frontend. Just install it, nothing to configure!
Comment Link Remove and Other Comment Tools
comment-link-remove
Remove Comment Author Link & Links from Comments, Unlink, Disable Comments, Delete All Pending Comments. AI Auto Comment Reply, Voice, Attachments
Disable Comments on Media Attachments Developer Profile
4 plugins · 430 total installs
How We Detect Disable Comments on Media Attachments
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/disable-comments-on-attachments/tracking/class-plugin-usage-tracker.php