
Disable Comments Security & Risk Analysis
wordpress.org/plugins/disable-comments-rbDisable Comments - easy tool to disable comments for your blog posts, and pages. Admin can disable comments in just a few clicks.
Is Disable Comments Safe to Use in 2026?
Generally Safe
Score 100/100Disable Comments has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "disable-comments-rb" plugin v1.0.26 exhibits a generally strong security posture based on the provided static analysis. The plugin boasts a remarkably small attack surface, with no identifiable AJAX handlers, REST API routes, shortcodes, or cron events that could be exploited as entry points. The code also demonstrates good security practices by using prepared statements exclusively for SQL queries and incorporating nonce and capability checks. The absence of external HTTP requests and file operations further reduces potential risks.
However, a significant concern is the output escaping. With 17 total outputs and only 41% properly escaped, there is a substantial risk of cross-site scripting (XSS) vulnerabilities. This means sensitive data or user-controlled input might be rendered directly in the browser without proper sanitization, allowing attackers to inject malicious scripts. The taint analysis revealing zero flows with unsanitized paths is positive, but it doesn't mitigate the identified output escaping issues.
The vulnerability history is also a positive indicator, with no recorded CVEs or past vulnerabilities. This suggests a history of responsible development. Despite the excellent history and minimal attack surface, the poor output escaping is a critical weakness that needs immediate attention. Addressing this would significantly improve the plugin's overall security.
Key Concerns
- Insufficient output escaping (59% not properly escaped)
Disable Comments Security Vulnerabilities
Disable Comments Code Analysis
Output Escaping
Disable Comments Attack Surface
WordPress Hooks 20
Maintenance & Trust
Disable Comments Maintenance & Trust
Maintenance Signals
Community Trust
Disable Comments Alternatives
Disable Comments – Remove Comments & Stop Spam [Multi-Site Support]
disable-comments
Allows administrators to globally disable comments on their site. Comments can be disabled according to post type. Multisite friendly.
WP Comment Cleaner – Delete All Comments, Disable Comments, Bulk Delete & Remove Comments
delete-all-comments-of-website
Delete comments, disable comments, and remove comments in one click. Bulk delete spam and all comments to optimize your WordPress database easily.
Disable Comments
wpsimpletools-disable-comments
Completely disables comments functionality from backend and frontend. Just install it, nothing to configure!
Comment Link Remove and Other Comment Tools
comment-link-remove
Remove Comment Author Link & Links from Comments, Unlink, Disable Comments, Delete All Pending Comments. AI Auto Comment Reply, Voice, Attachments
Disable Comments & Delete All Comments
comments-plus
Disable comments globally on all posts or certain post types. Delete all comments at once, by post type or comment status. Manage links in comments.
Disable Comments Developer Profile
8 plugins · 107K total installs
How We Detect Disable Comments
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
rbs_nw_wraprbs_nw_itemrbs_nw_item_logorbs_nw_item_logo_pluginrbs_nw_item_logo_upzrbs_nw_item_headerrbs_nw_item_buttonrbs-info-oneline+2 more