
Disable Comments Selectively Security & Risk Analysis
wordpress.org/plugins/disable-comments-selectivelyChoose which post types, taxonomies and/or terms will have comments disabled.
Is Disable Comments Selectively Safe to Use in 2026?
Generally Safe
Score 100/100Disable Comments Selectively has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "disable-comments-selectively" v0.16 exhibits a strong security posture based on the static analysis. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits its attack surface. Furthermore, the code demonstrates good practices by using prepared statements for its single SQL query and properly escaping the vast majority of its output. The presence of a capability check further reinforces its security. The lack of any recorded vulnerabilities in its history further strengthens this assessment, suggesting a well-maintained and secure codebase.
While the plugin's current analysis reveals no immediate critical flaws, the complete lack of any identified taint flows and the absence of nonce checks are notable. While not necessarily indicative of a vulnerability in this specific instance due to the limited attack surface, these are generally considered important security mechanisms. The plugin's minimal attack surface and robust use of prepared statements and output escaping are significant strengths. However, the absence of nonce checks, even with a limited attack surface, represents a minor area for potential improvement to ensure comprehensive security practices.
In conclusion, "disable-comments-selectively" v0.16 appears to be a very secure plugin. Its minimal attack surface, excellent data handling practices (prepared statements, output escaping), and clean vulnerability history are all positive indicators. The only minor concern is the absence of nonce checks, which, given the plugin's function and limited entry points, poses a very low risk but could be considered for future hardening.
Key Concerns
- Absence of nonce checks
Disable Comments Selectively Security Vulnerabilities
Disable Comments Selectively Code Analysis
SQL Query Safety
Output Escaping
Disable Comments Selectively Attack Surface
WordPress Hooks 11
Maintenance & Trust
Disable Comments Selectively Maintenance & Trust
Maintenance Signals
Community Trust
Disable Comments Selectively Alternatives
Disable Comments – Remove Comments & Stop Spam [Multi-Site Support]
disable-comments
Allows administrators to globally disable comments on their site. Comments can be disabled according to post type. Multisite friendly.
WP Comment Cleaner – Delete All Comments, Disable Comments, Bulk Delete & Remove Comments
delete-all-comments-of-website
Delete comments, disable comments, and remove comments in one click. Bulk delete spam and all comments to optimize your WordPress database easily.
Disable Comments
wpsimpletools-disable-comments
Completely disables comments functionality from backend and frontend. Just install it, nothing to configure!
Disable Comments & Delete All Comments
comments-plus
Disable comments globally on all posts or certain post types. Delete all comments at once, by post type or comment status. Manage links in comments.
Turn Off Comments — Hide Comment Box and Stop Spam
turn-off-comments
Remove comments functionality from your website!
Disable Comments Selectively Developer Profile
10 plugins · 300 total installs
How We Detect Disable Comments Selectively
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/disable-comments-selectively/admin.js/wp-content/plugins/disable-comments-selectively/admin.jsHTML / DOM Fingerprints
dcbtid="dcs_"name="DisableCommentsSelectivelyPlugin[