Disable / Hide Comment URL Security & Risk Analysis

wordpress.org/plugins/disable-hide-comment-url

Disable/Hide Comment URL lets you hide the URL/Website input field from the WordPress inbuilt comments block.

600 active installs v1.0 PHP + WP 2.0.2+ Updated Sep 2, 2011
commentsdisablehideurlwebsite
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Disable / Hide Comment URL Safe to Use in 2026?

Generally Safe

Score 85/100

Disable / Hide Comment URL has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 14yr ago
Risk Assessment

Based on the static analysis and vulnerability history provided, the "disable-hide-comment-url" v1.0 plugin exhibits a generally strong security posture. The absence of any identified dangerous functions, raw SQL queries, unsanitized output, file operations, external HTTP requests, or critical taint flows is highly positive. Furthermore, the plugin demonstrates a lack of known vulnerabilities, with no recorded CVEs, indicating a history of stable and secure development.

However, a significant concern arises from the complete absence of security checks, including nonce checks and capability checks. While the current version may not have exploitable entry points like AJAX handlers, REST API routes, or shortcodes, this lack of basic security hygiene means that if the plugin were to evolve and introduce such entry points in the future, they would be inherently unprotected. This creates a potential future attack vector. The plugin's strengths lie in its clean code and zero known vulnerabilities, but its weakness lies in its underdeveloped security framework, which could become a liability with future development.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Disable / Hide Comment URL Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Disable / Hide Comment URL Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Disable / Hide Comment URL Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
filtercomment_form_default_fieldsdisable-hide-comment-url.php:30
Maintenance & Trust

Disable / Hide Comment URL Maintenance & Trust

Maintenance Signals

WordPress version tested3.2.1
Last updatedSep 2, 2011
PHP min version
Downloads17K

Community Trust

Rating100/100
Number of ratings8
Active installs600
Developer Profile

Disable / Hide Comment URL Developer Profile

Sachin Khosla

1 plugin · 600 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Disable / Hide Comment URL

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Disable / Hide Comment URL