
Disable Post Comments Security & Risk Analysis
wordpress.org/plugins/disable-post-commentsThis plugin allows administrators can disable wordpress all post type comments on their site and also can be disabled specific post type.
Is Disable Post Comments Safe to Use in 2026?
Generally Safe
Score 85/100Disable Post Comments has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "disable-post-comments" v1.0.3 plugin exhibits a generally positive security posture based on the provided static analysis. The absence of an attack surface through AJAX, REST API, shortcodes, or cron events is a significant strength, indicating that there are no direct entry points for external manipulation. Furthermore, the plugin does not perform file operations or external HTTP requests, reducing potential attack vectors. The presence of nonce and capability checks, while not exhaustive, demonstrates an awareness of basic WordPress security practices.
However, a notable concern arises from the handling of SQL queries. All 12 detected SQL queries are executed without prepared statements. This is a significant risk, as it leaves the plugin vulnerable to SQL injection attacks if any user-supplied data is incorporated into these queries. The low percentage of properly escaped output (17%) also suggests a potential for Cross-Site Scripting (XSS) vulnerabilities, although the absence of taint flows with unsanitized paths offers some reassurance in this regard. The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive indicator, but this should not overshadow the inherent risks identified in the code itself.
In conclusion, while the plugin has a small attack surface and a clean vulnerability history, the lack of prepared statements for all SQL queries and the poor output escaping are critical security weaknesses that need immediate attention. Addressing these issues would significantly improve the plugin's overall security.
Key Concerns
- 100% of SQL queries use raw statements
- Only 17% of output is properly escaped
Disable Post Comments Security Vulnerabilities
Disable Post Comments Release Timeline
Disable Post Comments Code Analysis
SQL Query Safety
Output Escaping
Disable Post Comments Attack Surface
WordPress Hooks 32
Maintenance & Trust
Disable Post Comments Maintenance & Trust
Maintenance Signals
Community Trust
Disable Post Comments Alternatives
Disable Comments – Remove Comments & Stop Spam [Multi-Site Support]
disable-comments
Allows administrators to globally disable comments on their site. Comments can be disabled according to post type. Multisite friendly.
Disable Comments
disable-comments-rb
Disable Comments - easy tool to disable comments for your blog posts, and pages. Admin can disable comments in just a few clicks.
Comment Cleaner — Bulk Delete & Disable Comments
delete-all-comments-of-website
Delete, export, import, and manage WordPress comments with bulk tools and comment-control settings.
Disable Comments
wpsimpletools-disable-comments
Completely disables comments functionality from backend and frontend. Just install it, nothing to configure!
Disable Comments & Delete All Comments
comments-plus
Disable comments globally on all posts or certain post types. Delete all comments at once, by post type or comment status. Manage links in comments.
Disable Post Comments Developer Profile
3 plugins · 40 total installs
How We Detect Disable Post Comments
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/disable-post-comments/assets/css/disable-post-comments-admin.css/wp-content/plugins/disable-post-comments/assets/js/disable-post-comments-admin.js/wp-content/plugins/disable-post-comments/assets/js/disable-post-comments-admin.jsdisable-post-comments/assets/css/disable-post-comments-admin.css?ver=disable-post-comments/assets/js/disable-post-comments-admin.js?ver=HTML / DOM Fingerprints
disable-post-comments-settingsdata-dpc-plugin-urldpc_admin_options