Disable Update Notifications & Comments for WordPress Security & Risk Analysis

wordpress.org/plugins/disable-updates-comments

Disables Update notification for themes, plugins and core. disable auto-update of your WordPress Version and has ability to disable comments.

40 active installs v1.1 PHP 5.2.4+ WP 3.8+ Updated Jun 4, 2019
disable-update-notifications-in-wordpressdisable-updateshide-comments-optionshide-update-notificationpermanently-remove-comments
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Disable Update Notifications & Comments for WordPress Safe to Use in 2026?

Generally Safe

Score 85/100

Disable Update Notifications & Comments for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The "disable-updates-comments" v1.1 plugin exhibits an excellent security posture based on the provided static analysis. There are no identified entry points such as AJAX handlers, REST API routes, shortcodes, or cron events that are unprotected. The code also demonstrates strong adherence to security best practices, with all SQL queries using prepared statements, all output properly escaped, and no file operations or external HTTP requests being made. The presence of nonce and capability checks further solidifies its secure design.

Taint analysis reveals no critical or high-severity flows with unsanitized paths, indicating that user-supplied data is being handled securely and not leading to potential vulnerabilities. The plugin's vulnerability history is also clear, with zero known CVEs and no recorded past vulnerabilities of any severity. This clean history, coupled with the thorough static analysis, suggests a well-developed and secure plugin.

Overall, the plugin is exceptionally secure. The lack of any identified attack vectors, secure coding practices, and a clean vulnerability history are significant strengths. There are no discernible weaknesses based on the provided data, making it a low-risk plugin from a security perspective.

Vulnerabilities
None known

Disable Update Notifications & Comments for WordPress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Disable Update Notifications & Comments for WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
2 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped2 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
dun_update_options (disable-update-notifications-and-comments-for-wp.php:39)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Disable Update Notifications & Comments for WordPress Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 17
actionadmin_menudisable-update-notifications-and-comments-for-wp.php:17
actionadmin_initdisable-update-notifications-and-comments-for-wp.php:21
actionadmin_enqueue_scriptsdisable-update-notifications-and-comments-for-wp.php:36
actionadmin_initincludes\disable-comments.php:23
filtercomments_openincludes\disable-comments.php:29
filterpings_openincludes\disable-comments.php:30
filtercomments_arrayincludes\disable-comments.php:37
actionadmin_menuincludes\disable-comments.php:43
actionadmin_initincludes\disable-comments.php:52
actionadmin_initincludes\disable-comments.php:58
actioninitincludes\disable-comments.php:66
actionadmin_enqueue_scriptsincludes\disable-comments.php:74
filterpre_site_transient_update_coreincludes\disable-updates.php:17
filterpre_site_transient_update_pluginsincludes\disable-updates.php:18
filterpre_site_transient_update_themesincludes\disable-updates.php:19
filterauto_update_pluginincludes\disable-updates.php:21
filterauto_update_themeincludes\disable-updates.php:22
Maintenance & Trust

Disable Update Notifications & Comments for WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedJun 4, 2019
PHP min version5.2.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs40
Developer Profile

Disable Update Notifications & Comments for WordPress Developer Profile

Aman Verma

2 plugins · 140 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Disable Update Notifications & Comments for WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/disable-updates-comments/css/admin-style.css/wp-content/plugins/disable-updates-comments/includes/css/admin-comments-style.css
Version Parameters
disable-updates-comments/css/admin-style.css?ver=disable-updates-comments/includes/css/admin-comments-style.css?ver=

HTML / DOM Fingerprints

CSS Classes
updatederror
FAQ

Frequently Asked Questions about Disable Update Notifications & Comments for WordPress