Dispito – discussions and comments Security & Risk Analysis

wordpress.org/plugins/dispito

The Dispito comment system replaces your WordPress comment system with your comments hosted and powered by Dispito.

10 active installs v1.0.1 PHP + WP 3.0+ Updated Oct 9, 2013
commentsdiscussionemailforumthreaded
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Dispito – discussions and comments Safe to Use in 2026?

Generally Safe

Score 85/100

Dispito – discussions and comments has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

The "dispito" v1.0.1 plugin exhibits a generally positive security posture based on the static analysis. The plugin has a remarkably small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, the absence of dangerous functions and file operations suggests a careful approach to development. The plugin also avoids making external HTTP requests, which can be a source of vulnerabilities. The zero-known CVEs and lack of recorded vulnerabilities in its history are strong indicators of a well-maintained and secure plugin.

However, there are significant concerns regarding output escaping, with 0% of identified outputs being properly escaped. This presents a substantial risk of Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected into the website's output. Additionally, while the plugin uses prepared statements for some SQL queries, a considerable portion (67%) do not, posing a risk of SQL injection vulnerabilities. The absence of nonce and capability checks, coupled with a complete lack of taint analysis findings (which might indicate the analysis couldn't find entry points to track), suggests that if any exploitable paths do exist, they might not be adequately protected against unauthorized actions or data manipulation.

In conclusion, while the plugin's limited attack surface and clean vulnerability history are strengths, the critical issues of unescaped output and raw SQL queries, along with the missing security checks, introduce significant risks that need immediate attention. The lack of taint analysis flows being detected could be an indication of its limited scope or the absence of complex data manipulation, but the presence of raw SQL and unescaped output are direct indicators of exploitable flaws.

Key Concerns

  • Output escaping is not performed
  • SQL queries are not fully using prepared statements
  • Nonce checks are missing
  • Capability checks are missing
Vulnerabilities
None known

Dispito – discussions and comments Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Dispito – discussions and comments Code Analysis

Dangerous Functions
0
Raw SQL Queries
4
2 prepared
Unescaped Output
4
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

33% prepared6 total queries

Output Escaping

0% escaped4 total outputs
Attack Surface

Dispito – discussions and comments Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_menudispito.php:39
actionwp_headdispito.php:152
actionwp_enqueue_scriptsdispito.php:154
filtercomments_templatedispito.php:156
Maintenance & Trust

Dispito – discussions and comments Maintenance & Trust

Maintenance Signals

WordPress version tested3.0.5
Last updatedOct 9, 2013
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Dispito – discussions and comments Developer Profile

erik_cz

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Dispito – discussions and comments

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Script Paths
/wp-content/plugins/dispito/embed.js

HTML / DOM Fingerprints

JS Globals
dispito_thread
FAQ

Frequently Asked Questions about Dispito – discussions and comments