
Disqus Latest Comments Addon Security & Risk Analysis
wordpress.org/plugins/disqus-latest-commentsDisplay latest Disqus comments in a page, post or widget
Is Disqus Latest Comments Addon Safe to Use in 2026?
Generally Safe
Score 85/100Disqus Latest Comments Addon has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "disqus-latest-comments" plugin v2.3.1 exhibits a mixed security posture. On the positive side, the plugin does not use any dangerous functions, all SQL queries are properly prepared, and there are no file operations or known historical vulnerabilities. This indicates a good understanding of core security practices regarding data handling and known exploits.
However, significant concerns arise from the static analysis. The plugin exposes two AJAX handlers that lack any form of authentication check. This represents a substantial attack surface where unauthenticated users could potentially trigger plugin actions. Additionally, a notable portion of output (48%) is not properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is reflected in the output. The absence of nonce checks on AJAX actions exacerbates this risk, as it allows for easier exploitation of potential XSS vulnerabilities.
Overall, while the plugin is free from known historical vulnerabilities and demonstrates good practices in SQL and function usage, the lack of authentication on AJAX endpoints and insufficient output escaping present immediate and exploitable security risks. The absence of capability checks also contributes to a weakened security posture. Addressing these specific findings is crucial for improving the plugin's security.
Key Concerns
- Unprotected AJAX handlers
- Insufficient output escaping
- Missing nonce checks on AJAX
- Missing capability checks
Disqus Latest Comments Addon Security Vulnerabilities
Disqus Latest Comments Addon Code Analysis
Output Escaping
Data Flow Analysis
Disqus Latest Comments Addon Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
Disqus Latest Comments Addon Maintenance & Trust
Maintenance Signals
Community Trust
Disqus Latest Comments Addon Alternatives
Recent Posts Shortcode & Widget
recent-posts-shortcode-widget
Display list of recent posts and latest posts or random posts using the [recentposts-sc] shortcode in any page or in sidebar widgets.
Recent Comments
recent-comments-plugin
Displays a list of recent comments.
Recent Comments Widget with Comment Excerpts
recent-comments-widget-with-comment-excerpts
Changes the behavior of the built-in Recent Comments widget to display comment excerpts instead of post titles
Init Recent Comments – Templated, Modern, Minimal
init-recent-comments
Display recent comments with customizable templates and clean CSS. Lightweight, flexible, and built for modern WordPress sites.
Disqus Recent Comments Widget Advanced
disqus-recent-comments-widget-advanced
This plugin will add a recent comments widget for Disqus, to your WordPress site. The widget will not impact your site loading time, as all the querie …
Disqus Latest Comments Addon Developer Profile
2 plugins · 5K total installs
How We Detect Disqus Latest Comments Addon
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/disqus-latest-comments-addon/js/jquery.waypoints.min.js/wp-content/plugins/disqus-latest-comments-addon/js/infinite-scroll.min.js/wp-content/plugins/disqus-latest-comments-addon/js/itsg-disqus-latest-comments.js/wp-content/plugins/disqus-latest-comments-addon/css/style.css/wp-content/plugins/disqus-latest-comments-addon/js/jquery.waypoints.min.js/wp-content/plugins/disqus-latest-comments-addon/js/infinite-scroll.min.js/wp-content/plugins/disqus-latest-comments-addon/js/itsg-disqus-latest-comments.jsdisqus-latest-comments-addon/js/jquery.waypoints.min.js?ver=disqus-latest-comments-addon/js/infinite-scroll.min.js?ver=disqus-latest-comments-addon/js/itsg-disqus-latest-comments.js?ver=disqus-latest-comments-addon/css/style.css?ver=HTML / DOM Fingerprints
itsg-disqus-latest-comments<!-- IF THE USER HASNT SET THE SETTINGS --><!-- IF THE USER HASNT SET THE SETTINGS --><!-- IF THE USER HASNT SET THE SETTINGS --><!-- IF THE USER HASNT SET THE SETTINGS -->+35 moredata-forum-namedata-api-keydata-cache-timedata-bypass-cachedata-target-blankdata-hide-avatars+5 moreitsg_disqus_latest_comments_ajax_object/wp-json/disqus-latest-comments/v1/settings<div class="itsg-disqus-latest-comments"