Disqus Notify Post/Page Author Security & Risk Analysis

wordpress.org/plugins/disqus-notify-content-author

If using Disqus, the authors of posts/pages do not get notified of comments if they're not Disqus moderators. This plugin fixes that.

80 active installs v1.2.1 PHP + WP 2.8+ Updated Feb 22, 2016
commentcommentsdisqusnotificationnotify
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Disqus Notify Post/Page Author Safe to Use in 2026?

Generally Safe

Score 85/100

Disqus Notify Post/Page Author has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The "disqus-notify-content-author" plugin v1.2.1 exhibits a strong security posture based on the provided static analysis. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events without proper authentication and capability checks significantly reduces the attack surface. Furthermore, the code adheres to good practices by exclusively using prepared statements for SQL queries, properly escaping all output, and performing at least one capability check. The absence of any reported vulnerabilities in its history, including critical or high severity ones, further reinforces its current secure state.

However, there are minor areas for consideration. The presence of file operations without explicit mention of sanitization or permission checks could theoretically pose a risk if not handled securely. While no critical taint flows were identified, a complete lack of taint analysis flows analyzed might indicate limited testing for certain complex injection vectors. The absence of nonce checks on any potential entry points, though currently zero, would be a significant concern if any were introduced without them. Overall, the plugin appears well-secured and has a clean vulnerability history, but a thorough review of its file operation handling and ensuring future introductions of entry points include appropriate security measures would be prudent.

Key Concerns

  • File operations without explicit security review
  • No taint analysis flows analyzed
  • No nonce checks present
Vulnerabilities
None known

Disqus Notify Post/Page Author Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Disqus Notify Post/Page Author Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
1 escaped
Nonce Checks
0
Capability Checks
1
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped1 total outputs
Attack Surface

Disqus Notify Post/Page Author Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionwp_insert_commentdisqus-notify-content-author.php:226
actionshow_user_profiledisqus-notify-content-author.php:229
actionedit_user_profiledisqus-notify-content-author.php:230
actionpersonal_options_updatedisqus-notify-content-author.php:231
actionedit_user_profile_updatedisqus-notify-content-author.php:232
filtercomment_notification_textdisqus-notify-content-author.php:235
Maintenance & Trust

Disqus Notify Post/Page Author Maintenance & Trust

Maintenance Signals

WordPress version tested4.4.34
Last updatedFeb 22, 2016
PHP min version
Downloads10K

Community Trust

Rating86/100
Number of ratings3
Active installs80
Developer Profile

Disqus Notify Post/Page Author Developer Profile

Janne Cederberg

1 plugin · 80 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Disqus Notify Post/Page Author

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
dnca__main
HTML Comments
Disqus Notify Post/Page AuthorSee no evil, hear no evil, speak no evilWordPress post types that comment notifications will trigger onMake admin-configurable in WordPress UI+21 more
Data Attributes
dnca_dont_notifydnca-post-type-postdnca-post-type-page
FAQ

Frequently Asked Questions about Disqus Notify Post/Page Author