
Disqus Recent Comments Widget Security & Risk Analysis
wordpress.org/plugins/disqus-recent-comments-widgetDisqus has dropped support for their recent comments widget. This plugin creates a configurable widget that will display your latest Disqus comments.
Is Disqus Recent Comments Widget Safe to Use in 2026?
Generally Safe
Score 85/100Disqus Recent Comments Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The disqus-recent-comments-widget plugin version 1.2 demonstrates a generally good security posture with a clean vulnerability history and no recorded CVEs. The static analysis reveals no identified attack surface through common entry points like AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, the code shows a commitment to secure coding practices with 100% of SQL queries using prepared statements and a capability check present.
However, there are areas for concern. The most significant is the low percentage of properly escaped output (22%). This indicates a high risk of cross-site scripting (XSS) vulnerabilities if user-supplied data or dynamic content is not adequately sanitized before being displayed to users. The presence of an external HTTP request, while not inherently a vulnerability, could be a vector for information leakage or denial-of-service if not handled securely. The absence of nonce checks and the limited capability checks on the few signals that are present also leave room for potential unauthorized actions if an attack surface were to be discovered.
Given the lack of historical vulnerabilities and the absence of critical static analysis findings like dangerous functions or unsanitized taint flows, the plugin appears relatively safe. Nevertheless, the significant number of unescaped outputs is a notable weakness that requires immediate attention to prevent potential XSS attacks. The overall security can be considered moderate, with strengths in SQL handling and attack surface reduction, but weaknesses in output sanitization.
Key Concerns
- Low output escaping percentage
- External HTTP request without clear sanitization
- Lack of nonce checks
Disqus Recent Comments Widget Security Vulnerabilities
Disqus Recent Comments Widget Code Analysis
Output Escaping
Disqus Recent Comments Widget Attack Surface
WordPress Hooks 5
Maintenance & Trust
Disqus Recent Comments Widget Maintenance & Trust
Maintenance Signals
Community Trust
Disqus Recent Comments Widget Alternatives
Most Popular Posts
most-popular-posts
This is a very simple widget that displays a link to the top commented posts on your blog.
Top Commentators Widget
top-commentators-widget
Adds a sidebar widget to show the top commentators in your WP site. Demo: http://demo.webgrrrl.net
EMI Calculator
os-emi-calculator
Use EMI calculator as shortcode in post content or widget area without editing your theme files
FF Tab Widget
ff-tab-widget
Display popular posts, recent posts, recent commets, and tags in an animated tabs in a single widget.
Disqus Recent Comments Widget Advanced
disqus-recent-comments-widget-advanced
This plugin will add a recent comments widget for Disqus, to your WordPress site. The widget will not impact your site loading time, as all the querie …
Disqus Recent Comments Widget Developer Profile
1 plugin · 100 total installs
How We Detect Disqus Recent Comments Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/disqus-recent-comments-widget/disqus-recent-comments-widget.phpHTML / DOM Fingerprints
disqus_recent_comments_widget_wrapperdisqus_rcw_comments_listid="disqus_rcw_title"