
Disqus Recent Comments Widget Advanced Security & Risk Analysis
wordpress.org/plugins/disqus-recent-comments-widget-advancedThis plugin will add a recent comments widget for Disqus, to your WordPress site. The widget will not impact your site loading time, as all the querie …
Is Disqus Recent Comments Widget Advanced Safe to Use in 2026?
Generally Safe
Score 85/100Disqus Recent Comments Widget Advanced has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of the "disqus-recent-comments-widget-advanced" plugin v1.5 reveals a mixed security posture. On the positive side, there are no recorded CVEs, a clean vulnerability history, and all SQL queries are properly prepared. Furthermore, the plugin exhibits a minimal attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events that are directly exposed. There are also no file operations or external HTTP requests, which reduces potential attack vectors.
However, several significant concerns are present. The plugin utilizes the `create_function` function, which is deprecated and can be a source of security vulnerabilities if not handled with extreme care due to its ability to execute arbitrary code. More critically, a substantial 100% of its output is not properly escaped. This is a severe deficiency that could lead to cross-site scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the user's browser when they interact with the plugin's output.
The absence of nonce checks and capability checks on all entry points, combined with the lack of proper output escaping, presents a considerable risk. While the attack surface is currently small, any future additions or the exploitation of these weaknesses could have serious security implications. The plugin's strengths lie in its SQL practices and lack of historical vulnerabilities, but these are overshadowed by the critical output escaping issue and the use of a dangerous function.
Key Concerns
- 100% of output not properly escaped
- Use of dangerous function: create_function
- No nonce checks
- No capability checks
Disqus Recent Comments Widget Advanced Security Vulnerabilities
Disqus Recent Comments Widget Advanced Code Analysis
Dangerous Functions Found
Output Escaping
Disqus Recent Comments Widget Advanced Attack Surface
WordPress Hooks 1
Maintenance & Trust
Disqus Recent Comments Widget Advanced Maintenance & Trust
Maintenance Signals
Community Trust
Disqus Recent Comments Widget Advanced Alternatives
Better WordPress Recent Comments
bwp-recent-comments
This plugin displays recent comment lists at assigned locations, with comprehensive support for widgets.
Customized Recent Comments
customized-recent-comments
Display recent comments on your blog with complete control over the layout and format of comments.
Recent Comments Widget with Excerpts
recent-comments-widget-with-excerpts
Duplicates the built-in Recent Comments widget and adds functionality to display comment excerpts instead of post titles
Classic Widgets
classic-widgets
Enables the previous "classic" widgets settings screens in Appearance - Widgets and the Customizer. Disables the block editor from managing widgets.
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor
elementskit-lite
Join millions who empower their websites with ElementsKit Elementor Addons. Get templates, & 100+ widgets like header-footer, mega menu, custom widget
Disqus Recent Comments Widget Advanced Developer Profile
1 plugin · 40 total installs
How We Detect Disqus Recent Comments Widget Advanced
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/disqus-recent-comments-widget-advanced/drcwa/drcw.css/wp-content/plugins/disqus-recent-comments-widget-advanced/drcwa/drcw2.csshttp://*.disqus.com/recent_comments_widget.jsHTML / DOM Fingerprints
tp_disqusrecentcomments dsq-widgetid="recentcomments"