
Do Not Allow Comments Everywhere Security & Risk Analysis
wordpress.org/plugins/do-not-allow-comments-everywhereA lightweight plugin that globally disables comments and pings across all WordPress content - past and future.
Is Do Not Allow Comments Everywhere Safe to Use in 2026?
Generally Safe
Score 100/100Do Not Allow Comments Everywhere has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "do-not-allow-comments-everywhere" plugin, version 1.0.1, exhibits a strong security posture in its static analysis. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events, particularly those without authentication or permission checks, indicates a minimal attack surface. Furthermore, the plugin demonstrates good coding practices by utilizing prepared statements for all SQL queries and includes a nonce check and a capability check, suggesting an effort to prevent common vulnerabilities. The lack of recorded vulnerabilities in its history, including critical and high severities, further reinforces its current secure state.
Despite these positive indicators, the output escaping mechanism shows a potential area for concern. With only 25% of its outputs properly escaped, there's a risk of cross-site scripting (XSS) vulnerabilities if any of the unescaped outputs are rendered in the user's browser and contain malicious input. However, the analysis does not indicate any taint flows or dangerous functions being used, which mitigates this risk to some extent. The absence of external HTTP requests and file operations also reduces the potential for remote code execution or data leakage. Overall, the plugin is well-secured against common attack vectors, with the primary, albeit minor, concern being the partial unescaped output.
Key Concerns
- 25% of outputs are not properly escaped
Do Not Allow Comments Everywhere Security Vulnerabilities
Do Not Allow Comments Everywhere Code Analysis
SQL Query Safety
Output Escaping
Do Not Allow Comments Everywhere Attack Surface
WordPress Hooks 9
Maintenance & Trust
Do Not Allow Comments Everywhere Maintenance & Trust
Maintenance Signals
Community Trust
Do Not Allow Comments Everywhere Alternatives
PowerUp – Admin Tools (Login/Logout Redirects, Scripts & Comments Control)
powerup
Simplify site management with Login/Logout Redirect, Hide Admin Bar, Disable Comments, Header Footer Scripts and Remove Footer Credit.
Comment Moderation Highlighter
comment-moderation-highlighter
This plugin will highlight keywords you specify on the admin moderation page, making it easier to spot manual spam and/or troll comments.
WP Project Essentials
wp-project-essentials
An essential plugin for WordPress project.
Disable Comments – Remove Comments & Stop Spam [Multi-Site Support]
disable-comments
Allows administrators to globally disable comments on their site. Comments can be disabled according to post type. Multisite friendly.
Disable Comments
disable-comments-rb
Disable Comments - easy tool to disable comments for your blog posts, and pages. Admin can disable comments in just a few clicks.
Do Not Allow Comments Everywhere Developer Profile
1 plugin · 60 total installs
How We Detect Do Not Allow Comments Everywhere
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
wrapbuttonbutton-primaryname="npctwp_toggle"value="1"type="submit"name="npctwp_nonce"value="1"