
Do Not Allow Comments Everywhere Security & Risk Analysis
wordpress.org/plugins/do-not-allow-comments-everywhereA lightweight plugin that globally disables comments and pings across all WordPress content - past and future.
Is Do Not Allow Comments Everywhere Safe to Use in 2026?
Generally Safe
Score 100/100Do Not Allow Comments Everywhere has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "do-not-allow-comments-everywhere" plugin, version 1.0.1, exhibits a strong security posture in its static analysis. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events, particularly those without authentication or permission checks, indicates a minimal attack surface. Furthermore, the plugin demonstrates good coding practices by utilizing prepared statements for all SQL queries and includes a nonce check and a capability check, suggesting an effort to prevent common vulnerabilities. The lack of recorded vulnerabilities in its history, including critical and high severities, further reinforces its current secure state.
Despite these positive indicators, the output escaping mechanism shows a potential area for concern. With only 25% of its outputs properly escaped, there's a risk of cross-site scripting (XSS) vulnerabilities if any of the unescaped outputs are rendered in the user's browser and contain malicious input. However, the analysis does not indicate any taint flows or dangerous functions being used, which mitigates this risk to some extent. The absence of external HTTP requests and file operations also reduces the potential for remote code execution or data leakage. Overall, the plugin is well-secured against common attack vectors, with the primary, albeit minor, concern being the partial unescaped output.
Key Concerns
- 25% of outputs are not properly escaped
Do Not Allow Comments Everywhere Security Vulnerabilities
Do Not Allow Comments Everywhere Release Timeline
Do Not Allow Comments Everywhere Code Analysis
SQL Query Safety
Output Escaping
Do Not Allow Comments Everywhere Attack Surface
WordPress Hooks 9
Maintenance & Trust
Do Not Allow Comments Everywhere Maintenance & Trust
Maintenance Signals
Community Trust
Do Not Allow Comments Everywhere Alternatives
PowerUp – Admin Tools (Login/Logout Redirects, Scripts & Comments Control)
powerup
Simplify site management with Login/Logout Redirect, Hide Admin Bar, Disable Comments, Header Footer Scripts and Remove Footer Credit.
Comment Moderation Highlighter
comment-moderation-highlighter
This plugin will highlight keywords you specify on the admin moderation page, making it easier to spot manual spam and/or troll comments.
Quiet Admin – Hide Admin Notices, Disable Comments, Clean Dashboard & More
quiet-admin
Hide admin notices, disable comments, remove dashboard widgets, customize the login page, and clean the admin bar — all from one plugin.
CommentOff
commentoff
Easily disable all comments on your WordPress site: hide the form, block existing comments, and remove comment elements from the admin panel.
WP Project Essentials
wp-project-essentials
An essential plugin for WordPress project.
Do Not Allow Comments Everywhere Developer Profile
1 plugin · 70 total installs
How We Detect Do Not Allow Comments Everywhere
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
wrapbuttonbutton-primaryname="npctwp_toggle"value="1"type="submit"name="npctwp_nonce"value="1"