
Download Post Comments Security & Risk Analysis
wordpress.org/plugins/download-post-commentsThis plugin adds a link to the "Edit Posts" view that will allow you to download a CSV of all comments for that particular post.
Is Download Post Comments Safe to Use in 2026?
Generally Safe
Score 85/100Download Post Comments has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'download-post-comments' plugin version 1.1 exhibits a generally strong security posture with no known CVEs and all detected SQL queries utilizing prepared statements. The absence of critical or high-severity taint flows, along with no file operations or external HTTP requests, further contributes to its apparent safety. The code also includes capability checks, which is a positive security practice.
However, a significant concern arises from the complete lack of output escaping for the two identified output points. This represents a direct vulnerability to cross-site scripting (XSS) attacks, where malicious scripts could be injected and executed in the user's browser. Furthermore, the absence of nonce checks on any of its entry points (though there are zero entry points reported in this analysis) is a missed opportunity for an additional layer of security against CSRF attacks if entry points were to be added or discovered later.
While the plugin's vulnerability history is clean, indicating good development practices over time, the identified output escaping issue is a critical oversight in the current version. The lack of any reported attack surface in the static analysis could be a strength or a sign of limited functionality. The overall security is undermined by the unescaped output, making it a moderate risk.
Key Concerns
- Unescaped output detected
- Missing nonce checks on entry points
Download Post Comments Security Vulnerabilities
Download Post Comments Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Download Post Comments Attack Surface
WordPress Hooks 2
Maintenance & Trust
Download Post Comments Maintenance & Trust
Maintenance Signals
Community Trust
Download Post Comments Alternatives
No Page Comment
no-page-comment
An admin interface to control the default comment and trackback settings on new posts, pages and custom post types.
No External Links
mihdan-no-external-links
Convert external links into internal links, site wide or post/page specific. Add NoFollow, Click logging, and more...
news ticker benaceur
news-ticker-benaceur
This plugin allow you to display the latest posts or latest comments in a bar with twenty seven beautiful animations and effects...
Bulk Post Importer
bulk-post-importer
Import posts and custom post types from JSON and CSV files with intelligent field mapping for WordPress fields, ACF, and custom meta.
Disable Feeds and Comments
disable-rss-feeds-and-comments
This WordPress plugin, "Disable RSS Feeds and Comments," gives you the ability to turn off both the RSS feeds and comments on pages and/or p …
Download Post Comments Developer Profile
2 plugins · 20 total installs
How We Detect Download Post Comments
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/download-post-comments/images/arrowicon.gif/wp-content/plugins/download-post-comments/images/downloadcomments-icon.gif