
DX Unanswered Comments Security & Risk Analysis
wordpress.org/plugins/dx-unanswered-commentsFilter your admin comments that have not received a reply by internal user yet.
Is DX Unanswered Comments Safe to Use in 2026?
Generally Safe
Score 100/100DX Unanswered Comments has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'dx-unanswered-comments' plugin version 1.7 presents a significant security risk primarily due to its unprotected AJAX handlers. While the plugin has no known historical vulnerabilities and avoids dangerous functions, file operations, and external HTTP requests, the complete absence of authentication and capability checks on all four identified AJAX entry points creates a wide attack surface. This means any unauthenticated user could potentially trigger these functions, leading to unintended actions or information disclosure if these handlers are not inherently benign. The taint analysis did find one flow with unsanitized paths, though it was not classified as critical or high severity, it still warrants attention. The lack of proper output escaping on a portion of outputs also adds to the risk of cross-site scripting (XSS) vulnerabilities. Overall, while the plugin demonstrates good practices in some areas like SQL query preparation, the lack of fundamental security checks on its AJAX endpoints is a major concern.
Key Concerns
- Unprotected AJAX handlers
- Flows with unsanitized paths (taint analysis)
- Unescaped output
- Missing nonce checks on AJAX
- Missing capability checks on AJAX
DX Unanswered Comments Security Vulnerabilities
DX Unanswered Comments Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
DX Unanswered Comments Attack Surface
AJAX Handlers 4
WordPress Hooks 11
Maintenance & Trust
DX Unanswered Comments Maintenance & Trust
Maintenance Signals
Community Trust
DX Unanswered Comments Alternatives
One Click Close Comments
one-click-close-comments
Conveniently close or open comments for a post or page with one click from the admin listing of posts.
Relative URL
relative-url
Relative URL applies wp_make_link_relative function to links to convert them to relative URLs.
Quotmarks Replacer
quotmarks-replacer
Quotmarks Replacer disables wptexturize function that keeps all quotation marks and suspension points in half-width form.
Nofollow Case by Case
nofollow-case-by-case
"Dofollow" but Nofollow Case by Case allows you to selectively apply nofollow to your comments as well.
PowerUp – Admin Tools (Login/Logout Redirects, Scripts & Comments Control)
powerup
Simplify site management with Login/Logout Redirect, Hide Admin Bar, Disable Comments, Header Footer Scripts and Remove Footer Credit.
DX Unanswered Comments Developer Profile
13 plugins · 5K total installs
How We Detect DX Unanswered Comments
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/dx-unanswered-comments/js/dxuc-script.js/wp-content/plugins/dx-unanswered-comments/js/dxuc-comments.js/wp-content/plugins/dx-unanswered-comments/css/dxuc-style.css/wp-content/plugins/dx-unanswered-comments/js/dxuc-script.js/wp-content/plugins/dx-unanswered-comments/js/dxuc-comments.jsdxuc-script.js?ver=dxuc-comments.js?ver=dxuc-style.css?ver=HTML / DOM Fingerprints
mark_as_non_repliedmark_as_replieddata-value