
Extended Comments Widget Security & Risk Analysis
wordpress.org/plugins/extended-comments-widgetA widget that shows a section of comment text along with the author name.
Is Extended Comments Widget Safe to Use in 2026?
Generally Safe
Score 85/100Extended Comments Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "extended-comments-widget" plugin v0.1.1 demonstrates a strong security posture in several key areas. The absence of any known CVEs and a clean vulnerability history is a significant positive indicator. Furthermore, the code analysis reveals no dangerous functions, file operations, or external HTTP requests, which minimizes common attack vectors. Notably, all SQL queries are properly prepared, and there are no taint analysis findings, suggesting a robust defense against injection-type attacks. However, there are areas for improvement. The plugin has zero capability checks and zero nonce checks. While the current attack surface is reported as zero, relying solely on this without built-in checks means any future additions to the plugin, or shifts in WordPress's internal handling of entry points, could expose vulnerabilities without proper authorization and validation mechanisms. Additionally, only 40% of output is properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is displayed without adequate sanitization.
Key Concerns
- Missing nonce checks
- Missing capability checks
- Low percentage of properly escaped output
Extended Comments Widget Security Vulnerabilities
Extended Comments Widget Release Timeline
Extended Comments Widget Code Analysis
SQL Query Safety
Output Escaping
Extended Comments Widget Attack Surface
WordPress Hooks 2
Maintenance & Trust
Extended Comments Widget Maintenance & Trust
Maintenance Signals
Community Trust
Extended Comments Widget Alternatives
Remove noreferrer
remove-noreferrer
"Remove noreferrer" automatically removes rel="noreferrer" attribute from links on your website on-the-fly.
Better Recent Comments
better-recent-comments
Provides an improved Recent Comments widget and a shortcode to display your recent comments on any post or page.
Recent Comments Widget Plus
comments-widget-plus
Provides custom recent comments widget with extra features such as display avatar, comment excerpt and much more!
Better WordPress Recent Comments
bwp-recent-comments
This plugin displays recent comment lists at assigned locations, with comprehensive support for widgets.
GraphComment Comment system
graphcomment-comment-system
Transform your site's engagement with GraphComment—an advanced, interactive commenting system featuring live discussions and real-time notifications.
Extended Comments Widget Developer Profile
14 plugins · 2.2M total installs
How We Detect Extended Comments Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
widget_extended_comments