
Extended Recent Comments Security & Risk Analysis
wordpress.org/plugins/extended-recent-commentsAdd a recent comments widget that shows Gravatars.
Is Extended Recent Comments Safe to Use in 2026?
Generally Safe
Score 85/100Extended Recent Comments has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of "extended-recent-comments" v1.2 shows a positive security posture with no identified attack surface entry points and no dangerous functions or SQL queries without prepared statements. The absence of any recorded vulnerabilities in its history further suggests a generally secure development approach.
However, a significant concern is the very low percentage of properly escaped output (22%). This indicates a high likelihood of cross-site scripting (XSS) vulnerabilities, as user-supplied data might be rendered directly in the browser without sufficient sanitization. The lack of nonce checks and capability checks, while not directly indicating a vulnerability in the absence of exploitable entry points, means that if an entry point were discovered or introduced, protections against common attacks would be missing. The absence of taint analysis results might be due to the limited analysis scope or simply the plugin's simplicity, but it doesn't negate the output escaping issue.
In conclusion, while the plugin exhibits strengths in avoiding common pitfalls like raw SQL and a large attack surface, the critical weakness in output escaping presents a substantial risk. The vulnerability history is encouraging, but the code analysis reveals a clear area for immediate improvement to prevent potential XSS attacks.
Key Concerns
- Low output escaping percentage
- Missing nonce checks
- Missing capability checks
Extended Recent Comments Security Vulnerabilities
Extended Recent Comments Code Analysis
Output Escaping
Extended Recent Comments Attack Surface
WordPress Hooks 4
Maintenance & Trust
Extended Recent Comments Maintenance & Trust
Maintenance Signals
Community Trust
Extended Recent Comments Alternatives
Recent Comments Widget Plus
comments-widget-plus
Provides custom recent comments widget with extra features such as display avatar, comment excerpt and much more!
Better WordPress Recent Comments
bwp-recent-comments
This plugin displays recent comment lists at assigned locations, with comprehensive support for widgets.
Customized Recent Comments
customized-recent-comments
Display recent comments on your blog with complete control over the layout and format of comments.
Advanced Comments Widget
advanced-comments-widget
A highly customizable recent comments widget with avatars and excerpts.
Init Recent Comments – Templated, Modern, Minimal
init-recent-comments
Display recent comments with customizable templates and clean CSS. Lightweight, flexible, and built for modern WordPress sites.
Extended Recent Comments Developer Profile
7 plugins · 8K total installs
How We Detect Extended Recent Comments
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
widget_ercerc-commentid="erc"