Fancy Comments WordPress Security & Risk Analysis

wordpress.org/plugins/fancy-facebook-comments

Integrate Facebook Comments with your WordPress website easiest possible way

2K active installs v1.2.21 PHP + WP 2.5.0+ Updated Nov 9, 2025
facebook-commentingfacebook-commentssocial-commentingsocial-comments
99
A · Safe
CVEs total2
Unpatched0
Last CVEMar 25, 2024
Safety Verdict

Is Fancy Comments WordPress Safe to Use in 2026?

Generally Safe

Score 99/100

Fancy Comments WordPress has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Mar 25, 2024Updated 4mo ago
Risk Assessment

The "fancy-facebook-comments" plugin v1.2.21 presents a mixed security posture. While it boasts a low number of entry points and avoids dangerous functions and file operations, significant concerns arise from its handling of input and output. The plugin has an unprotected AJAX handler, which is a direct entry point for unauthenticated attackers. Furthermore, a stark 18% of output escaping indicates a high likelihood of cross-site scripting (XSS) vulnerabilities, especially given the plugin's history of medium severity XSS CVEs. The taint analysis, while showing no critical or high severity flows, did reveal flows with unsanitized paths, further supporting the XSS risk. The vulnerability history, with two medium-severity XSS issues and a recent one, suggests a pattern of input validation deficiencies. Despite a relatively small attack surface and good use of capability checks, the unprotected AJAX endpoint and widespread output escaping are critical weaknesses that require immediate attention. The plugin's past vulnerabilities and current code analysis point towards a significant risk of XSS attacks and potential unauthorized actions via the AJAX endpoint.

Key Concerns

  • Unprotected AJAX handler
  • Low percentage of properly escaped output
  • Taint flows with unsanitized paths
  • Past medium severity XSS vulnerabilities
Vulnerabilities
2

Fancy Comments WordPress Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2024-29804medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Fancy Comments WordPress <= 1.2.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

Mar 25, 2024 Patched in 1.2.15 (7d)
CVE-2023-23670medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

WordPress Fancy Comments <= 1.2.10 - Authenticated (Contributor+) Stored Cross Site Scripting via Shortcode

Feb 13, 2023 Patched in 1.2.11 (344d)
Code Analysis
Analyzed Mar 16, 2026

Fancy Comments WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
1 prepared
Unescaped Output
109
24 escaped
Nonce Checks
1
Capability Checks
4
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

50% prepared2 total queries

Output Escaping

18% escaped133 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

3 flows3 with unsanitized paths
render_facebook_comments (public\class-fancy-facebook-comments-public.php:91)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Fancy Comments WordPress Attack Surface

Entry Points2
Unprotected1

AJAX Handlers 1

authwp_ajax_heateor_ffc_gdpr_notification_readincludes\class-fancy-facebook-comments.php:129

Shortcodes 1

[Fancy_Facebook_Comments] includes\class-fancy-facebook-comments.php:218
WordPress Hooks 28
actionsave_postadmin\class-fancy-facebook-comments-admin.php:87
actionwpmu_new_blogfancy-facebook-comments.php:103
actionplugins_loadedincludes\class-fancy-facebook-comments.php:125
actionadmin_noticesincludes\class-fancy-facebook-comments.php:127
actionadmin_menuincludes\class-fancy-facebook-comments.php:131
actionbp_includeincludes\class-fancy-facebook-comments.php:133
actionadmin_initincludes\class-fancy-facebook-comments.php:135
actionwpmu_new_blogincludes\class-fancy-facebook-comments.php:139
actionupdate_option_heateor_ffcincludes\class-fancy-facebook-comments.php:141
filterplugin_action_links_fancy-facebook-comments/fancy-facebook-comments.phpincludes\class-fancy-facebook-comments.php:144
actioninitincludes\class-fancy-facebook-comments.php:160
actionwp_headincludes\class-fancy-facebook-comments.php:163
actionbp_activity_entry_metaincludes\class-fancy-facebook-comments.php:166
actionbp_before_group_headerincludes\class-fancy-facebook-comments.php:169
filterbbp_get_reply_contentincludes\class-fancy-facebook-comments.php:171
filterbbp_template_before_single_forumincludes\class-fancy-facebook-comments.php:172
filterbbp_template_before_single_topicincludes\class-fancy-facebook-comments.php:173
filterbbp_template_before_lead_topicincludes\class-fancy-facebook-comments.php:174
filterbbp_template_after_single_forumincludes\class-fancy-facebook-comments.php:175
filterbbp_template_after_single_topicincludes\class-fancy-facebook-comments.php:176
filterbbp_template_after_lead_topicincludes\class-fancy-facebook-comments.php:177
actionwoocommerce_after_shop_loop_itemincludes\class-fancy-facebook-comments.php:180
actionwoocommerce_shareincludes\class-fancy-facebook-comments.php:183
actionwoocommerce_thankyouincludes\class-fancy-facebook-comments.php:186
filterheateor_ffc_facebook_comments_target_urlincludes\class-fancy-facebook-comments.php:190
actionwidgets_initincludes\class-fancy-facebook-comments.php:203
filterthe_contentpublic\class-fancy-facebook-comments-public.php:68
filterthe_excerptpublic\class-fancy-facebook-comments-public.php:69
Maintenance & Trust

Fancy Comments WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 9, 2025
PHP min version
Downloads169K

Community Trust

Rating90/100
Number of ratings32
Active installs2K
Developer Profile

Fancy Comments WordPress Developer Profile

Heateor Support

6 plugins · 107K total installs

73
trust score
Avg Security Score
92/100
Avg Patch Time
174 days
View full developer profile
Detection Fingerprints

How We Detect Fancy Comments WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/fancy-facebook-comments/admin/css/admin-style.css/wp-content/plugins/fancy-facebook-comments/admin/js/admin-scripts.js/wp-content/plugins/fancy-facebook-comments/public/css/public-style.css/wp-content/plugins/fancy-facebook-comments/public/js/public-scripts.js
Script Paths
/wp-content/plugins/fancy-facebook-comments/admin/js/admin-scripts.js/wp-content/plugins/fancy-facebook-comments/public/js/public-scripts.js
Version Parameters
fancy-facebook-comments/admin/css/admin-style.css?ver=fancy-facebook-comments/admin/js/admin-scripts.js?ver=fancy-facebook-comments/public/css/public-style.css?ver=fancy-facebook-comments/public/js/public-scripts.js?ver=

HTML / DOM Fingerprints

CSS Classes
heateor_ffc_comments
HTML Comments
<!-- Fancy Facebook Comments Start --><!-- Fancy Facebook Comments End -->
Data Attributes
id="heateor_ffc"name="_heateor_ffc_meta[facebook_comments]"
JS Globals
heateor_ffc_global
FAQ

Frequently Asked Questions about Fancy Comments WordPress