
Featured Comments Security & Risk Analysis
wordpress.org/plugins/feature-commentsLets the admin add "featured" or "buried" css class to selected comments. Handy to highlight comments that add value to your post.
Is Featured Comments Safe to Use in 2026?
Mostly Safe
Score 83/100Featured Comments is generally safe to use though it hasn't been updated recently. 2 past CVEs were resolved. Keep it updated.
The "feature-comments" plugin v1.2.6 presents a mixed security posture. On the positive side, the static analysis indicates a relatively small attack surface, with only one AJAX handler identified, and importantly, no unprotected entry points. The plugin also demonstrates good practices in several areas, including 100% of SQL queries using prepared statements, the absence of file operations or external HTTP requests, and a reasonable number of capability checks. However, several concerning findings warrant attention. The presence of the `create_function` dangerous function is a significant red flag, as it can be a source of arbitrary code execution vulnerabilities if not handled with extreme care. Furthermore, the output escaping is only 43% properly done, meaning a substantial portion of output is not being sanitized, which could lead to Cross-Site Scripting (XSS) vulnerabilities. The vulnerability history reveals two High severity CVEs, both of which were related to Cross-Site Request Forgery (CSRF). While there are currently no unpatched vulnerabilities, the past occurrence of High severity issues, particularly CSRF, suggests a history of potential weaknesses in how user actions are validated. In conclusion, while the plugin has strengths in its limited attack surface and prepared SQL statements, the presence of a dangerous function and significant unescaped output, coupled with a history of high-severity CSRF vulnerabilities, indicates a need for careful review and potential remediation.
Key Concerns
- Dangerous function used (create_function)
- Low percentage of properly escaped output
- Past High severity CVEs (2 total)
- Vulnerability history indicates CSRF
Featured Comments Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Featured Comments < 1.2.5 - Cross-Site Request Forgery
Featured Comments < 1.2.5 - Cross-Site Request Forgery
Featured Comments Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Featured Comments Attack Surface
AJAX Handlers 1
WordPress Hooks 10
Maintenance & Trust
Featured Comments Maintenance & Trust
Maintenance Signals
Community Trust
Featured Comments Alternatives
Akismet Anti-spam: Spam Protection
akismet
The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam solution for WordPress and WooCommerce.
Disable Comments – Remove Comments & Stop Spam [Multi-Site Support]
disable-comments
Allows administrators to globally disable comments on their site. Comments can be disabled according to post type. Multisite friendly.
Antispam Bee
antispam-bee
Sophisticated antispam plugin for effective daily comment and trackback spam-fighting. Built with data protection and privacy in mind.
Spam protection, Honeypot, Anti-Spam by CleanTalk
cleantalk-spam-protect
Blocks spam comments, fake users, contact form spam and more. No impact on SEO. Privacy focused. CAPTCHA free, premium Antispam plugin.
Captcha Code
captcha-code-authentication
GDPR compatible captcha anti-spam protection for login form, comments form, registration form & lost password form. Eliminate spam with captcha.
Featured Comments Developer Profile
94 plugins · 23.5M total installs
How We Detect Featured Comments
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/feature-comments/widget.php/wp-content/plugins/feature-comments/feature-comments.js/wp-content/plugins/feature-comments/feature-comments.jsfeature-comments/feature-comments.js?ver=HTML / DOM Fingerprints
feature-commentsunfeatureunburyfeaturedburiedfeatureburydata-comment_iddata-dodata-noncefeatured_comments