Delete All Comments in One Click for Free With / Without Hyperlink Option Security & Risk Analysis

wordpress.org/plugins/free-bulk-delete-all-comments-with-without-hyperlink

A professional plugin to delete all comments from blog posts with options to preserve or remove hyperlinks.

10 active installs v2.1 PHP 7.0+ WP 4.7+ Updated Feb 21, 2025
bulk-deletecomment-managementcommentsdelete-comments
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Delete All Comments in One Click for Free With / Without Hyperlink Option Safe to Use in 2026?

Generally Safe

Score 92/100

Delete All Comments in One Click for Free With / Without Hyperlink Option has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The security posture of the "free-bulk-delete-all-comments-with-without-hyperlink" plugin version 2.1 appears to be relatively strong based on the provided static analysis. There are no identified direct attack vectors such as unprotected AJAX handlers, REST API routes, or shortcodes. The absence of dangerous functions, file operations, and external HTTP requests further contributes to a lower immediate risk profile. Furthermore, the plugin demonstrates some good security practices by including a nonce check and a capability check, indicating an awareness of common WordPress security vulnerabilities.

However, the static analysis does reveal significant areas of concern regarding data handling. The plugin utilizes three SQL queries, none of which employ prepared statements, indicating a high risk of SQL injection vulnerabilities. Additionally, the single identified output is not properly escaped, posing a risk of Cross-Site Scripting (XSS) attacks. The taint analysis results are inconclusive due to zero flows being analyzed, which is itself a weakness as it means potential vulnerabilities in data handling might have been missed.

The plugin's vulnerability history is clean, with zero known CVEs. This is a positive indicator, suggesting that the plugin has either been well-maintained or has not been a significant target for attackers. However, the lack of historical data doesn't negate the risks identified in the current static analysis. In conclusion, while the plugin avoids common attack surface vulnerabilities and has a clean history, the unescaped output and, more critically, the raw SQL queries without prepared statements present substantial security risks that require immediate attention.

Key Concerns

  • SQL queries without prepared statements
  • Output not properly escaped
  • No taint analysis flows analyzed
Vulnerabilities
None known

Delete All Comments in One Click for Free With / Without Hyperlink Option Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Delete All Comments in One Click for Free With / Without Hyperlink Option Code Analysis

Dangerous Functions
0
Raw SQL Queries
3
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared3 total queries

Output Escaping

0% escaped1 total outputs
Attack Surface

Delete All Comments in One Click for Free With / Without Hyperlink Option Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_menudelete-all-comments-in-one-click.php:25
actionadmin_post_delete_all_commentsdelete-all-comments-in-one-click.php:26
actionadmin_enqueue_scriptsdelete-all-comments-in-one-click.php:27
Maintenance & Trust

Delete All Comments in One Click for Free With / Without Hyperlink Option Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedFeb 21, 2025
PHP min version7.0
Downloads1K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Delete All Comments in One Click for Free With / Without Hyperlink Option Developer Profile

Sourabh Nagori

5 plugins · 180 total installs

91
trust score
Avg Security Score
95/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Delete All Comments in One Click for Free With / Without Hyperlink Option

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/free-bulk-delete-all-comments-with-without-hyperlink/admin-style.css

HTML / DOM Fingerprints

CSS Classes
enhanced-delete-commentscreditssocial-linkssocial-iconsocial-icon-linkedinsocial-icon-instagramdeveloper-name
HTML Comments
Warning: This action is irreversible. Please backup your database before proceeding.
Data Attributes
name="delete_option"value="with_links"value="without_links"
FAQ

Frequently Asked Questions about Delete All Comments in One Click for Free With / Without Hyperlink Option