
Google+ Comments Security & Risk Analysis
wordpress.org/plugins/google-plus-commentsThe Google+ Comments WordPress plugin makes it easier for you to setup, administer and customise Google+ comments from your WordPress site.
Is Google+ Comments Safe to Use in 2026?
Use With Caution
Score 63/100Google+ Comments has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The `google-plus-comments` plugin v1.0 exhibits a mixed security posture. While it demonstrates good practices such as avoiding dangerous functions, using prepared statements for all SQL queries, and having no direct file operations or external HTTP requests, significant concerns remain. The plugin has a known vulnerability history with one unpatched medium severity CVE related to Cross-Site Scripting (XSS), which is a significant risk. The static analysis shows a low output escaping rate (17%), indicating a potential for XSS vulnerabilities in the 83% of outputs that are not properly escaped. Furthermore, the absence of nonce checks and capability checks on its single shortcode entry point is concerning, as this could allow for unauthorized actions or content injection if the shortcode's functionality is not inherently safe. The lack of taint analysis results is not necessarily positive, as it could indicate the analysis tool was unable to perform a thorough examination or that the plugin's code structure made it difficult to analyze for such vulnerabilities.
Key Concerns
- Unpatched CVE exists
- Low rate of proper output escaping
- Missing nonce checks
- Missing capability checks
Google+ Comments Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Google+ Comments <= 1.0 - Authenticated (Administrator+) Stored Cross-Site Scripting
Google+ Comments Code Analysis
Output Escaping
Google+ Comments Attack Surface
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
Google+ Comments Maintenance & Trust
Maintenance Signals
Community Trust
Google+ Comments Alternatives
Social Comments by Heateor
heateor-social-comments
Integrate Facebook Comments, Vkontakte Comments and/or Disqus Comments along with default comment form at your website
Social Comments
social-comments
This plugin adds Google Plus Comments system, Facebook comments and / or Disqus Comments to your site.
GP – GeePress
gp
All the tools you need to integrate your WordPress and Google+.
VCP Events
vcp-events
Add a google plus comment stream next to a your livestream or video.
Fancy Comments WordPress
fancy-facebook-comments
Integrate Facebook Comments with your WordPress website easiest possible way
Google+ Comments Developer Profile
11 plugins · 4K total installs
How We Detect Google+ Comments
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
https://apis.google.com/js/plusone.jsHTML / DOM Fingerprints
<!-- Google+ Comments for WordPress: http://3doordigital.com/wordpress/plugins/google-plus-comments/ -->data-hrefdata-num-postsdata-widthdata-colorscheme<g:comments href="width="first_party_property="BLOGGER"view_type="FILTERED_POSTMOD"