
GraphComment Comment system Security & Risk Analysis
wordpress.org/plugins/graphcomment-comment-systemTransform your site's engagement with GraphComment—an advanced, interactive commenting system featuring live discussions and real-time notifications.
Is GraphComment Comment system Safe to Use in 2026?
Generally Safe
Score 92/100GraphComment Comment system has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The graphcomment-comment-system plugin v4.0.3 exhibits a mixed security posture. On the positive side, it demonstrates excellent practices regarding SQL queries, with 100% utilizing prepared statements, and has no known historical vulnerabilities, suggesting a generally stable codebase. However, significant concerns arise from the static analysis. The plugin exposes two AJAX handlers without any authentication or capability checks, creating a substantial attack surface that could be leveraged by unauthenticated users. Furthermore, only 37% of output escaping is properly implemented, leaving a considerable portion of the output potentially vulnerable to cross-site scripting (XSS) attacks. The presence of one flow with unsanitized paths, though not classified as critical or high severity in the taint analysis, warrants attention as it indicates a potential for input manipulation.
The lack of any recorded CVEs and the absence of unpatched vulnerabilities are positive indicators of past maintenance and security awareness. However, this historical data cannot fully mitigate the risks identified in the current code. The absence of nonce checks and capability checks on AJAX endpoints is a critical oversight. While the taint analysis didn't flag high-severity issues, the combination of unprotected AJAX endpoints and insufficient output escaping presents a clear risk. The plugin has a total of 2 unprotected entry points, which is a significant concern.
Key Concerns
- AJAX handlers without authentication checks
- Insufficient output escaping (37% proper)
- Flow with unsanitized paths (taint analysis)
- No nonce checks on AJAX handlers
- No capability checks on AJAX handlers
GraphComment Comment system Security Vulnerabilities
GraphComment Comment system Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
GraphComment Comment system Attack Surface
AJAX Handlers 2
WordPress Hooks 12
Scheduled Events 4
Maintenance & Trust
GraphComment Comment system Maintenance & Trust
Maintenance Signals
Community Trust
GraphComment Comment system Alternatives
PhpSword Disable Comments
phpsword-disable-comments
Disable Comments from your WordPress website.
Advanced Comments Widget
advanced-comments-widget
A highly customizable recent comments widget with avatars and excerpts.
FastComments
fastcomments
A live, fast, privacy-focused commenting system with advanced spam prevention capabilities. FastComments prioritizes speed and user experience above a …
Featured Comment Widget
featured-comment-widget
The Featured Comment Widget gives you the ability to shine a spotlight on some of your favorite comments on the site.
BLOGCHAT Chat System
blogchat-chat-system
BLOGCHAT is a live comment and chat system.
GraphComment Comment system Developer Profile
1 plugin · 500 total installs
How We Detect GraphComment Comment system
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/graphcomment-comment-system/css/app.css/wp-content/plugins/graphcomment-comment-system/css/chunk-vendors.css/wp-content/plugins/graphcomment-comment-system/js/app.js/wp-content/plugins/graphcomment-comment-system/js/chunk-vendors.js/wp-content/plugins/graphcomment-comment-system/comments.phpgraphcomment-comment-system/css/app.css?ver=graphcomment-comment-system/css/chunk-vendors.css?ver=graphcomment-comment-system/js/app.js?ver=graphcomment-comment-system/js/chunk-vendors.js?ver=HTML / DOM Fingerprints
gc-comment-containergc-comment-listgc-comment-formgc-comment-wrapper<!-- graphcomment --><!-- End graphcomment -->data-gc-widget-iddata-gc-user-idwindow.graphcommentvar graphcommentSettings/wp-json/graphcomment/v1/comments/wp-json/graphcomment/v1/settings[graphcomment]