
Hatena Bookmark Comment Security & Risk Analysis
wordpress.org/plugins/hatena-bookmark-commentDisplays hatena bookmark comments on entry by using HatenaBookmark Blogparts.
Is Hatena Bookmark Comment Safe to Use in 2026?
Generally Safe
Score 85/100Hatena Bookmark Comment has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "hatena-bookmark-comment" plugin version 0.2 exhibits a mixed security posture. On the positive side, the plugin demonstrates a commendable lack of critical vulnerabilities in its history, with no recorded CVEs. Furthermore, all SQL queries are properly prepared, and there are no file operations or external HTTP requests, which are common vectors for exploitation. However, significant concerns arise from the static code analysis. The presence of a dangerous function (preg_replace with the /e modifier) is a major red flag, as it can lead to arbitrary code execution if user input is not strictly controlled. Compounding this, 100% of the plugin's outputs are not properly escaped, presenting a high risk of cross-site scripting (XSS) vulnerabilities. The complete absence of nonce checks and capability checks, coupled with zero AJAX handlers or REST API routes that require authentication, indicates a very broad, unprotected attack surface, making any potential vulnerabilities much easier to exploit.
Key Concerns
- Dangerous function (preg_replace(/e)) detected
- 100% of outputs are not properly escaped
- 0 Nonce checks present
- 0 Capability checks present
- 0 unprotected AJAX handlers
- 0 unprotected REST API routes
Hatena Bookmark Comment Security Vulnerabilities
Hatena Bookmark Comment Code Analysis
Dangerous Functions Found
Output Escaping
Hatena Bookmark Comment Attack Surface
WordPress Hooks 4
Maintenance & Trust
Hatena Bookmark Comment Maintenance & Trust
Maintenance Signals
Community Trust
Hatena Bookmark Comment Alternatives
Hatena Bookmark AutoPost
hatena-bookmark-autopost
When you added new post, this plugin send email to Hatena bookmark.
Sharekoube
sharekoube
Add to Sharedaddy support service.
Social Bookmarking JP
social-bookmarking-jp
Embedding Japanese major social bookmark services hyper links and icons
dekabotann
dekabotann
"dekabotann" is a plugin providing big social button. Hatena, Twitter, Facebook, Google+. Especially, this plugin is optimized for Japanese.
Akismet Anti-spam: Spam Protection
akismet
The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam solution for WordPress and WooCommerce.
Hatena Bookmark Comment Developer Profile
3 plugins · 40 total installs
How We Detect Hatena Bookmark Comment
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/hatena-bookmark-comment/js/bookmark_blogparts.jshttp://b.hatena.ne.jp/js/bookmark_blogparts.jshatena-bookmark-comment/js/bookmark_blogparts.js?ver=HTML / DOM Fingerprints
WPHatenaBookmarkComment