Social Comments by Heateor Security & Risk Analysis

wordpress.org/plugins/heateor-social-comments

Integrate Facebook Comments, Vkontakte Comments and/or Disqus Comments along with default comment form at your website

800 active installs v1.6.3 PHP + WP 2.5.0+ Updated Sep 12, 2025
disqus-commentsfacebook-commentsgoogle-commentsvkontakte-commentingvkontakte-comments
100
A · Safe
CVEs total1
Unpatched0
Last CVEJan 20, 2023
Safety Verdict

Is Social Comments by Heateor Safe to Use in 2026?

Generally Safe

Score 100/100

Social Comments by Heateor has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jan 20, 2023Updated 6mo ago
Risk Assessment

The "heateor-social-comments" plugin v1.6.3 presents a mixed security posture. While it has no known unpatched vulnerabilities, the static analysis reveals concerning weaknesses. A significant attack surface exists with 2 AJAX handlers, both of which lack authentication checks. This means any unauthenticated user could potentially trigger these handlers. Furthermore, a very low percentage (6%) of output is properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities, which is consistent with its past vulnerability history of improper neutralization of input. The complete absence of taint analysis flows for this version makes it difficult to assess direct data manipulation risks, but the identified entry points and poor output sanitization are substantial red flags.

Key Concerns

  • Unprotected AJAX handlers
  • Low output escaping percentage
  • Raw SQL queries without prepared statements
  • Past XSS vulnerability
Vulnerabilities
1

Social Comments by Heateor Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2023-23977medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

WordPress Social Comments Plugin for Vkontakte Comments and Disqus Comments <= 1.6.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

Jan 20, 2023 Patched in 1.6.2 (368d)
Code Analysis
Analyzed Mar 16, 2026

Social Comments by Heateor Code Analysis

Dangerous Functions
0
Raw SQL Queries
4
0 prepared
Unescaped Output
60
4 escaped
Nonce Checks
1
Capability Checks
4
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

0% prepared4 total queries

Output Escaping

6% escaped64 total outputs
Attack Surface
2 unprotected

Social Comments by Heateor Attack Surface

Entry Points3
Unprotected2

AJAX Handlers 2

authwp_ajax_heateor_sc_plugin_notification_readheateor-social-comments.php:570
authwp_ajax_heateor_sc_gdpr_notification_readheateor-social-comments.php:632

Shortcodes 1

[Heateor-SC] inc\shortcode.php:76
WordPress Hooks 11
actionwp_enqueue_scriptsheateor-social-comments.php:25
filtercomments_templateheateor-social-comments.php:28
actioninitheateor-social-comments.php:32
actionadmin_menuheateor-social-comments.php:318
actionsave_postheateor-social-comments.php:355
actionadmin_initheateor-social-comments.php:358
actionwpmu_new_blogheateor-social-comments.php:507
actionplugins_loadedheateor-social-comments.php:545
filterplugin_action_links_heateor-social-comments/heateor-social-comments.phpheateor-social-comments.php:561
actionadmin_noticesheateor-social-comments.php:623
actionadmin_noticesheateor-social-comments.php:664
Maintenance & Trust

Social Comments by Heateor Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 12, 2025
PHP min version
Downloads77K

Community Trust

Rating96/100
Number of ratings24
Active installs800
Developer Profile

Social Comments by Heateor Developer Profile

Heateor Support

6 plugins · 107K total installs

73
trust score
Avg Security Score
92/100
Avg Patch Time
174 days
View full developer profile
Detection Fingerprints

How We Detect Social Comments by Heateor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/heateor-social-comments/css/style.css/wp-content/plugins/heateor-social-comments/css/heateor-social-comments.css
Script Paths
/wp-content/plugins/heateor-social-comments/js/heateor-social-comments.js
Version Parameters
heateor-social-comments/css/style.css?ver=heateor-social-comments/css/heateor-social-comments.css?ver=heateor-social-comments/js/heateor-social-comments.js?ver=

HTML / DOM Fingerprints

CSS Classes
heateor_sc_social_commentsheateor_sc_comments_tabsheateor-sc-ui-tabs-activeheateor_sc_facebook_backgroundheateor_sc_facebook_svgheateor_sc_vkontakte_backgroundheateor_sc_vkontakte_svgheateor_sc_disqus_background+4 more
Data Attributes
id="heateor_sc_facebook_comments"id="heateor_sc_disqus_comments"id="heateor_sc_vkontakte_comments"id="heateor_sc_wordpress_comments"id="heateor_sc_facebook_comments_a"id="heateor_sc_disqus_comments_a"+3 more
JS Globals
heateor_sc_options
FAQ

Frequently Asked Questions about Social Comments by Heateor