
Hikari Enhanced Comments Security & Risk Analysis
wordpress.org/plugins/hikari-enhanced-commentsComments are enhanced with new features that make them more visible and becoming more exciting in website structure.
Is Hikari Enhanced Comments Safe to Use in 2026?
Generally Safe
Score 85/100Hikari Enhanced Comments has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "hikari-enhanced-comments" plugin, at version 0.03.05, exhibits a concerning security posture despite a clean vulnerability history. While the plugin has no recorded CVEs and a seemingly limited attack surface, the static analysis reveals significant weaknesses. A critical finding is that 100% of outputs are not properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. Furthermore, all four analyzed taint flows have unsanitized paths, although they are not classified as critical or high severity, this still suggests potential for data manipulation or leakage if these flows are ever exposed through an attack vector.
The complete lack of capability checks and nonce checks, coupled with the absence of authentication on any potential entry points (even though none are explicitly listed in the attack surface), is a major red flag. This implies that even if the plugin were to introduce new entry points or if an attacker found a way to trigger existing code paths indirectly, there would be no security checks in place to prevent unauthorized actions. The vulnerability history being completely clean might be due to the plugin's low adoption, recent development, or simply a lack of dedicated security auditing. However, the code signals strongly suggest that the plugin is not production-ready from a security perspective, particularly concerning XSS and the lack of fundamental security controls.
Key Concerns
- Output escaping: 100% outputs unescaped
- Taint flows with unsanitized paths (4/4)
- No nonce checks
- No capability checks
- SQL queries: 33% not using prepared statements
Hikari Enhanced Comments Security Vulnerabilities
Hikari Enhanced Comments Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Hikari Enhanced Comments Attack Surface
WordPress Hooks 11
Maintenance & Trust
Hikari Enhanced Comments Maintenance & Trust
Maintenance Signals
Community Trust
Hikari Enhanced Comments Alternatives
Hikari Titled Comments
hikari-title-comments
Hikari Titled Comments enables each comment to have a title, so that commentators can give a subject meaning to their comments.
Remove noreferrer
remove-noreferrer
"Remove noreferrer" automatically removes rel="noreferrer" attribute from links on your website on-the-fly.
Better Recent Comments
better-recent-comments
Provides an improved Recent Comments widget and a shortcode to display your recent comments on any post or page.
Recent Comments Widget Plus
comments-widget-plus
Provides custom recent comments widget with extra features such as display avatar, comment excerpt and much more!
Better WordPress Recent Comments
bwp-recent-comments
This plugin displays recent comment lists at assigned locations, with comprehensive support for widgets.
Hikari Enhanced Comments Developer Profile
6 plugins · 350 total installs
How We Detect Hikari Enhanced Comments
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/hikari-enhanced-comments/flags//wp-content/plugins/hikari-enhanced-comments/css/hikari-enhanced-comments.css/wp-content/plugins/hikari-enhanced-comments/js/hikari-enhanced-comments.jsHikari Enhanced Comments/wp-content/plugins/hikari-enhanced-comments/js/hikari-enhanced-comments.jshikari-enhanced-comments/css/hikari-enhanced-comments.css?ver=hikari-enhanced-comments/js/hikari-enhanced-comments.js?ver=HTML / DOM Fingerprints
comment-author-flagwidget_hikari_enhanced_recent_commentshkec-recentcomments-listhkec-recentcomments-itemavatar_contgravar_commentgravar_ping<!-- Enhanced Recent Comments provided by
Hikari Enhanced Comments - http://Hikari.ws -->data-hkec-optionhkEC