Comment and Pingback Blocker by Himel Security & Risk Analysis

wordpress.org/plugins/himel-comment-pingback-blocker

A simple and lightweight plugin to completely disable comments, pingbacks, and trackbacks across your WordPress site.

0 active installs v1.0.1 PHP + WP 5.0+ Updated Apr 14, 2026
disable-commentsdisable-pingbacksdisable-trackbacksno-comments
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Comment and Pingback Blocker by Himel Safe to Use in 2026?

Generally Safe

Score 100/100

Comment and Pingback Blocker by Himel has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The plugin 'himel-comment-pingback-blocker' version 1.0.1 exhibits a strong security posture based on the provided static analysis. The absence of any detected AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the potential attack surface. Furthermore, the code analysis reveals a clean bill of health with no dangerous functions, 100% usage of prepared statements for SQL queries, and all output being properly escaped. The plugin also avoids file operations and external HTTP requests, and importantly, lacks any critical or high severity taint flows. Its vulnerability history is also clean, with no recorded CVEs, indicating a history of secure development or a lack of past exploitation. The plugin's strengths lie in its minimal attack surface and its adherence to secure coding practices for data handling and output. The main weakness, if it can be called that, is the complete absence of capability checks and nonce checks. While this is not a direct security flaw given the lack of exposed entry points, it represents an opportunity for improvement should the plugin's functionality expand in the future to include user-interactive features.

Key Concerns

  • Missing capability checks
  • Missing nonce checks
Vulnerabilities
None known

Comment and Pingback Blocker by Himel Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Comment and Pingback Blocker by Himel Release Timeline

v1.0.1Current
v1.0.0
Code Analysis
Analyzed Apr 16, 2026

Comment and Pingback Blocker by Himel Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Comment and Pingback Blocker by Himel Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actionadmin_inithimel-comment-pingback-blocker.php:29
filtercomments_openhimel-comment-pingback-blocker.php:38
filterpings_openhimel-comment-pingback-blocker.php:39
filtercomments_arrayhimel-comment-pingback-blocker.php:48
actionadmin_menuhimel-comment-pingback-blocker.php:57
actionadmin_inithimel-comment-pingback-blocker.php:71
actioninithimel-comment-pingback-blocker.php:82
filterrest_endpointshimel-comment-pingback-blocker.php:97
actionpre_pinghimel-comment-pingback-blocker.php:110
filterxmlrpc_methodshimel-comment-pingback-blocker.php:115
Maintenance & Trust

Comment and Pingback Blocker by Himel Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedApr 14, 2026
PHP min version
Downloads68

Community Trust

Rating100/100
Number of ratings2
Active installs0
Developer Profile

Comment and Pingback Blocker by Himel Developer Profile

Himel Ahmed

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Comment and Pingback Blocker by Himel

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

REST Endpoints
/wp/v2/comments/wp/v2/comments/(?P<id>[\d]+)
FAQ

Frequently Asked Questions about Comment and Pingback Blocker by Himel