
Import Vk Comments Security & Risk Analysis
wordpress.org/plugins/import-vk-commentsПлагин импортирует комментарии из виджета комментариев ВК в WordPress.
Is Import Vk Comments Safe to Use in 2026?
Generally Safe
Score 85/100Import Vk Comments has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "import-vk-comments" v1.0.0 plugin exhibits a mixed security posture. On the positive side, it has no known vulnerabilities (CVEs) and does not engage in dangerous function calls, file operations, or external HTTP requests. The absence of bundled libraries and the use of prepared statements for SQL queries are also good security practices. However, significant concerns arise from the attack surface analysis. The plugin exposes two AJAX handlers, both of which lack authentication checks, creating a direct pathway for unauthenticated attackers to interact with the plugin's functionality. Furthermore, there are no nonce checks implemented, which is a standard WordPress security measure to prevent CSRF attacks. While the taint analysis shows no immediate critical or high-severity issues, the lack of proper authentication on AJAX endpoints means that any sensitive operations performed by these handlers are inherently vulnerable to exploitation.
The vulnerability history is clean, which is a positive indicator, suggesting that the plugin developers have either been diligent or lucky. However, this does not mitigate the current risks identified in the code. The primary weakness lies in the unprotected AJAX endpoints, which represent a significant risk given the lack of any authorization or CSRF protection. Despite the lack of historical vulnerabilities, the current static analysis findings point to an urgent need for security improvements, particularly concerning access control for its entry points.
Key Concerns
- AJAX handlers without auth checks
- AJAX handlers without nonce checks
- Insufficient output escaping
Import Vk Comments Security Vulnerabilities
Import Vk Comments Code Analysis
Output Escaping
Import Vk Comments Attack Surface
AJAX Handlers 2
WordPress Hooks 7
Maintenance & Trust
Import Vk Comments Maintenance & Trust
Maintenance Signals
Community Trust
Import Vk Comments Alternatives
Social Comments by Heateor
heateor-social-comments
Integrate Facebook Comments, Vkontakte Comments and/or Disqus Comments along with default comment form at your website
VKontakte
vkontakte
The plugin adds a wide range of VKontakte functionality to your site.
Bologer VK Comments
bologer-vk-comments
Bologer VK Comments adds comment widget from VK.com for posts and pages with custom settings.
Last comments VK widget
last-comments-vk-widget
Widget last comments VK
Social Monster
social-features-for-wp
This plugin adds some social functionality to Wordpress. Such as FB comments, VK comments, share buttons etc.
Import Vk Comments Developer Profile
1 plugin · 20 total installs
How We Detect Import Vk Comments
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/import-vk-comments/css/import-vk-comments-admin.css/wp-content/plugins/import-vk-comments/js/import-vk-comments-admin.js/wp-content/plugins/import-vk-comments/js/loading-bar.jswp-content/plugins/import-vk-comments/js/import-vk-comments-admin.jswp-content/plugins/import-vk-comments/js/loading-bar.jsimport-vk-comments/css/import-vk-comments-admin.css?ver=import-vk-comments/js/import-vk-comments-admin.js?ver=import-vk-comments/js/loading-bar.js?ver=HTML / DOM Fingerprints
<!-- Admin page for Import Vk Comments -->data-plugin-name="import-vk-comments"import_vk_comments_settingsImportVkComments/wp-json/import-vk-comments/v1/settings