
Kento Top Commenters Security & Risk Analysis
wordpress.org/plugins/kento-top-commentersTop Commentators list By Count Comments
Is Kento Top Commenters Safe to Use in 2026?
Generally Safe
Score 85/100Kento Top Commenters has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'kento-top-commenters' v1.0 plugin presents a concerning security posture despite a clean vulnerability history. Static analysis reveals a complete lack of output escaping for all identified output points, meaning any user-supplied data outputted by the plugin could be vulnerable to cross-site scripting (XSS) attacks. Furthermore, all SQL queries are executed without prepared statements, creating a significant risk of SQL injection vulnerabilities. The presence of two taint analysis flows with unsanitized paths further amplifies these risks, indicating potential pathways for malicious data to be processed without proper sanitization. While the plugin has no recorded vulnerability history, this does not negate the severe weaknesses identified in its current implementation. The absence of any detected CVEs is a positive, but the code itself contains critical security flaws that require immediate attention.
Key Concerns
- 0% of outputs properly escaped
- 0% of SQL queries use prepared statements
- 2 flows with unsanitized paths (taint)
Kento Top Commenters Security Vulnerabilities
Kento Top Commenters Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Kento Top Commenters Attack Surface
WordPress Hooks 1
Maintenance & Trust
Kento Top Commenters Maintenance & Trust
Maintenance Signals
Community Trust
Kento Top Commenters Developer Profile
20 plugins · 600 total installs
How We Detect Kento Top Commenters
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/kento-top-commenters/css/style.csskento-top-commenters/css/style.css?ver=HTML / DOM Fingerprints
top_commenterstop_commenters-listtop-commenters-imagetop-commenters-namecommenters-countname="widgettitle"name="number"name="ktc_style"value="style1"value="style2"value="style3"