
Last comments VK widget Security & Risk Analysis
wordpress.org/plugins/last-comments-vk-widgetWidget last comments VK
Is Last comments VK widget Safe to Use in 2026?
Generally Safe
Score 85/100Last comments VK widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'last-comments-vk-widget' v1.3 plugin exhibits a generally positive security posture based on the provided static analysis. There are no identified dangerous functions, raw SQL queries, file operations, or external HTTP requests, which are common sources of vulnerabilities. The absence of any known CVEs in its history further suggests a history of secure development or effective patching. However, a significant concern is the extremely low percentage of properly escaped output (8%). This indicates a high likelihood of cross-site scripting (XSS) vulnerabilities, as user-supplied data is likely being rendered directly to the browser without sufficient sanitization. The lack of any identified attack surface points (AJAX handlers, REST API routes, shortcodes, cron events) is unusual and could suggest the plugin is very simple or that the analysis might have missed potential entry points. Despite the lack of direct evidence of malicious code flows from taint analysis, the output escaping issue presents a clear and actionable risk.
Key Concerns
- Low percentage of properly escaped output
Last comments VK widget Security Vulnerabilities
Last comments VK widget Code Analysis
Output Escaping
Last comments VK widget Attack Surface
WordPress Hooks 5
Maintenance & Trust
Last comments VK widget Maintenance & Trust
Maintenance Signals
Community Trust
Last comments VK widget Alternatives
Import Vk Comments
import-vk-comments
Плагин импортирует комментарии из виджета комментариев ВК в WordPress.
Remove noreferrer
remove-noreferrer
"Remove noreferrer" automatically removes rel="noreferrer" attribute from links on your website on-the-fly.
Better Recent Comments
better-recent-comments
Provides an improved Recent Comments widget and a shortcode to display your recent comments on any post or page.
Recent Comments Widget Plus
comments-widget-plus
Provides custom recent comments widget with extra features such as display avatar, comment excerpt and much more!
Social Comments by Heateor
heateor-social-comments
Integrate Facebook Comments, Vkontakte Comments and/or Disqus Comments along with default comment form at your website
Last comments VK widget Developer Profile
4 plugins · 190 total installs
How We Detect Last comments VK widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/last-comments-vk-widget/lang///vk.com/js/api/openapi.jsHTML / DOM Fingerprints
widefatlcw_widgetid="container-VK.initVK.Widgets.CommentsBrowse