
Last Comments Without Links Security & Risk Analysis
wordpress.org/plugins/last-comments-without-linksThis plugin does default wordpress widget but without links. It is only shows name and comment.
Is Last Comments Without Links Safe to Use in 2026?
Generally Safe
Score 85/100Last Comments Without Links has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'last-comments-without-links' plugin v1.0 exhibits a generally good security posture with no known vulnerabilities or high-risk static analysis findings. The absence of any CVEs and the consistent use of prepared statements for SQL queries are strong indicators of responsible development. Furthermore, the plugin's minimal attack surface, with zero AJAX handlers, REST API routes, shortcodes, or cron events, significantly reduces the potential for external exploitation.
However, there are notable areas for improvement. The presence of the `create_function` dangerous function, although likely isolated and not directly exploitable in this context, is a deprecated and insecure practice. More concerning is the low rate of output escaping (33%), which could lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is displayed without proper sanitization. The lack of nonce and capability checks, while less critical given the limited attack surface, still represents a missed opportunity to further harden the plugin against potential CSRF or unauthorized access in the future, should its functionality expand.
In conclusion, 'last-comments-without-links' v1.0 is currently in a relatively secure state due to its limited functionality and good SQL practices. The primary risks stem from the use of `create_function` and the insufficient output escaping. Addressing these specific code-level concerns would elevate the plugin's security to an even higher standard.
Key Concerns
- Dangerous function used (create_function)
- Low percentage of properly escaped output
- Missing nonce checks
- Missing capability checks
Last Comments Without Links Security Vulnerabilities
Last Comments Without Links Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Last Comments Without Links Attack Surface
WordPress Hooks 1
Maintenance & Trust
Last Comments Without Links Maintenance & Trust
Maintenance Signals
Community Trust
Last Comments Without Links Alternatives
Remove noreferrer
remove-noreferrer
"Remove noreferrer" automatically removes rel="noreferrer" attribute from links on your website on-the-fly.
Better Recent Comments
better-recent-comments
Provides an improved Recent Comments widget and a shortcode to display your recent comments on any post or page.
Recent Comments Widget Plus
comments-widget-plus
Provides custom recent comments widget with extra features such as display avatar, comment excerpt and much more!
Better WordPress Recent Comments
bwp-recent-comments
This plugin displays recent comment lists at assigned locations, with comprehensive support for widgets.
GraphComment Comment system
graphcomment-comment-system
Transform your site's engagement with GraphComment—an advanced, interactive commenting system featuring live discussions and real-time notifications.
Last Comments Without Links Developer Profile
2 plugins · 140 total installs
How We Detect Last Comments Without Links
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
icerikler-sag-kutuyorumlar-widgetSinLastComments