
Lazy Social Comments Security & Risk Analysis
wordpress.org/plugins/lazy-facebook-commentsUse Facebook Comments with lazy loading feature. Load FB comments after button click or scroll down.
Is Lazy Social Comments Safe to Use in 2026?
Generally Safe
Score 85/100Lazy Social Comments has a strong security track record. Known vulnerabilities have been patched promptly.
The lazy-facebook-comments plugin, v2.0.5, exhibits a generally strong security posture based on the provided static analysis. There are no identified critical or high severity taint flows, no dangerous functions, and all SQL queries are properly prepared. File operations and external HTTP requests are also absent, reducing potential attack vectors. The high percentage of properly escaped output (81%) is a positive indicator of good development practices.
However, there are significant areas for concern. The complete absence of nonce checks and capability checks across all entry points is a major weakness. This means that any functionality exposed, even if not directly listed as an entry point in the static analysis, could be invoked by an unauthenticated or unauthorized user. The vulnerability history shows one medium severity CVE in the past, specifically related to Cross-site Scripting. While there are no currently unpatched vulnerabilities, the presence of past XSS issues combined with the lack of input validation mechanisms like nonces and capability checks suggests a potential for future vulnerabilities.
In conclusion, while the plugin demonstrates good practices in areas like SQL query preparation and output escaping, the fundamental lack of authentication and authorization checks on its potential entry points presents a significant security risk. The past XSS vulnerability further underscores the need for robust input validation and access control mechanisms to be implemented.
Key Concerns
- Missing nonce checks on entry points
- Missing capability checks on entry points
- Past medium severity XSS vulnerability
- 81% output escaping is good, but 19% is not
Lazy Social Comments Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Lazy Social Comments <= 2.0.4 - Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin Options
Lazy Social Comments Code Analysis
Output Escaping
Lazy Social Comments Attack Surface
WordPress Hooks 9
Maintenance & Trust
Lazy Social Comments Maintenance & Trust
Maintenance Signals
Community Trust
Lazy Social Comments Alternatives
Future Aim Social Comments
future-aim-social-comment-system
Use Facebook Comments with lazy loading feature. Load FB comments after button click or scroll down.
Social Share, Social Login and Social Comments Plugin – Super Socializer
super-socializer
The unique Social Plugin to let you integrate Social Login, Social Share, Social Comments and Social Media follow at your website
Social comments by WpDevArt
comments-from-facebook
This plugin will help you display Facebook Comments on your website. You can use it on your pages/posts.
Fancy Comments WordPress
fancy-facebook-comments
Integrate Facebook Comments with your WordPress website easiest possible way
Lazy Load for Comments
lazy-load-for-comments
Lazy load default WordPress commenting system on scroll or click. Improve page speed.
Lazy Social Comments Developer Profile
7 plugins · 117K total installs
How We Detect Lazy Social Comments
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/lazy-facebook-comments/admin/css/min/admin.css/wp-content/plugins/lazy-facebook-comments/public/css/frontend.css/wp-content/plugins/lazy-facebook-comments/public/js/frontend.js/wp-content/plugins/lazy-facebook-comments/public/js/frontend.jslazy-facebook-comments/admin/css/min/admin.css?ver=lazy-facebook-comments/public/css/frontend.css?ver=lazy-facebook-comments/public/js/frontend.js?ver=HTML / DOM Fingerprints
lfc-load-more-btnlfc-hiddenlfc-lazy-comment-wrap<!-- Thank you for your interest in Lazy FB Comments - Developed and managed by Joel James --><!-- LFC: Load comments by clicking on the button --><!-- LFC: Load comments by scrolling down the page --><!-- LFC: To avoid header already sent issue+1 moredata-lfc-post-iddata-lfc-comment-countdata-lfc-localedata-lfc-layoutdata-lfc-colorschemedata-lfc-order-by+2 morelfc_options[lazy_facebook_comments]