
LH Comment Form Shortcode and Block Security & Risk Analysis
wordpress.org/plugins/lh-comment-form-shortcodeShortcodes to display comment forms and comment listings inline on any post, page, or cpt!
Is LH Comment Form Shortcode and Block Safe to Use in 2026?
Generally Safe
Score 100/100LH Comment Form Shortcode and Block has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "lh-comment-form-shortcode" plugin v1.01 exhibits a strong security posture based on the provided static analysis. The absence of any identified dangerous functions, file operations, or external HTTP requests is commendable. Furthermore, the plugin exclusively utilizes prepared statements for its single SQL query, mitigating the risk of SQL injection vulnerabilities. The limited number of output operations, with a majority properly escaped, also suggests a good understanding of secure coding practices regarding output sanitization.
The taint analysis reveals no identified flows, indicating that no unsanitized data is being passed to sensitive operations. The vulnerability history also shows a clean record, with no known CVEs associated with this plugin. This lack of historical vulnerabilities, combined with the positive static analysis results, suggests that the plugin has been developed with security in mind and has likely undergone careful review.
While the plugin demonstrates excellent security practices in many areas, the complete absence of nonces and capability checks across all identified entry points (though there are none) is a theoretical weakness. If entry points were to be introduced in future versions, this lack of inherent protection could become a concern. However, based solely on the current version's analysis, the plugin appears to be very secure, with no immediate risks identified.
Key Concerns
- No nonce checks present
- No capability checks present
- 67% output escaping (potentially 1 unescaped)
LH Comment Form Shortcode and Block Security Vulnerabilities
LH Comment Form Shortcode and Block Code Analysis
SQL Query Safety
Output Escaping
LH Comment Form Shortcode and Block Attack Surface
WordPress Hooks 7
Maintenance & Trust
LH Comment Form Shortcode and Block Maintenance & Trust
Maintenance Signals
Community Trust
LH Comment Form Shortcode and Block Alternatives
Post Content Shortcodes
post-content-shortcodes
Adds shortcodes to display the content of a post or a list of posts.
JSM file_get_contents() Shortcode
wp-file-get-contents
A safe and reliable WordPress shortcode for PHP's file_get_contents() function.
Custom ShortCode Creator
custom-shortcode-creator
This Custom Shotcode Creator plugin allows you to quickly define custom shortcodes via admin dashboard without any hassle.
TC Comment Out
tc-comment-out
Comment out page and post content using a shortcode.
Post Content Shortcode
post-content-shortcode
Embed the content of another post using a simple shortcode. Useful for reusing content across pages or posts.
LH Comment Form Shortcode and Block Developer Profile
77 plugins · 15K total installs
How We Detect LH Comment Form Shortcode and Block
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/lh-comment-form-shortcode/lh-comment-form-shortcode.phpHTML / DOM Fingerprints
lh_comment_form_shortcode-list[lh_comment_form_shortcode][lh_comment_list]