
Limit Comments and Word Count Security & Risk Analysis
wordpress.org/plugins/limit-comments-and-word-countThis plugin will limit the number of comments and the word count each user can add to a WordPress blog post, configurable by user role and time.
Is Limit Comments and Word Count Safe to Use in 2026?
Generally Safe
Score 100/100Limit Comments and Word Count has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'limit-comments-and-word-count' plugin, version 1.2.4, exhibits a mixed security posture. While it demonstrates good practices in avoiding dangerous functions, file operations, and external HTTP requests, and a decent percentage of its SQL queries use prepared statements, significant concerns arise from its attack surface. The presence of 5 AJAX handlers without authentication checks presents a notable risk, as these can be exploited by unauthenticated users to trigger unintended actions. The complete lack of nonce checks further exacerbates this risk, making these AJAX endpoints highly vulnerable to Cross-Site Request Forgery (CSRF) attacks. The plugin's history of zero known vulnerabilities is a positive sign, suggesting a generally stable codebase and diligent maintenance. However, this does not negate the immediate risks identified in the static analysis.
Key Concerns
- Unprotected AJAX handlers
- Missing nonce checks on AJAX handlers
- SQL queries not using prepared statements (40% of 5)
- Improperly escaped output (35% of 63)
Limit Comments and Word Count Security Vulnerabilities
Limit Comments and Word Count Code Analysis
SQL Query Safety
Output Escaping
Limit Comments and Word Count Attack Surface
AJAX Handlers 5
Shortcodes 2
WordPress Hooks 28
Maintenance & Trust
Limit Comments and Word Count Maintenance & Trust
Maintenance Signals
Community Trust
Limit Comments and Word Count Alternatives
No alternatives data available yet.
Limit Comments and Word Count Developer Profile
8 plugins · 5K total installs
How We Detect Limit Comments and Word Count
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/limit-comments-and-word-count/js/limit-comments-admin.js/wp-content/plugins/limit-comments-and-word-count/css/limit-comments-admin.css/wp-content/plugins/limit-comments-and-word-count/js/limit-comments-admin.jslimit-comments-and-word-count/js/limit-comments-admin.js?ver=limit-comments-and-word-count/css/limit-comments-admin.css?ver=HTML / DOM Fingerprints
lpwc_noticelpwc_content<!-- Comment restrictions meta box --><!-- End Comment restrictions meta box -->data-lpwc-idlpwc_admin_obj/wp-json/lpwc/v1/settings[IN_LIMIT][in_limit]