
LNC Near Comments Security & Risk Analysis
wordpress.org/plugins/lnc-near-commentsLNC Near Comments plugin is advanced captcha system prevents spam comments and bots from infiltrating your site, by integration with near web3 smart c …
Is LNC Near Comments Safe to Use in 2026?
Generally Safe
Score 85/100LNC Near Comments has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The lnc-near-comments plugin v0.1.3 exhibits a concerning security posture due to a critical lack of authentication checks on its exposed entry points. While the static analysis indicates good practices in other areas, such as the absence of dangerous functions, 100% use of prepared statements for SQL queries, and proper output escaping, these strengths are significantly undermined by the unprotected AJAX handler.
The plugin presents a single, unprotected entry point in the form of an AJAX handler. This means any unauthenticated user can potentially interact with this handler, leading to a high risk of unauthorized actions or information disclosure if the handler performs sensitive operations. The absence of nonce and capability checks further exacerbates this risk, as there are no mechanisms in place to verify the user's identity or permissions.
Furthermore, the lack of any recorded vulnerability history, while seemingly positive, could also indicate that the plugin has not been subjected to extensive security testing or that its limited functionality has not yet attracted malicious attention. The plugin's static analysis shows no critical or high-severity issues in taint flows, and it does not use dangerous functions or make external HTTP requests. However, the single, unprotected AJAX handler is a significant weakness that overrides these positive observations. The plugin's overall security is compromised by this single point of failure, making it a high-risk component despite its apparent clean slate in other security metrics.
Key Concerns
- AJAX handler without auth checks
- Missing nonce checks on AJAX handler
- Missing capability checks on AJAX handler
LNC Near Comments Security Vulnerabilities
LNC Near Comments Code Analysis
Output Escaping
LNC Near Comments Attack Surface
AJAX Handlers 1
WordPress Hooks 8
Maintenance & Trust
LNC Near Comments Maintenance & Trust
Maintenance Signals
Community Trust
LNC Near Comments Alternatives
Meritocracy – Near-Powered Gamification Plugin for WordPress
meritocracy
Meritocracy is a Near protocol-powered gamification plugin for WordPress.
Talkee
talkee
Own Web3 Commenting and Chat with Ethereum Login & Wallets
Web3Press – Migrating to 3ook.com Decentralized Bookstore
likecoin
FINAL LEGACY VERSION: Read-only maintenance version before 3ook.com transition. No new publishing features.
CardanoPress – Cardano Blockchain Integration for WordPress
cardanopress
Integrate the Cardano blockchain with your WordPress website. Merging Web2 and Web3.
Chainium – Blockchain Integrations & Web3 Crypto Wallet Authenticator
chainium
Blockchain Integrations, Web3, Crypto, Wallet, Authenticator, Login, NFT Marketplace, Explorer, MetaMask, Trust Wallet, Ethereum, Solana, Tron
LNC Near Comments Developer Profile
2 plugins · 20 total installs
How We Detect LNC Near Comments
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/lnc-near-comments/assets/js/index.js/wp-content/plugins/lnc-near-comments/assets/js/index.jslnc-near-comments/assets/js/index.js?ver=0.01HTML / DOM Fingerprints
lnc_near_comments