
LoudVoice Comments Plugin – Supercharge your WordPress comments Security & Risk Analysis
wordpress.org/plugins/loudvoice-comment-systemReplaces the basic WordPress comments by a powerful comment system that includes logging in with 40+ social networks, spam filters and more.
Is LoudVoice Comments Plugin – Supercharge your WordPress comments Safe to Use in 2026?
Generally Safe
Score 85/100LoudVoice Comments Plugin – Supercharge your WordPress comments has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "loudvoice-comment-system" v2.2 plugin exhibits a mixed security posture. While it demonstrates good practices by utilizing prepared statements for all SQL queries and including a reasonable number of nonce checks, there are significant areas of concern. The presence of two AJAX handlers without authentication checks, combined with two taint analysis flows identified as having unsanitized paths, represents a notable risk. These weaknesses suggest potential entry points for attackers to execute unauthorized actions or manipulate data if these paths are exploitable. The plugin's history of having no known vulnerabilities is a positive indicator, suggesting that past code may have been more robust or that active maintenance has prevented critical issues. However, the current code analysis reveals specific vulnerabilities that should not be overlooked. The overall security is weakened by the unprotected AJAX endpoints and the identified unsanitized flows, despite the absence of historical CVEs.
Key Concerns
- AJAX handlers without authentication checks
- Taint flows with unsanitized paths (High severity)
- Low percentage of properly escaped output
- No capability checks
LoudVoice Comments Plugin – Supercharge your WordPress comments Security Vulnerabilities
LoudVoice Comments Plugin – Supercharge your WordPress comments Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
LoudVoice Comments Plugin – Supercharge your WordPress comments Attack Surface
AJAX Handlers 10
WordPress Hooks 20
Maintenance & Trust
LoudVoice Comments Plugin – Supercharge your WordPress comments Maintenance & Trust
Maintenance Signals
Community Trust
LoudVoice Comments Plugin – Supercharge your WordPress comments Alternatives
Comments – wpDiscuz
wpdiscuz
AJAX powered realtime comments. Designed to extend WordPress native comments. Custom comment forms/fields. Making comments has never been so awesome!
AnyComment
anycomment
AnyComment is blazing-fast commenting plugin based on React for WordPress.
Import Markdown – Versatile Markdown Importer
import-markdown
Import Markdown lets you easily generates posts based on Markdown files.
Markup Markdown
markup-markdown
Disable Wordpress's native Gutenberg or TinyMCE editor in favor of a Markdown editor.
Comment Edit Core – Simple Comment Editing
simple-comment-editing
Allow your users to edit their comments for a period of time. Adjust the comment timer and save some admin headaches.
LoudVoice Comments Plugin – Supercharge your WordPress comments Developer Profile
2 plugins · 5K total installs
How We Detect LoudVoice Comments Plugin – Supercharge your WordPress comments
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/loudvoice-comment-system/assets/css/backend.css/wp-content/plugins/loudvoice-comment-system/assets/js/dashboard.js/wp-content/plugins/loudvoice-comment-system/assets/js/backend.js/wp-content/plugins/loudvoice-comment-system/assets/js/dashboard.js/wp-content/plugins/loudvoice-comment-system/assets/js/backend.jsloudvoice-comment-system/assets/css/backend.css?ver=loudvoice-comment-system/assets/js/dashboard.js?ver=loudvoice-comment-system/assets/js/backend.js?ver=HTML / DOM Fingerprints
oa_loudvoice_boxoa_loudvoice_box_dangeroa_loudvoice_box_titleoa_loudvoice_box_contentdata-ajax-urlobjectL10n