
Meet Your Commenters Security & Risk Analysis
wordpress.org/plugins/meet-your-commentersDisplays web pages and social networks' profiles of your commenters in the dashboard.
Is Meet Your Commenters Safe to Use in 2026?
Generally Safe
Score 85/100Meet Your Commenters has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "meet-your-commenters" plugin v1.2 presents a mixed security posture. While the static analysis indicates a remarkably small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events, this is overshadowed by significant concerns within its code.
The most critical issues stem from the lack of proper security checks and data handling. Specifically, none of the SQL queries use prepared statements, meaning there's a high risk of SQL injection vulnerabilities. Furthermore, a concerning 100% of output is not properly escaped, creating a strong potential for Cross-Site Scripting (XSS) attacks. The presence of two taint flows with unsanitized paths, identified as high severity, directly supports these risks. The plugin also lacks essential security measures like nonce checks and capability checks on its entry points (even though they are currently zero), which are fundamental for preventing unauthorized actions.
The plugin's vulnerability history is currently clean, with no recorded CVEs. This is a positive sign but does not negate the immediate code-level risks. The absence of past vulnerabilities might be due to the plugin's limited complexity or a lack of focused security auditing. In conclusion, while the plugin has minimal direct attack vectors exposed, the internal code quality is poor, with a high likelihood of exploitable vulnerabilities due to unescaped output and raw SQL queries. The lack of any security checks further exacerbates these weaknesses.
Key Concerns
- All SQL queries lack prepared statements
- 100% of output not properly escaped
- Two high severity unsanitized taint flows
- No nonce checks implemented
- No capability checks implemented
Meet Your Commenters Security Vulnerabilities
Meet Your Commenters Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Meet Your Commenters Attack Surface
WordPress Hooks 2
Maintenance & Trust
Meet Your Commenters Maintenance & Trust
Maintenance Signals
Community Trust
Meet Your Commenters Alternatives
Error Log Monitor
error-log-monitor
Adds a Dashboard widget that displays the latest messages from your PHP error log. It can also send logged errors to email.
Widget Disable
wp-widget-disable
Disable sidebar and dashboard widgets with an easy to use interface.
Server Info
server-info
This plugin will show you very useful information about your hosting server such as PHP version, Server OS, Server IP etc.
Dashboard Commander
dashboard-commander
Command your admin dashboard. Manage built-in widgets and dynamically registered widgets. Hide widgets depending upon user capabilities.
Dashboard quick links widget
dashboard-quick-link-widget
A lightweight plugin to allows admins to create a admin dashboard widget with frequently accessed links for quick access.
Meet Your Commenters Developer Profile
4 plugins · 40 total installs
How We Detect Meet Your Commenters
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/meet-your-commenters/css/style.css/wp-content/plugins/meet-your-commenters/js/meet-your-commenters.js/wp-content/plugins/meet-your-commenters/js/meet-your-commenters.jsmeet-your-commenters/css/style.css?ver=meet-your-commenters/js/meet-your-commenters.js?ver=HTML / DOM Fingerprints
textright