Mention-Me Widget Security & Risk Analysis

wordpress.org/plugins/mention-me

Simple widget to extend P2s (and other themes) functionality and display recent @replies for a logged in user in the sidebar.

10 active installs v1.0.5 PHP + WP 2.8+ Updated Oct 31, 2009
p2replieswidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Mention-Me Widget Safe to Use in 2026?

Generally Safe

Score 85/100

Mention-Me Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 16yr ago
Risk Assessment

The "mention-me" plugin version 1.0.5 presents a generally good security posture with no recorded vulnerabilities or critical code signals.

The static analysis reveals a remarkably small attack surface, with zero entry points identified. This is a strong indicator of secure development practices. However, the absence of taint analysis flows and the limited output escaping (28% properly escaped) are notable concerns. While no unsanitized paths were found in the analyzed flows, this could be due to the small number of flows or the lack of complex interactions that might expose such issues. The plugin uses SQL queries without prepared statements, which is a potential risk for SQL injection vulnerabilities, especially if the data processed by these queries is user-controlled.

The plugin's vulnerability history is clean, with no known CVEs. This, combined with the lack of recorded common vulnerability types, suggests a history of stable and secure releases. Despite the positive historical trend and minimal attack surface, the observed lack of prepared statements for SQL queries and the low percentage of proper output escaping warrant attention as potential future weaknesses.

Key Concerns

  • SQL queries not using prepared statements
  • Low percentage of properly escaped output
Vulnerabilities
None known

Mention-Me Widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Mention-Me Widget Release Timeline

v1.0.5Current
v1.0.4
v1.0.3
v1.0.2
v1.0.1
v1.0.0
Code Analysis
Analyzed Mar 17, 2026

Mention-Me Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
5
0 prepared
Unescaped Output
21
8 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared5 total queries

Output Escaping

28% escaped29 total outputs
Attack Surface

Mention-Me Widget Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actioncomment_postmention-me.php:14
actionwp_set_comment_statusmention-me.php:15
actionsave_postmention-me.php:16
actionwidgets_initmention-me.php:300
Maintenance & Trust

Mention-Me Widget Maintenance & Trust

Maintenance Signals

WordPress version tested2.8.5
Last updatedOct 31, 2009
PHP min version
Downloads4K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Mention-Me Widget Developer Profile

Thorsten Ott

3 plugins · 80 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Mention-Me Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
p2-recent-mentions
Data Attributes
avatar
FAQ

Frequently Asked Questions about Mention-Me Widget