Mindvalley Comments Moderator Security & Risk Analysis

wordpress.org/plugins/mindvalley-comment-moderator

Create a custom role that enables only Comment Moderation actions and pages.

10 active installs v1.1.3 PHP + WP 3.1+ Updated Jul 29, 2012
commentmoderationmoderatoruser-role
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Mindvalley Comments Moderator Safe to Use in 2026?

Generally Safe

Score 85/100

Mindvalley Comments Moderator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 13yr ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the 'mindvalley-comment-moderator' plugin v1.1.3 appears to have a strong security posture. The static analysis reveals no identified attack vectors such as unprotected AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, the code demonstrates good practices by not utilizing dangerous functions, performing SQL queries exclusively with prepared statements, and ensuring all output is properly escaped. The absence of file operations and external HTTP requests further reduces potential attack surfaces. The presence of capability checks, although not explicitly detailed in terms of their implementation, indicates an attempt to enforce permissions.

The vulnerability history is equally positive, with zero known CVEs, no unpatched vulnerabilities, and no recorded common vulnerability types. This suggests a history of robust security development and maintenance. The taint analysis also returned zero critical or high severity flows, reinforcing the idea that there are no immediate, severe security flaws detected within the analyzed code paths. The plugin's strength lies in its minimal attack surface and its adherence to secure coding principles in the areas that were analyzed.

While the data presents a highly favorable security outlook, it's important to note that the static analysis reported zero taint flows and zero total flows analyzed. This could indicate either a very simple plugin with minimal dynamic behavior, or it could mean that the taint analysis was not comprehensive enough to cover all potential interaction points or complex data transformations. However, given the other positive indicators, the plugin is assessed as having a low overall risk. The main area to consider is the reported zero nonce checks, which, when combined with the absence of AJAX handlers, suggests that direct client-side interactions might not be a primary concern, or that authorization is handled solely through capability checks.

Key Concerns

  • No nonce checks detected
Vulnerabilities
None known

Mindvalley Comments Moderator Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Mindvalley Comments Moderator Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
5
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Mindvalley Comments Moderator Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionadmin_bar_menumindvalley-comment-moderator.php:14
actionadmin_menumindvalley-comment-moderator.php:19
actionadmin_initmindvalley-comment-moderator.php:20
actionwp_dashboard_setupmindvalley-comment-moderator.php:22
actionadmin_menumindvalley-comment-moderator.php:23
actioninitmindvalley-comment-moderator.php:24
actionadmin_menumindvalley-comment-moderator.php:153
actionwp_before_admin_bar_rendermindvalley-comment-moderator.php:154
Maintenance & Trust

Mindvalley Comments Moderator Maintenance & Trust

Maintenance Signals

WordPress version tested3.4.2
Last updatedJul 29, 2012
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Mindvalley Comments Moderator Developer Profile

Mindvalley

7 plugins · 160 total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Mindvalley Comments Moderator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mindvalley-comment-moderator/mindvalley-comment-moderator.php

HTML / DOM Fingerprints

CSS Classes
pending-count
FAQ

Frequently Asked Questions about Mindvalley Comments Moderator