
MM Comment Field Ratings Security & Risk Analysis
wordpress.org/plugins/mm-comment-field-ratingsAdds a customizable 5 star rating field to the worpress native comment form..
Is MM Comment Field Ratings Safe to Use in 2026?
Generally Safe
Score 85/100MM Comment Field Ratings has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "mm-comment-field-ratings" plugin v1.0 presents a mixed security profile. On one hand, the absence of known CVEs and no recorded vulnerabilities suggest a history of stable and secure code. The static analysis also indicates a lack of direct attack vectors like AJAX handlers, REST API routes, shortcodes, or cron events, and importantly, all SQL queries are properly prepared, mitigating the risk of SQL injection. However, several significant concerns emerge from the code analysis. The plugin has a low percentage (10%) of properly escaped outputs, meaning there's a high likelihood of Cross-Site Scripting (XSS) vulnerabilities when displaying user-generated content or data. Furthermore, the complete absence of nonce checks and capability checks on potential entry points (even though none are explicitly listed) is a critical oversight. While the attack surface appears minimal, any future expansion or an unforeseen vulnerability in file operations could be exploited without these fundamental security measures. The file operation present is also a potential point of concern without further context or checks.
Key Concerns
- Low output escaping percentage (10%)
- Missing nonce checks
- Missing capability checks
- Presence of file operations without context
MM Comment Field Ratings Security Vulnerabilities
MM Comment Field Ratings Code Analysis
Output Escaping
MM Comment Field Ratings Attack Surface
WordPress Hooks 17
Maintenance & Trust
MM Comment Field Ratings Maintenance & Trust
Maintenance Signals
Community Trust
MM Comment Field Ratings Alternatives
Akismet Anti-spam: Spam Protection
akismet
The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam solution for WordPress and WooCommerce.
Disable Comments – Remove Comments & Stop Spam [Multi-Site Support]
disable-comments
Allows administrators to globally disable comments on their site. Comments can be disabled according to post type. Multisite friendly.
Antispam Bee
antispam-bee
Sophisticated antispam plugin for effective daily comment and trackback spam-fighting. Built with data protection and privacy in mind.
WP Armour – Honeypot Anti Spam
honeypot
Fastest growing Anti Spam plugin. No API calls, subscriptions, captcha or puzzle. Full GDPR complaint. For comments, contact form, login, registration
Advanced Google reCAPTCHA
advanced-google-recaptcha
Captcha protection against spam comments & brute force login attacks using Google reCAPTCHA.
MM Comment Field Ratings Developer Profile
2 plugins · 20 total installs
How We Detect MM Comment Field Ratings
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mm-comment-field-ratings/css/mmcfr-styles.css/wp-content/plugins/mm-comment-field-ratings/js/mmcfr-user.js/wp-content/plugins/mm-comment-field-ratings/assets/js/jquery.barrating.min.js/wp-content/plugins/mm-comment-field-ratings/assets/css/bars-reversed.css/wp-content/plugins/mm-comment-field-ratings/assets/css/bars-horizontal.css/wp-content/plugins/mm-comment-field-ratings/assets/css/bars-movie.css/wp-content/plugins/mm-comment-field-ratings/assets/css/bars-pill.css/wp-content/plugins/mm-comment-field-ratings/assets/css/bars-css.css+3 more/wp-content/plugins/mm-comment-field-ratings/js/mmcfr-user.js/wp-content/plugins/mm-comment-field-ratings/css/mmcfr-styles.css?ver=/wp-content/plugins/mm-comment-field-ratings/js/mmcfr-user.js?ver=/wp-content/plugins/mm-comment-field-ratings/assets/js/jquery.barrating.min.js?ver=/wp-content/plugins/mm-comment-field-ratings/assets/css/bars-reversed.css?ver=/wp-content/plugins/mm-comment-field-ratings/assets/css/bars-horizontal.css?ver=/wp-content/plugins/mm-comment-field-ratings/assets/css/bars-movie.css?ver=/wp-content/plugins/mm-comment-field-ratings/assets/css/bars-pill.css?ver=/wp-content/plugins/mm-comment-field-ratings/assets/css/bars-css.css?ver=/wp-content/plugins/mm-comment-field-ratings/assets/css/theme.css?ver=/wp-content/plugins/mm-comment-field-ratings/assets/css/fontawesome-stars.css?ver=/wp-content/plugins/mm-comment-field-ratings/assets/css/fontawesome-stars-o.css?ver=HTML / DOM Fingerprints
mmcfr-starsmmcfr-color-mm-rating-titlemm-ratingsmm-fontawesome-stars-odata-name="mmcfr-stars-count"data-name="mmcfr-stars-style"data-name="mmcfr-stars-required"jQuery