
MyCommentAuthors Security & Risk Analysis
wordpress.org/plugins/mycommentauthorsPublish a list of your commentators and their number of comments for a certain month on a blog post
Is MyCommentAuthors Safe to Use in 2026?
Generally Safe
Score 85/100MyCommentAuthors has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "mycommentauthors" v2.0 plugin exhibits a mixed security posture. On the positive side, the plugin has no known vulnerabilities (CVEs) and a seemingly small attack surface with zero identified entry points requiring authentication. All identified SQL queries utilize prepared statements, indicating good practice in preventing SQL injection. However, there are significant concerns. The presence of the `create_function` dangerous function is a critical red flag, as it can be used to execute arbitrary code. Furthermore, a very low percentage (11%) of output escaping is concerning, suggesting a high risk of cross-site scripting (XSS) vulnerabilities. All identified taint flows lead to unsanitized paths, which, despite not being classified as critical or high severity in this report, combined with the poor output escaping, points to a substantial risk of XSS. The lack of any nonce checks or capability checks on any entry points, even though the static analysis reports zero unprotected entry points, still leaves room for concern if any new entry points are introduced or if the static analysis missed something. The vulnerability history is clean, but this, coupled with the identified code quality issues, suggests the plugin may have been lucky rather than robustly secure.
Key Concerns
- Dangerous function 'create_function' found
- Low output escaping percentage (11%)
- All taint flows lead to unsanitized paths
- No nonce checks on any entry points
- No capability checks on any entry points
MyCommentAuthors Security Vulnerabilities
MyCommentAuthors Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
MyCommentAuthors Attack Surface
WordPress Hooks 4
Maintenance & Trust
MyCommentAuthors Maintenance & Trust
Maintenance Signals
Community Trust
MyCommentAuthors Alternatives
GraphComment Comment system
graphcomment-comment-system
Transform your site's engagement with GraphComment—an advanced, interactive commenting system featuring live discussions and real-time notifications.
PhpSword Disable Comments
phpsword-disable-comments
Disable Comments from your WordPress website.
Comments Leaderboard
comments-leaderboard
Let the games begin! The Comments Leaderboard ranks your top commentators in a way that's sure to spark competition throughout your community.
Kento Top Commenters
kento-top-commenters
Top Commentators list By Count Comments
Akismet Anti-spam: Spam Protection
akismet
The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam solution for WordPress and WooCommerce.
MyCommentAuthors Developer Profile
2 plugins · 20 total installs
How We Detect MyCommentAuthors
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mycommentauthors/mca-home.php/wp-content/plugins/mycommentauthors/mca_sql_install_data.phpHTML / DOM Fingerprints
MyCommentAuthors<!-- Show form here --><!-- Show widget --><!-- End widget -->data-name="mcaNum"data-id="mcaNum"