Nested Comments Unbound Security & Risk Analysis

wordpress.org/plugins/nested-comments-unbound

Enable open-ended maximum depth for nested comments, preserve comment-reply-links for all comments, keep the results readable.

10 active installs v1.0 PHP + WP 3.3+ Updated Feb 25, 2017
commentariatcommentsmax-depthnested-commentsthreaded-comments
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Nested Comments Unbound Safe to Use in 2026?

Generally Safe

Score 85/100

Nested Comments Unbound has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The "nested-comments-unbound" v1.0 plugin exhibits a strong security posture based on the provided static analysis. The complete absence of any identified dangerous functions, SQL queries without prepared statements, file operations, external HTTP requests, and taint flows with unsanitized paths indicates a diligent approach to secure coding practices. Furthermore, the zero recorded CVEs and lack of any historical vulnerabilities suggest a mature and well-maintained plugin. The plugin also correctly implements capability checks where necessary.

However, the analysis does highlight a potential area for improvement. The statistic showing only 62% of output being properly escaped, with 37 total outputs, suggests that there are a number of instances where user-supplied or dynamic data might be rendered without adequate sanitization. This could potentially lead to cross-site scripting (XSS) vulnerabilities if the unescaped outputs contain malicious code that is then interpreted by the browser. While no specific XSS issues were flagged by taint analysis, this is a common attack vector and warrants attention.

In conclusion, "nested-comments-unbound" v1.0 is generally secure, with a commendable lack of critical vulnerabilities. The primary concern lies in the incomplete output escaping, which, while not currently exploited according to the data, represents a potential risk that should be addressed to further harden the plugin's security.

Key Concerns

  • 62% output escaping is not 100%
Vulnerabilities
None known

Nested Comments Unbound Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Nested Comments Unbound Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
14
23 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

62% escaped37 total outputs
Attack Surface

Nested Comments Unbound Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actioninitwp-ncu.php:89
actionadmin_initwp-ncu.php:90
actionadmin_menuwp-ncu.php:91
actioncomment_form_beforewp-ncu.php:92
filterthread_comments_depth_maxwp-ncu.php:95
filtercomment_classwp-ncu.php:96
actionwp_enqueue_scriptswp-ncu.php:99
actionadmin_print_styleswp-ncu.php:100
Maintenance & Trust

Nested Comments Unbound Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.32
Last updatedFeb 25, 2017
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Nested Comments Unbound Developer Profile

CK MacLeod

4 plugins · 540 total installs

80
trust score
Avg Security Score
80/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Nested Comments Unbound

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/nested-comments-unbound/style.css
Version Parameters
nested-comments-unbound/style.css?ver=nested-comments-unbound/css/wp_ncu_admin.css?ver=

HTML / DOM Fingerprints

CSS Classes
ncu_super-maxncu_breakpointncu_super-super-maxncu_turnpointncu_returnncu_return-ncu_turnncu_turn-
FAQ

Frequently Asked Questions about Nested Comments Unbound