
New Page Comments Security & Risk Analysis
wordpress.org/plugins/new-page-commentsShow comments section in new page or load when user wants to see. Reduce load time process of comments functionality on your WordPress site.
Is New Page Comments Safe to Use in 2026?
Generally Safe
Score 100/100New Page Comments has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "new-page-comments" plugin v0.3 exhibits a mixed security posture. On the positive side, the absence of any known CVEs, including critical or high-severity ones, and the consistent use of prepared statements for SQL queries are strong indicators of good security practices. The plugin also performs file operations or external HTTP requests, and it utilizes nonce and capability checks on at least one entry point. However, there are significant concerns. The presence of two AJAX handlers, with one lacking authentication checks, creates a direct vulnerability. Additionally, while the taint analysis shows no flows, the relatively low percentage of properly escaped output (67%) suggests a potential risk of cross-site scripting (XSS) vulnerabilities, especially if untrusted data reaches these unescaped outputs. The limited attack surface is a positive, but the unprotected AJAX handler is a notable weakness.
Key Concerns
- Unprotected AJAX handler found
- Significant portion of output not properly escaped
New Page Comments Security Vulnerabilities
New Page Comments Code Analysis
Output Escaping
New Page Comments Attack Surface
AJAX Handlers 2
WordPress Hooks 11
Maintenance & Trust
New Page Comments Maintenance & Trust
Maintenance Signals
Community Trust
New Page Comments Alternatives
Remove Yoast SEO Comments
remove-yoast-seo-comments
Removes the Yoast SEO advertisement HTML comments from your front-end source code.
No External Links
mihdan-no-external-links
Convert external links into internal links, site wide or post/page specific. Add NoFollow, Click logging, and more...
AnyComment
anycomment
AnyComment is blazing-fast commenting plugin based on React for WordPress.
Lazy Load for Comments
lazy-load-for-comments
Lazy load default WordPress commenting system on scroll or click. Improve page speed.
Lazy Social Comments
lazy-facebook-comments
Use Facebook Comments with lazy loading feature. Load FB comments after button click or scroll down.
New Page Comments Developer Profile
2 plugins · 10 total installs
How We Detect New Page Comments
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/new-page-comments/assets/cmnt.css/wp-content/plugins/new-page-comments/assets/npc-cmnt.js/wp-content/plugins/new-page-comments/assets/admin-main.css/wp-content/plugins/new-page-comments/assets/admin-main.js/wp-content/plugins/new-page-comments/assets/npc-cmnt.js/wp-content/plugins/new-page-comments/assets/admin-main.jsnew-page-comments/assets/cmnt.css?ver=new-page-comments/assets/npc-cmnt.js?ver=new-page-comments/assets/admin-main.css?ver=new-page-comments/assets/admin-main.js?ver=HTML / DOM Fingerprints
npc-main-wrappernpc_vars/wp-json/new-page-comments/v1/...