
NFCBC SEO Plugin Add-on Security & Risk Analysis
wordpress.org/plugins/nfcbc-seo-plugin-add-onNFCBC SEO Plugin Add-on is an administration tool for follow and nofollow comment moderation.
Is NFCBC SEO Plugin Add-on Safe to Use in 2026?
Generally Safe
Score 85/100NFCBC SEO Plugin Add-on has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The nfcbc-seo-plugin-add-on v1.2 plugin exhibits a strong security posture in several key areas, notably its absence of reported CVEs and a clean taint analysis. The plugin also has a zero attack surface for AJAX, REST API, shortcodes, and cron events, indicating that these common entry points are either not present or are secured against unauthorized access. The low number of file operations and external HTTP requests further contributes to a reduced risk profile.
However, the static analysis reveals significant concerns. All six SQL queries are executed without prepared statements, posing a high risk of SQL injection vulnerabilities. Furthermore, a mere 20% of output is properly escaped, leaving a substantial portion vulnerable to cross-site scripting (XSS) attacks. The absence of nonce checks on any potential entry points (though the static analysis shows none exist, the lack of checks is a general weakness if any were to be added) and the limited capability checks (only 2) suggest a potential for privilege escalation or unauthorized actions if other weaknesses are discovered.
Given the complete lack of historical vulnerabilities, it's possible the developers are diligent, or that the plugin's limited functionality has gone unnoticed by attackers. However, the presence of raw SQL and unescaped output are fundamental security flaws that, if exploited, could lead to serious breaches. The plugin's strengths lie in its minimal attack surface and clean history, but these are overshadowed by critical code-level weaknesses.
Key Concerns
- Raw SQL queries without prepared statements
- Insufficient output escaping
- Lack of nonce checks
- Limited capability checks
NFCBC SEO Plugin Add-on Security Vulnerabilities
NFCBC SEO Plugin Add-on Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
NFCBC SEO Plugin Add-on Attack Surface
WordPress Hooks 5
Maintenance & Trust
NFCBC SEO Plugin Add-on Maintenance & Trust
Maintenance Signals
Community Trust
NFCBC SEO Plugin Add-on Alternatives
Comment Link Manager
comment-link-manager
CLM enables admins to disable author links, open links in new window, and remove the nofollow tag from links that are left in comments by visitors.
Nofollow Case by Case
nofollow-case-by-case
"Dofollow" but Nofollow Case by Case allows you to selectively apply nofollow to your comments as well.
Remove Website Link Field From Comment Section
remove-website-link-field-from-comment-section
Remove Website Link Field From Comment Section is a simple plug & play plugin. It removes website link input field from the comment section.
Disable Author Url and Comment Links
wp-remove-author-url-and-comment-links
Disable Author Url and Comment Links : DAUnCL helps you keep your comments clean from spam links left by automated or manual comment spammers who are …
Custom Base Terms
custom-base-terms
Modifique las estructuras personalizadas en las URLs para autor, búsqueda, comentarios, página y feed.
NFCBC SEO Plugin Add-on Developer Profile
4 plugins · 230 total installs
How We Detect NFCBC SEO Plugin Add-on
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
nfcbc-seo-plugin-add-on/nfcbc-seo-plugin-add-on.php?ver=HTML / DOM Fingerprints
<!-- NFCBC SEO Plugin Add-on (Nofollow Comment Author Management) --><!-- made by fob marketing (Oliver Bockelmann) --><!-- http://www.fob-marketing.de/ --><!-- THIS PLUGIN DOES NOT WORK WITHOUT NOFOLLOW CASE BY CASE or NFCBC SEO Light! -->+12 moreid^=commentwindow.jQuery