No Comment Links Security & Risk Analysis

wordpress.org/plugins/no-comment-links

When activated, disables automatic parsing and creation of clickable links in comments, including http, ftp, and e-mail links.

100 active installs v1.0.1 PHP + WP 1.5+ Updated Dec 8, 2016
commentcommentslinksurl
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is No Comment Links Safe to Use in 2026?

Generally Safe

Score 85/100

No Comment Links has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The 'no-comment-links' plugin v1.0.1 exhibits an exceptionally strong security posture based on the provided static analysis and vulnerability history. The absence of any detected dangerous functions, file operations, external HTTP requests, or SQL queries without prepared statements is highly commendable. Furthermore, the complete lack of unescaped output and the zero total entry points, all of which are protected, indicate a very small and securely implemented attack surface. The plugin's history of zero known CVEs, with no currently unpatched vulnerabilities, reinforces this positive assessment. This suggests the developers have a strong understanding of secure coding practices and have maintained this standard over time.

While the static analysis reveals no immediate code-level vulnerabilities, the primary area for potential concern, albeit minor given the current data, is the complete absence of nonce checks and capability checks. For a plugin with zero entry points, this might not pose an immediate threat. However, if the plugin's functionality were to expand in the future to include any form of user interaction or data modification, the lack of these fundamental security mechanisms could become a significant oversight. Nevertheless, based on the current data, the plugin appears to be very secure and well-developed.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

No Comment Links Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

No Comment Links Release Timeline

v1.0.1Current
Code Analysis
Analyzed Mar 16, 2026

No Comment Links Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

No Comment Links Attack Surface

Entry Points0
Unprotected0
Maintenance & Trust

No Comment Links Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.28
Last updatedDec 8, 2016
PHP min version
Downloads11K

Community Trust

Rating60/100
Number of ratings2
Active installs100
Developer Profile

No Comment Links Developer Profile

aaron44126

2 plugins · 110 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect No Comment Links

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about No Comment Links