No Comments On Pages Security & Risk Analysis

wordpress.org/plugins/no-comments-on-pages

A tiny WordPress plugin which, when activated, disables posting of new comments to all pages and hides existing ones.

1K active installs v1.0.2 PHP + WP 2.7+ Updated Nov 28, 2017
commentspages
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is No Comments On Pages Safe to Use in 2026?

Generally Safe

Score 85/100

No Comments On Pages has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The "no-comments-on-pages" plugin v1.0.2 exhibits an exceptionally strong security posture based on the provided static analysis. There are no identified entry points such as AJAX handlers, REST API routes, or shortcodes, which significantly limits the potential attack surface. Furthermore, the code analysis reveals no dangerous functions, no direct SQL queries (all handled via prepared statements), and all outputs are properly escaped, indicating good coding practices for secure development. The absence of file operations and external HTTP requests further reduces the risk profile. The plugin also demonstrates robust security by lacking any nonce checks or capability checks, which, while seemingly an omission, is not a concern in this case due to the complete absence of traditional entry points that would necessitate them. The vulnerability history is clean, with no recorded CVEs, which is a positive indicator of the plugin's historical security and maintenance.

Overall, the plugin appears to be very securely developed, with a minimal attack surface and no apparent vulnerabilities detected in the static analysis. The lack of any identified issues or past vulnerabilities suggests a high level of diligence from the developer. The only potential area of note, albeit not a direct security flaw given the analysis, is the complete absence of nonces and capability checks, which would be a significant concern if the plugin had exposed any user-facing or admin-facing entry points. However, in this specific context, it doesn't translate to a real risk.

Given the data, there are no evidence-backed security concerns to report. The plugin's design, with zero entry points and adherence to secure coding principles for the minimal code it has, makes it appear very secure. The absence of any historical vulnerabilities further reinforces this assessment. Therefore, no deductions are warranted.

Vulnerabilities
None known

No Comments On Pages Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

No Comments On Pages Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

No Comments On Pages Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
filtercomments_openno-comments-on-pages.php:47
filtercomments_templateno-comments-on-pages.php:48
Maintenance & Trust

No Comments On Pages Maintenance & Trust

Maintenance Signals

WordPress version tested2.7
Last updatedNov 28, 2017
PHP min version
Downloads60K

Community Trust

Rating100/100
Number of ratings2
Active installs1K
Developer Profile

No Comments On Pages Developer Profile

jakajancar

1 plugin · 1K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect No Comments On Pages

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/no-comments-on-pages/
Version Parameters
no-comments-on-pages?ver=1.0.2

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about No Comments On Pages