
No English Comments Security & Risk Analysis
wordpress.org/plugins/no-english-commentsDisallow English Comments in Your Blog. 在你的部落格中禁止英文評論
Is No English Comments Safe to Use in 2026?
Generally Safe
Score 85/100No English Comments has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "no-english-comments" v1.0.6 plugin exhibits a mixed security posture. On the positive side, the static analysis reveals a minimal attack surface with zero identified entry points (AJAX, REST API, shortcodes, cron events) that are unprotected. Furthermore, there are no identified dangerous functions, no file operations, no external HTTP requests, and notably, 100% of SQL queries utilize prepared statements. The vulnerability history is also clean, with zero known CVEs of any severity, suggesting a generally stable and well-maintained codebase. However, a significant concern arises from the output escaping analysis, where 100% of the 5 identified outputs are not properly escaped. This could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is directly rendered in the output without sanitization. The absence of nonce and capability checks, while aligned with the zero attack surface, means that if an entry point were discovered, authorization and integrity checks would be entirely missing, making any potential vulnerabilities more impactful.
Key Concerns
- 100% of outputs unescaped
- No nonce checks found
- No capability checks found
No English Comments Security Vulnerabilities
No English Comments Code Analysis
Output Escaping
No English Comments Attack Surface
WordPress Hooks 4
Maintenance & Trust
No English Comments Maintenance & Trust
Maintenance Signals
Community Trust
No English Comments Alternatives
Block Spam Comments
block-spam-comments
Detect and Block spam comments.
Akismet Anti-spam: Spam Protection
akismet
The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam solution for WordPress and WooCommerce.
Disable Comments – Remove Comments & Stop Spam [Multi-Site Support]
disable-comments
Allows administrators to globally disable comments on their site. Comments can be disabled according to post type. Multisite friendly.
Antispam Bee
antispam-bee
Sophisticated antispam plugin for effective daily comment and trackback spam-fighting. Built with data protection and privacy in mind.
Spam protection, Honeypot, Anti-Spam by CleanTalk
cleantalk-spam-protect
Blocks spam comments, fake users, contact form spam and more. No impact on SEO. Privacy focused. CAPTCHA free, premium Antispam plugin.
No English Comments Developer Profile
24 plugins · 2K total installs
How We Detect No English Comments
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/no-english-comments/js/nec.js/wp-content/plugins/no-english-comments/css/nec.css/wp-content/plugins/no-english-comments/js/nec.jsno-english-comments/js/nec.js?ver=no-english-comments/css/nec.css?ver=