
No Page Comment Security & Risk Analysis
wordpress.org/plugins/no-page-commentAn admin interface to control the default comment and trackback settings on new posts, pages and custom post types.
Is No Page Comment Safe to Use in 2026?
Generally Safe
Score 99/100No Page Comment has a strong security track record. Known vulnerabilities have been patched promptly.
The "no-page-comment" plugin v1.3.1 exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and performing a decent number of capability checks. The absence of file operations, external HTTP requests, and critical or high severity taint flows is also encouraging, suggesting a contained and relatively safe codebase in certain areas. However, significant concerns arise from the attack surface analysis and its vulnerability history.
The presence of three AJAX handlers, with one completely lacking authentication checks, presents a direct entry point for potential attackers. This unprotected endpoint is a prime target for unauthorized actions or data manipulation if not properly secured. While the plugin has nonce checks, the absence of authorization on one AJAX handler overshadows this. The vulnerability history, with two past CVEs including a high-severity 'Cross-site Scripting' and a medium-severity 'Cross-Site Request Forgery', indicates a pattern of past security weaknesses. The fact that these vulnerabilities were discovered and patched suggests the developers are responsive, but the recurrence of common web vulnerabilities is a red flag for ongoing diligence.
In conclusion, while the plugin employs some secure coding practices like prepared statements, the unprotected AJAX handler is a critical flaw. The historical vulnerability data further elevates the risk, suggesting a need for more robust and consistent security auditing. The plugin's strengths lie in its SQL handling and lack of complex external interactions, but its weaknesses in input validation and authorization on critical endpoints, coupled with past security incidents, necessitate caution.
Key Concerns
- Unprotected AJAX handler found
- Past high severity vulnerability (XSS)
- Past medium severity vulnerability (CSRF)
- Large attack surface without auth checks
- Output escaping below optimal levels (72%)
No Page Comment Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
No Page Comment <= 1.1 - Reflected Cross-Site Scripting
No Page Comment <= 1.1 - Cross-Site-Request Forgery to Settings Change
No Page Comment Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
No Page Comment Attack Surface
AJAX Handlers 3
WordPress Hooks 10
Maintenance & Trust
No Page Comment Maintenance & Trust
Maintenance Signals
Community Trust
No Page Comment Alternatives
Posts in Page
posts-in-page
Easily add one or more posts to any page using simple shortcodes.
Author Filters
author-filters
Author filters plugin integrates an author filter drop down to sort listing on post, page, custom post type in admin.
Search by ID
search-by-id
Enables the user to search by post ID using the built-in search within the control panel. Works for all kinds of posts.
Disable Feeds and Comments
disable-rss-feeds-and-comments
This WordPress plugin, "Disable RSS Feeds and Comments," gives you the ability to turn off both the RSS feeds and comments on pages and/or p …
ClonePress – Duplicate Pages, Posts & Custom Post Types
clonepress
Easily duplicate posts, pages, and custom post types with a single click.
No Page Comment Developer Profile
1 plugin · 10K total installs
How We Detect No Page Comment
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/no-page-comment/no-page-comment.js/wp-content/plugins/no-page-comment/assets/css/admin.css/wp-content/plugins/no-page-comment/assets/js/admin.js/wp-content/plugins/no-page-comment/no-page-comment.js/wp-content/plugins/no-page-comment/assets/js/admin.jsno-page-comment.js?ver=admin.css?ver=admin.js?ver=HTML / DOM Fingerprints
sta-npc-noticesta-npc-notice-dismissdata-noncestaNpcNotice